Anti-pharming Module for Wireless Networks at Pre-IP State

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless computer networks are vulnerable to pharming attacks during the pre-IP state, where malicious computers can redirect data communications by impersonating DHCP servers, compromising user security and confidentiality.

Innovation Solution

An anti-pharming module is implemented in user computers to monitor data communications and detect suspicious activity by distinguishing between legitimate DHCP server responses and responses from malicious wireless stations, using IEEE 802.11 standards to identify and prevent pharming attacks before the networking software is fully configured.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless data transmission is used to provide freedom and convenience, then ease of operation and accessibility are improved, but security vulnerabilities and exposure to malicious attacks worsen

Engineering Contradiction:
Improvewireless connectivityVSAvoidpharming attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The anti-pharming module performs preliminary monitoring and validation of DHCP packets before the system becomes fully operational. It checks the source of DHCP responses during the pre-IP state to prevent malicious redirection before it can take effect, thereby maintaining wireless convenience while preemptively blocking security threats.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If encryption is applied to protect wireless data communication, then security is improved, but it is still insufficient to protect against pharming attacks

Engineering Contradiction:
Improvedata transmission securityVSAvoidpharming attack susceptibility
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The anti-pharming module acts as an intermediary layer between the wireless network interface and the operating system. It monitors and validates DHCP packets at the driver level, checking whether responses come from legitimate access points or malicious wireless stations, thereby providing security beyond standard encryption mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If the system monitors all data communications to detect malicious activity, then security detection capability is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvemalicious activity detectionVSAvoidanti-pharming module complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The anti-pharming module focuses monitoring efforts on specific critical packets during the pre-IP state, particularly DHCP DISCOVER and DHCP OFFER packets. Rather than analyzing all network traffic equally, it applies specialized validation only to these high-risk communication phases, maintaining high detection precision while limiting complexity to essential functions.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8191143B1Anti-pharming in wireless computer networks at pre-IP state
Publication Date: 2012.05.29 TREND MICRO INC
  • US8191143B1 patent drawing
  • US8191143B1 patent drawing
  • US8191143B1 patent drawing

AI summary

Anti-pharming techniques in wireless computer networks at pre-IP state are disclosed. A user computer connecting to a wireless computer network may include an anti-pharming module configured to monitor data communications to and from a wireless access point of the wireless computer network. The anti-pharming module may be configured to determine if data communication going in a direction from the wireless access point to the user computer originated from a wireless station rather than a server configured to dynamically provide network addresses to computers connecting to the wireless computer network. The wireless station may be deemed a malicious computer perpetrating a pharming attack when it originated the data communication and is responding to a request to obtain network address previously sent by the user computer.