Rogue Access Point Detection via Pre-Detection Suppression
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting rogue access points in communication networks are either passive, limited in range, or prone to missing devices in uncovered areas, posing security threats due to their inefficiencies.
Innovation Solution
A method involving a probing unit that sends a pre-detection message to associated access points, informing them not to respond to probe requests, and broadcasting probe requests with proprietary information to detect rogue access points based on their responses, ensuring active detection across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If client devices scan for beacons from a rogue device, then the detection method is simple to implement, but the detection is passive and delayed because the client device has to wait for a beacon
Solution Approach 1:
The system sends a pre-detection message to authorized access points before the actual probe request is broadcast. This preliminary action instructs authorized access points to suppress their responses during the detection phase, enabling the probing unit to receive responses only from rogue access points, thereby eliminating detection delay while maintaining implementation simplicity
2Area of stationary object
If radio frequency scanning is employed by the wireless communication network, then the detection coverage is comprehensive, but there is a possibility of missing rogue devices in areas not covered by sensors
Solution Approach 1:
The rogue access point itself is utilized to reveal its presence. By broadcasting probe requests and analyzing responses from access points, the system enables the rogue device to effectively identify itself through its unauthorized responses, eliminating detection gaps without requiring extensive sensor deployment
3Ease of operation
If access points scan for the rogue device, then the detection can be performed by network infrastructure, but the scanning range is limited to a very short range
Solution Approach 1:
The system transitions from traditional unidirectional scanning to a multi-dimensional detection approach by broadcasting probe requests across multiple communication dimensions and analyzing responses from multiple access points simultaneously, thereby extending the effective detection range beyond the limitations of single access point scanning
4Reliability
If the probing unit broadcasts probe requests to all access points, then active detection is achieved, but authorized access points may respond and create false positives
Solution Approach 1:
A pre-detection message is sent to authorized access points before the probe request broadcast. This preliminary anti-action instructs authorized access points to suppress their responses during the detection phase, preventing false positives while maintaining detection accuracy. The complexity is managed through standardized message protocols
Data Source
AI summary
A method and apparatus for detecting a rogue access point in a communication network is described herein. The method includes a probing unit sending a pre-detection message to an associated access point in the communication network. The pre-detection message indicates a start of rogue access point detection mode and informs the associated access point not to respond to probe requests following the pre-detection message. The method further includes the probing unit broadcasting probe requests in the communication network. The probing unit detect that one or more of the plurality of access points is the rogue access point based on receiving a probe response in reply to the broadcasted probe request from the rogue access point. A method for detecting a rogue access point includes broadcasting a probe request with a proprietary information bit and detecting the rogue access point based on receiving a probe response for the broadcasted probe request.


