Rogue Access Point Detection via Scanning and Association Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless networks are vulnerable to unauthorized access points, known as rogue access points, which can allow network intruders to access confidential information without physical proximity to the company's building, posing a significant security risk.

Innovation Solution

A system comprising a detecting station and a device that scans for access points and associated stations, compiles lists, and determines whether each access point is rogue by checking pre-authorization, connection status, and client association, informing operators to mitigate potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless network is deployed to enable remote access, then network accessibility and convenience are improved, but vulnerability to rogue access points and security risks increases

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary scanning and identification of access points before they can be used for unauthorized access. By proactively detecting and listing all access points in the network scope, the system can compare them against authorized lists and identify rogue access points before they compromise security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors the network environment, compares detected access points against authorized lists, and provides feedback about potential security threats. This closed-loop approach enables ongoing security assessment and alerting of operators about rogue access points

Inventive Principle:
Principle #23Feedback

2Reliability

If access point scanning and monitoring is implemented to detect rogue APs, then network security is improved, but system complexity and detection difficulty increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the security monitoring function into separate modules: a scanning module that detects access points, a list management module that maintains authorized lists, and a comparison module that identifies rogue APs. This segmentation allows each component to perform its specific function independently, reducing overall system complexity while maintaining security effectiveness

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7561554B2Method and system for detecting rogue access points and device for identifying rogue access points
Publication Date: 2009.07.14 HON HAI PRECISION INDUSTRY CO LTD
  • US7561554B2 patent drawing
  • US7561554B2 patent drawing
  • US7561554B2 patent drawing

AI summary

A system for detecting rogue access points (APs) includes a detecting station (130) and a device for identifying rogue access points (110). The detecting station scans access points and stations associated with the access points, in order to compile an AP list and an association list within the scope of the detecting station, and transmits the AP list and the association list. The device for identifying rogue access points (110) includes a receiving module (112) and a determining module (114). The receiving module receives the AP list and the association list. The determining module determines whether each access point in the AP list is a rogue access point. A related method is also provided.