Endpoint Network Verification for Rogue Access Point Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security systems fail to reliably verify the legitimacy of wireless networks, making devices vulnerable to attacks where malicious devices can mimic known networks, putting users at risk due to lack of awareness and protection solutions.

Innovation Solution

A system and method that detects requests from endpoint devices to connect to wireless networks, establishes a connection with an illegitimate network that mimics the requested network, determines vulnerability to attacks, and facilitates security actions to protect the device, such as increasing security protocols or removing the network from trusted connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional network security systems allow automatic reconnection to known wireless networks, then device connectivity and user convenience are improved, but devices become vulnerable to attacks by malicious devices mimicking legitimate networks

Engineering Contradiction:
Improveautomatic reconnection capabilityVSAvoidvulnerability to network attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification of wireless network legitimacy before allowing automatic reconnection. A network verification service checks whether a wireless network is legitimate or illegitimate before the endpoint device establishes a connection, preventing devices from automatically connecting to malicious networks that mimic legitimate ones.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A network verification service acts as an intermediary between the endpoint device and the wireless network. This service receives connection requests, verifies the legitimacy of the target network, and only then permits the connection to proceed, thereby protecting devices from attacking malicious networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users are provided with more security verification options, then protection against network attacks is improved, but system complexity and user configuration burden increase

Engineering Contradiction:
Improvenetwork security verificationVSAvoidsecurity configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The endpoint device automatically performs security verification by communicating with the network verification service without requiring user intervention. The device autonomously determines whether a wireless network is legitimate or illegitimate and adjusts its connection behavior accordingly, eliminating the need for users to manually configure security settings.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The network verification service provides a universal security verification mechanism that works across different wireless networks and endpoint devices. This single service handles multiple verification functions including legitimacy checking, attack detection, and connection authorization, simplifying the overall security architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10348755B1Systems and methods for detecting network security deficiencies on endpoint devices
Publication Date: 2019.07.09 GEN DIGITAL INC
  • US10348755B1 patent drawing
  • US10348755B1 patent drawing
  • US10348755B1 patent drawing

AI summary

The disclosed computer-implemented method for detecting network security deficiencies on endpoint devices may include (i) detecting, at a network device, a request from an endpoint device to automatically connect to a wireless network, (ii) establishing, via the network device, a network connection between the endpoint device and a wireless network that appears to be the wireless network requested by the endpoint device but is not actually the requested wireless network, (iii) determining, based on establishing the network connection between the endpoint device and the wireless network that appears to be the requested wireless network, that the endpoint device is vulnerable to network attacks, and then (iv) facilitating, via the network connection, a security action on the endpoint device to protect the endpoint device against the network attacks. Various other methods, systems, and computer-readable media are also disclosed.