Rogue Access Point Detection via Network Path Tracing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current rogue access point detection algorithms face challenges such as low detection accuracy, resource wastage, and failure in encrypted connections, especially when rogue access points use Network Address Translation or have separate wired and wireless ports.
Innovation Solution
A computer-implemented method that uses unauthorized frames intercepted by authorized access points to trace the path from a gateway network element to a compromised network element, correlating client and gateway MAC addresses to identify and disable the rogue access point's connection without additional sensors or bandwidth, leveraging un-encrypted portions of connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a legitimate access point tries to associate with a rogue access point for detection, then the detection algorithm can identify the rogue access point, but encrypted authentication protocols used by the rogue access point hinder the effectiveness of detection
Solution Approach 1:
The patent introduces an intermediary approach by having the legitimate access point associate with the rogue access point and then tracing the connection path through network elements using MAC addresses. This intermediary tracing method bypasses the encrypted authentication protocol barrier by operating at the network layer rather than attempting to decrypt wireless authentication.
Solution Approach 2:
The patent replaces the mechanical approach of attempting to break through encrypted authentication protocols with a different mechanism - tracing network layer connections using MAC addresses and neighbor tables. This substitution moves the detection problem from the wireless authentication domain to the network routing domain where encryption is not a barrier.
2Measurement precision
If a dedicated access point runs in rogue detector mode to listen to ARP messages and match rogue access point's network address, then rogue access points can be detected, but using an access point solely for detection wastes resources that customers prefer to use for other purposes
Solution Approach 1:
The patent makes the legitimate access point multi-functional by enabling it to perform both its primary wireless access function and the secondary rogue detection function. The same access point infrastructure is used for both providing network access to legitimate clients and for detecting rogue access points, eliminating the need for dedicated detection hardware.
Solution Approach 2:
The patent enables the legitimate access point to self-serve the detection function by having it associate with rogue access points and generate the necessary detection data (MAC addresses, connection information) that the management entity then uses for tracing and identification. The detection capability is built into the existing access points rather than requiring separate dedicated devices.
3Measurement precision
If another algorithm uses a legitimate access point as a client and tries to associate with the rogue access point, then the rogue access point's connection to the network can be identified, but this method fails when the rogue access point uses Network Address Translation service
Solution Approach 1:
The patent moves the detection problem from the wireless dimension (where NAT obscures the rogue access point's identity) to the network dimension by tracing connections through network elements using MAC addresses and neighbor tables. This dimensional shift allows detection to succeed even when wireless-layer address translation is employed.
Data Source
AI summary
A computer-implemented method is provided for a management entity to detect where a rogue access point is connected to the network infrastructure. The management entity receives from a wireless network controller an indication of an unauthorized frame wirelessly intercepted by an authorized access point. The unauthorized frame carries data between a rogue access point and a wireless client device. The rogue access point is connected to a compromised network element in a managed network at a compromised port of the compromised network element. The management entity extracts a client network address and a gateway network address from the indication of the unauthorized frame. The management entity traces a path through the managed network from a gateway network element associated with the gateway network address to the compromised network element. The management entity determines the compromised port in the compromised network element at which the rogue access point is connected.


