Rogue Access Point Detection via SSL and URL Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless network security systems struggle to detect rogue access points (APs) in mobile or uncontrolled environments, such as households and public places, making it difficult for individual users to identify and prevent unauthorized access, which poses a significant threat to personal data security.
Innovation Solution
A system and method that utilize a user device and a detection server to identify rogue APs by referencing a rogue AP database, using URL access detection, SSL certificate validity, electronic signature information, and MAC address collection, allowing users to determine if an accessed AP is rogue without the need for external devices, and generating a rogue AP database based on access log information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a separate sensor or network equipment is installed in the internal network to detect rogue APs, then detection capability is improved, but device complexity and installation requirements increase
Solution Approach 1:
The user device performs rogue AP detection functions by itself using its own network stack and processing capabilities, without requiring separate detection sensors or dedicated network equipment. The device leverages its existing resources (CPU, memory, network interface) to execute detection algorithms, thereby improving detection capability while avoiding additional hardware complexity
Solution Approach 2:
The user device is designed to perform multiple functions including both normal network communication and rogue AP detection simultaneously. By making the detection system universal across different device types and network environments, the patent eliminates the need for specialized detection equipment, reducing overall system complexity while maintaining detection effectiveness
2Measurement precision
If existing WIPS or NAC products are used to detect rogue APs, then detection accuracy is improved, but ease of operation deteriorates due to requiring pre-installed sensors and fixed network environments
Solution Approach 1:
The detection system operates autonomously on the user device without requiring pre-installation of separate sensors or configuration of fixed network environments. The device automatically performs detection when needed, making the system easy to use while maintaining high detection accuracy through its self-contained capabilities
Solution Approach 2:
The detection system is designed to be dynamic and adaptable to different network environments rather than requiring a fixed, pre-configured setup. It can operate in various scenarios (home networks, public Wi-Fi, mobile locations) without requiring reinstallation or complex configuration, thereby improving ease of operation while preserving detection accuracy
3Reliability
If multiple detection methods (URL access detection, SSL certificate validation, electronic signature verification, MAC address collection) are used, then detection reliability is improved, but device complexity increases
Solution Approach 1:
The detection system is divided into multiple independent modules, each responsible for a specific detection method (URL access detection, SSL certificate validation, electronic signature verification, MAC address collection). This segmentation allows each module to be implemented and maintained independently, managing complexity while achieving high reliability through the combination of multiple detection approaches
Solution Approach 2:
Multiple detection methods are merged into a unified detection framework that operates within the user device. By combining URL access detection, SSL certificate validation, electronic signature verification, and MAC address collection into a single integrated system, the patent achieves high detection reliability while avoiding the complexity of managing separate systems
Data Source
AI summary
A system for detecting a rogue access point (AP) may include: a user device configured to detect whether an accessed AP is a rogue AP with reference to a rogue AP database based on uniform resource locator (URL) access detection, and determine whether the accessed AP is a rogue AP by further using one or more information of secure sockets layer (SSL) certificate validity information of a predetermined server, electronic signature information of an accessed web page, and media access control (MAC) address collection information of an accessed gateway, if information of the accessed AP is not searched in the rogue AP database; and a detection server configured to share the rogue AP database with the user device. Using the system for detecting a rogue AP, it is possible to detect existence of a rogue AP having an unknown form through access detecting using a one-time URL, and detect address resolution protocol (ARP) spoofing attack.


