Location-Based Reputation System for Link-Layer Wireless Attack Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security systems lack reliable techniques to verify the legitimacy and identity of wireless access points, making devices vulnerable to link-layer wireless attacks, such as spoofing, where malicious devices mimic known access points, allowing attackers to intercept network traffic.

Innovation Solution

A system and method for disseminating location-based reputations for link-layer wireless attacks, which includes modules for receiving and generating reports on detected attacks, allowing clients to query a server for reputation information before connecting to a wireless access point, and performing security actions based on received reputations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If computing devices store and automatically reconnect to known wireless access points, then connection efficiency and speed are improved, but vulnerability to link-layer wireless attacks increases

Engineering Contradiction:
Improveconnection speedVSAvoidsecurity reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system performs preliminary actions by collecting attack data at locations before devices attempt to connect to wireless access points. A reputation score is pre-calculated for each location based on detected attacks, allowing devices to proactively assess security risks before establishing connections, thus preventing vulnerable connections while maintaining fast reconnection for safe locations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a server as an intermediary between computing devices and wireless access points. This server collects attack data, generates location-based reputation scores, and provides security assessments to devices. The intermediary enables devices to make informed connection decisions without directly implementing complex attack detection mechanisms, balancing security enhancement with device capability constraints.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If devices implement link-layer attack detection capabilities, then security is improved, but device complexity and resource requirements increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddetection capability complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The server acts as an intermediary that centralizes the complex attack detection and analysis functions. Individual devices only need to report basic connection status and receive pre-processed reputation scores, rather than implementing full attack detection stacks. This distributes the computational burden to the server while keeping device complexity minimal.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service security by allowing devices to autonomously query location reputation scores and make connection decisions based on pre-analyzed data. Devices don't need to implement complex detection algorithms themselves; instead, they consume ready-made security assessments from the server, making security accessible to resource-constrained devices.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If a centralized server collects and processes attack data from multiple devices, then security intelligence accuracy is improved, but network communication overhead increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoidnetwork communication energy
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The system uses periodic action by having devices report attack data at scheduled intervals rather than continuously. The server periodically aggregates reports from multiple devices, updates location reputation scores, and makes this information available for querying. This periodic approach achieves accurate security intelligence through accumulated data while minimizing continuous network communication overhead.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The server merges attack data from multiple devices into consolidated location-based reputation scores. By combining reports from numerous devices observing the same location, the system achieves high detection accuracy through data aggregation. This merging approach efficiently utilizes network communication by transmitting consolidated intelligence rather than individual device reports.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10178122B1Systems and methods for disseminating location-based reputations for link-layer wireless attacks
Publication Date: 2019.01.08 GEN DIGITAL INC
  • US10178122B1 patent drawing
  • US10178122B1 patent drawing
  • US10178122B1 patent drawing

AI summary

The disclosed computer-implemented method for disseminating location-based reputations for link-layer wireless attacks may include (i) receiving, at a server from a first wireless client, a wireless-attack report for a location that includes (a) information that indicates that the first wireless client detected a link-layer wireless attack (e.g., a wireless-access-point spoofing attack or a deauthentication attack) at the location or (b) information that indicates that the first wireless client did not detect any link-layer wireless attacks at the location, (ii) using, at the server, the wireless-attack report to generate a reputation for link-layer wireless attacks for the location, (iii) receiving, at the server from a second wireless client, a request for the reputation of the location, and (iv) responding to the request with the reputation of the location. Various other methods, systems, and computer-readable media are also disclosed.