Rogue Access Point Detection via Pre-Detection Suppression

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting rogue access points in communication networks are either passive, limited in range, or prone to missing devices in uncovered areas, posing security threats due to their inefficiencies.

Innovation Solution

A method involving a probing unit that sends a pre-detection message to associated access points, informing them not to respond to probe requests, and broadcasting probe requests with proprietary information to detect rogue access points based on their responses, ensuring active detection across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If client devices scan for beacons from a rogue device, then the detection method is simple to implement, but the detection is passive and delayed because the client device has to wait for a beacon

Engineering Contradiction:
Improveease of implementationVSAvoiddetection delay
Core Design Contradiction:
Ease of manufactureVSLoss of time

Solution Approach 1:

The system sends a pre-detection message to authorized access points before the actual probe request is broadcast. This preliminary action instructs authorized access points to suppress their responses during the detection phase, enabling the probing unit to receive responses only from rogue access points, thereby eliminating detection delay while maintaining implementation simplicity

Inventive Principle:
Principle #10Preliminary action

2Area of stationary object

If radio frequency scanning is employed by the wireless communication network, then the detection coverage is comprehensive, but there is a possibility of missing rogue devices in areas not covered by sensors

Engineering Contradiction:
Improvedetection coverage areaVSAvoiddetection reliability
Core Design Contradiction:
Area of stationary objectVSReliability

Solution Approach 1:

The rogue access point itself is utilized to reveal its presence. By broadcasting probe requests and analyzing responses from access points, the system enables the rogue device to effectively identify itself through its unauthorized responses, eliminating detection gaps without requiring extensive sensor deployment

Inventive Principle:
Principle #25Self-service

3Ease of operation

If access points scan for the rogue device, then the detection can be performed by network infrastructure, but the scanning range is limited to a very short range

Engineering Contradiction:
Improvenetwork infrastructure operationVSAvoiddetection range
Core Design Contradiction:
Ease of operationVSLength of stationary object

Solution Approach 1:

The system transitions from traditional unidirectional scanning to a multi-dimensional detection approach by broadcasting probe requests across multiple communication dimensions and analyzing responses from multiple access points simultaneously, thereby extending the effective detection range beyond the limitations of single access point scanning

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Reliability

If the probing unit broadcasts probe requests to all access points, then active detection is achieved, but authorized access points may respond and create false positives

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A pre-detection message is sent to authorized access points before the probe request broadcast. This preliminary anti-action instructs authorized access points to suppress their responses during the detection phase, preventing false positives while maintaining detection accuracy. The complexity is managed through standardized message protocols

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS8549634B2Method and apparatus for detecting a rogue access point in a communication network
Publication Date: 2013.10.01 EXTREME NETWORKS INC
  • US8549634B2 patent drawing
  • US8549634B2 patent drawing
  • US8549634B2 patent drawing

AI summary

A method and apparatus for detecting a rogue access point in a communication network is described herein. The method includes a probing unit sending a pre-detection message to an associated access point in the communication network. The pre-detection message indicates a start of rogue access point detection mode and informs the associated access point not to respond to probe requests following the pre-detection message. The method further includes the probing unit broadcasting probe requests in the communication network. The probing unit detect that one or more of the plurality of access points is the rogue access point based on receiving a probe response in reply to the broadcasted probe request from the rogue access point. A method for detecting a rogue access point includes broadcasting a probe request with a proprietary information bit and detecting the rogue access point based on receiving a probe response for the broadcasted probe request.