Wireless Access Point Security Reputation System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges in determining the security risk of public wireless network access points, as they often cannot distinguish between safe and insecure access points, and malicious access points can pose as legitimate ones, putting devices at risk of attacks.
Innovation Solution
A system and method that correlate security events on mobile devices connected to wireless network access points to assign a reputation score, which is then used to inform other devices about the security risk, allowing them to decide whether to connect, thereby enhancing network security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If public wireless access points are made open to any device, then ease of operation is improved, but security reliability deteriorates
Solution Approach 1:
The system performs preliminary security assessment of access points before devices connect to them. Security reputation scores are calculated in advance based on historical security events, and this information is provided to devices before connection occurs, allowing users to make informed decisions without compromising the open nature of public WiFi
Solution Approach 2:
The system implements a feedback mechanism where security events on connected devices are collected and used to update the security reputation of access points. This feedback loop continuously improves the accuracy of security assessments, allowing the system to warn users about compromised access points while maintaining open access
2Reliability
If security monitoring is implemented on wireless access points, then security reliability is improved, but device complexity increases
Solution Approach 1:
The system enables mobile devices to self- assess their security status after connecting to access points. Devices automatically report security events (such as malware infections or security compromises) back to the network, which then updates the security reputation database. This self-service approach eliminates the need for complex centralized monitoring infrastructure at each access point
Solution Approach 2:
The patent introduces a security reputation database as an intermediary between access points and devices. Instead of implementing complex direct monitoring between devices and access points, the database mediates by collecting security events, calculating reputation scores, and providing this information to devices before connection, simplifying the overall system architecture
3Measurement precision
If security information is collected from multiple devices, then measurement precision is improved, but loss of information increases
Solution Approach 1:
The system extracts only the necessary security event information from devices without collecting sensitive personal data. It focuses on collecting anonymized security posture information (such as whether malware was detected or security compromises occurred) while leaving private user information behind, thus improving assessment accuracy while minimizing privacy loss
Data Source
AI summary
A computer-implemented method for determining security reputations of wireless network access points may include (1) receiving a unique identifier for a wireless network access point to which a mobile device has connected and security information that identifies the security posture of the mobile device after connecting to the wireless network access point, (2) adding the unique identifier and the security information to a security database, (3) correlating the security information with an additional set of security information that identifies the security posture of an additional mobile device after connecting to the wireless network access point, (4) assigning a security reputation to the wireless network access point, and (5) enabling a requesting mobile device to determine whether to connect to the wireless network access point by providing the security reputation of the wireless network access point to the requesting mobile device. Various other methods, systems, and computer-readable media are also disclosed.


