Anomalous Access Point Detection via Client Reports
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in detecting and mitigating 'evil twin' access points, which impersonate legitimate access points to steal data or deliver malicious payloads, especially in large corporate environments with numerous access points.
Innovation Solution
A fraud detection service that utilizes client devices to report visible access points and their locations, comparing these reports to expected access point positions to identify anomalies, such as evil twin access points, and trigger corrective actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional signal monitoring methods are used to detect evil twin access points, then detection capability is improved, but cost and system complexity increase significantly
Solution Approach 1:
The patent makes client devices (smartphones, laptops) perform the detection work themselves by having them scan for access points and report their observations to the fraud detection service, eliminating the need for expensive dedicated signal monitoring hardware while leveraging the computational resources already present in user devices
Solution Approach 2:
The system uses multi-functional client devices that serve both as end-user computing devices and as distributed detection sensors, allowing these devices to perform their primary computing functions while simultaneously contributing to network security by detecting evil twin access points
2Measurement precision
If comprehensive access point monitoring is implemented across large corporate environments, then detection accuracy is improved, but the number of access points to monitor and system resource requirements increase
Solution Approach 1:
The system divides the monitoring task into segments performed by multiple client devices distributed throughout the corporate environment, with each device independently scanning and reporting access points in its local area, collectively providing comprehensive coverage without requiring centralized monitoring of all access points simultaneously
Solution Approach 2:
The system adds the dimension of client device location data to the detection process, using geographic positioning information from multiple devices to triangulate and verify access point locations, thereby improving detection accuracy through spatial distribution rather than increasing the number of monitored access points
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Disclosed in some examples are methods, systems, devices, and machine-readable mediums that detect evil twin and other anomalous access points in an IT infrastructure by detecting access points that are not in their expected locations based upon an analysis of access point reports from one or more computing devices.