Access Point QoS Null Frame Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless communication networks face challenges in security and robustness due to QoS Null frame-based Denial of Service (DoS) attacks, which can disrupt network performance by manipulating queue depth and UL OFDMA information, leading to unfair resource allocation and denial of service opportunities.

Innovation Solution

Implement a method to detect and mitigate QoS Null Frame DoS attacks by monitoring suspicious events, verifying peer authenticity through defined tests, and ignoring malicious QoS Null frames to prevent disruption, utilizing access points and network infrastructure devices to manage queue sizes and UL OFDMA capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If QoS Null frames are used for quality of service management, then network performance and power saving are improved, but the network becomes vulnerable to DoS attacks and resource allocation manipulation

Engineering Contradiction:
Improvenetwork performanceVSAvoidsecurity against DoS attacks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an intermediary verification mechanism where the access point validates QoS Null frame parameters against previously established profile information before accepting them. This intermediary validation layer prevents direct manipulation of queue depth and UL OFDMA fields while maintaining legitimate QoS functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by establishing a profile of legitimate QoS Null frame parameters before actual communication occurs. This pre-established profile serves as a reference for subsequent validation, allowing the access point to detect and reject malicious frames that deviate from expected patterns.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the access point implements strict verification of QoS Null frames, then security against attacks is improved, but false positives may occur and network stability is reduced

Engineering Contradiction:
Improvesecurity verificationVSAvoidnetwork stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent employs parameter changes by dynamically adjusting verification thresholds and profile parameters based on network conditions and historical data. This allows the system to adapt its verification stringency, reducing false positives during normal operation while maintaining security against actual attacks.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements feedback mechanisms where the access point continuously monitors network behavior and adjusts the QoS Null frame verification profiles accordingly. This feedback loop allows the system to learn from actual network conditions and refine its detection algorithms, reducing erroneous blocking of legitimate frames.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11490290B2Protecting 802.11 ax networks from QOS Null attacks
Publication Date: 2022.11.01 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11490290B2 patent drawing
  • US11490290B2 patent drawing
  • US11490290B2 patent drawing

AI summary

A method for protecting 802.11 ax networks includes receiving, by an access point, a plurality of Single User (SU) Quality of Service (QOS) NULL frames from a station, tracking, by the access point as the plurality of SU QOS NULL frames are received, a variable in one or more of the plurality of SU QOS NULL frames, determining, by the access point and based on tracking the variable, the station is suspicious, sending, by the access point and in response to determining the station is suspicious, a request to check a status of the variable, determining, by the access point and based on a response to the request, the station is under attack, and flagging, by the access point, the station as under an attack.