Access Point RSN IE Verification for DoS Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Unsolicited probe responses in Wi-Fi networks are vulnerable to Denial of Service (DoS) attacks, where rogue access points send incorrect Robust Security Network Information Elements (RSN IE) to client devices, causing authentication failures and service interruptions.
Innovation Solution
Access points detect such attacks by comparing RSN IE parameters with their own security profiles and disable unsolicited probe responses, switching to alternative authentication methods like Fast Initial Link Setup (FILS) discovery to mitigate the attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If unsolicited probe responses are used for AP discovery, then client battery life is extended and airtime efficiency is improved, but the network becomes vulnerable to DoS attacks with incorrect RSN IE
Solution Approach 1:
The patent applies preliminary action by having the access point verify RSN IE parameters in advance before processing unsolicited probe responses. The AP compares received RSN IE against its own security profile configuration, and only processes responses with matching parameters. This pre-verification mechanism prevents malicious responses from causing authentication failures while maintaining the efficiency benefits of unsolicited probe responses.
2Reliability
If RSN IE verification is implemented in unsolicited probe responses, then DoS attack resistance is improved, but device complexity increases
Solution Approach 1:
The patent applies local quality by implementing verification only in the specific context of unsolicited probe response processing, rather than throughout the entire authentication system. The RSN IE parameter comparison is performed locally at the probe response handling stage, focusing computational resources only where needed. This targeted approach provides attack resistance without unnecessarily increasing overall device complexity.
3Reliability
If incorrect RSN IE is processed, then client authentication fails causing service interruption, but implementing verification increases processing overhead
Solution Approach 1:
The patent applies the extraction principle by isolating the verification logic specifically for RSN IE parameters in unsolicited probe responses. Rather than implementing comprehensive verification of all message components, the system extracts and verifies only the critical RSN IE security parameters against the AP's profile. This focused verification prevents authentication failures from incorrect security information while minimizing processing overhead by avoiding unnecessary verification of non-critical elements.
Data Source
AI summary
Examples of techniques for handling unsolicited probe responses are disclosed. In an example, occurrence of an attack on an access point (AP) in an enterprise Wireless Local Area Network (WLAN) is detected based on an unsolicited probe response and Robust Security Network Information Element (RSN IE). Responsive to detecting the attack, unsolicited probe responses at the AP is disabled. Further, Fast initial Link Setup (FILS) discovery at the AP is enabled.


