Rogue Wireless Access Point Detection via Sensor Node Triangulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Rogue or decoy wireless access points (WAPs) can be physically placed in geospatial locations to spoof legitimate networks, posing a significant security risk by allowing malicious actors to gain unauthorized access and perform harmful actions, as existing technologies lack effective methods for detecting and responding to such threats in real-time.

Innovation Solution

A system and method for incident detection and response (IDR) using WAP data from fixed and agent-based sensor nodes, which involves performing a wireless site survey to identify rogue WAPs by analyzing Service Set Identifier (SSID), Basic Service Set Identifier (BSSID), Receive Signal Strength Indicator (RSSI), channel number, encryption type, and hidden status, and classifying WAPs into trusted and malicious categories to determine their location and mitigate risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless access points are deployed to provide network coverage, then network connectivity is improved, but security vulnerabilities increase due to potential rogue WAPs

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system continuously monitors the wireless environment by collecting WAP data from multiple sensor nodes and provides feedback about detected rogue access points. The IDR server analyzes RSSI values, SSID/BSSID matching, and spatial relationships to identify suspicious WAPs and alerts administrators, creating a closed-loop security system that responds to threats in real-time.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Fixed sensor nodes and agent-based sensor nodes act as intermediaries between legitimate WAPs and user devices. These sensor nodes collect and analyze WAP data, serving as a security layer that identifies rogue access points before users can connect to them. The sensor nodes mediate the wireless environment by filtering and reporting on WAP authenticity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Area of stationary object

If signal strength is increased to extend WAP coverage, then network reach is improved, but detection accuracy of rogue WAPs deteriorates due to signal interference

Engineering Contradiction:
Improvecoverage areaVSAvoidrogue WAP detection accuracy
Core Design Contradiction:
Area of stationary objectVSMeasurement precision

Solution Approach 1:

The system divides the wireless monitoring task into multiple segments by deploying several fixed sensor nodes at different locations throughout the facility. Each sensor node collects WAP data from its local area, and the IDR server aggregates these segmented measurements. This segmentation allows the system to maintain detection accuracy even when individual WAP signals are strong, as multiple nodes can triangulate and identify rogue WAPs through comparative analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds spatial dimensionality to WAP detection by collecting RSSI measurements from multiple sensor nodes positioned at different locations. Instead of relying on a single point measurement that may be affected by signal strength variations, the system uses multi-dimensional spatial data to triangulate the location of rogue WAPs and distinguish them from legitimate ones based on their spatial signal patterns.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If manual monitoring of wireless networks is performed, then detection thoroughness is improved, but response time deteriorates due to human limitations

Engineering Contradiction:
Improvedetection thoroughnessVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs self-service monitoring by automatically collecting WAP data from sensor nodes, analyzing the data to identify rogue access points, and generating alerts without requiring continuous human intervention. The IDR server autonomously processes SSID/BSSID matching, RSSI analysis, and spatial relationship calculations, enabling the network to monitor itself and respond to threats automatically.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system accelerates the detection process by using computational power to rapidly analyze WAP data at speeds far exceeding human capabilities. The IDR server processes multiple data streams from numerous sensor nodes simultaneously, performing complex comparisons and pattern recognition in real-time, thereby accelerating threat detection from what would be a slow manual process to an instantaneous automated one.

Inventive Principle:
Principle #38Strong oxidants (Accelerated oxidation)

Data Source

PatentUS11917411B1Detecting rogue wireless access points in geospatial locations
Publication Date: 2024.02.27 RAPID7 INC
  • US11917411B1 patent drawing
  • US11917411B1 patent drawing
  • US11917411B1 patent drawing

AI summary

Disclosed herein are methods, systems, and processes to detect rogue wireless access points and determine their approximate location in a geospatial location. Wireless access point data collected from wireless access points by fixed sensor nodes and agent-based sensor nodes in a geospatial location is received. A wireless site survey is performed at the geospatial location based on the wireless access point data. Based on the wireless site survey, an approximate location of a rogue wireless access point at the geospatial location is determined.