Wireless AP Intrusion Detection Broadcast
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Intrusion detection systems in wireless communication networks face challenges in efficiently disseminating information about illegal devices and incorrectly detecting legitimate access points, leading to unnecessary disconnection of clients and increased reconnection time.
Innovation Solution
Access points proactively broadcast intrusion detection information, including identifiers of illegal devices and the AP performing containment, using beacon frames and encryption to ensure secure communication, allowing other APs to determine and respond to malicious activity while minimizing false positives.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an AP performs containment on a detected illegal device, then network security is improved, but false positives may cause legitimate devices to be disconnected
Solution Approach 1:
The patent implements a feedback mechanism where APs broadcast containment information and receive responses from other APs to verify the illegal status of detected devices. This allows legitimate devices to be identified and excluded from containment actions, reducing false positives while maintaining security.
Solution Approach 2:
The system performs preliminary verification by broadcasting containment information before executing containment actions. Other APs can respond to verify the device status, ensuring that containment is only applied to genuinely illegal devices and not legitimate ones.
2Reliability
If an AP disconnects clients from a detected illegal device, then security is enhanced, but reconnection time increases when the detection is incorrect
Solution Approach 1:
The feedback mechanism allows APs to verify the legality of devices before disconnection. By receiving responses from other APs confirming the illegal status, the system avoids unnecessary disconnections of legitimate devices, thereby preventing extended reconnection times.
Solution Approach 2:
The system takes preliminary anti-action by verifying device status through broadcasting and receiving responses before executing disconnection. This prevents the harmful action of disconnecting legitimate devices, avoiding the need for time-consuming reconnection processes.
3Speed
If intrusion detection information is broadcast to all APs, then response time to malicious activity is reduced, but network traffic increases
Solution Approach 1:
The patent extracts only the necessary containment information (device identifiers and detecting AP identifier) and broadcasts it selectively to other APs. This minimizes the amount of network traffic while still enabling rapid response to malicious activity across the network.
Data Source
AI summary
Implementations of the present disclosure relate to intrusion detection information. A method comprises detecting, by an access point (AP), at least one device in a wireless communication network to be an illegal device. The method also comprises obtaining, by the AP, intrusion detection information related to the at least one device, the intrusion detection information comprising at least one identifier of the at least one device.


