Server Public Key Validation for Wireless Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional wireless intrusion detection systems fail to detect attacks targeting Transport Layer Security (TLS) tunnels, particularly those that spoof network authentication servers, leading to false negatives and false positives, and do not effectively validate server public keys, making them susceptible to credential theft.

Innovation Solution

A detection system that monitors network frames for a server public key, checks its validity, and alerts for invalid authentications, allowing for password resets or device reconfiguration, specifically designed to identify spoofed access points by verifying the public key in the Server Hello message within the TLS tunnel establishment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional wireless intrusion detection methodology is applied to detect attacks, then the detection coverage is improved, but the signature becomes complex and the alarm is prone to false negatives and false positives

Engineering Contradiction:
Improvedetection accuracyVSAvoidsignature complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts and focuses on a single critical element - the server public key validation in the Server Hello message - rather than attempting to detect attacks through complex multi-parameter signatures. By isolating this key validation step, the system achieves reliable attack detection without the complexity and error-proneness of traditional signature-based approaches.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the authentication process into distinct phases, focusing detection efforts on the specific moment when the server public key is presented in the Server Hello message. This segmentation allows the detection system to concentrate on validating this critical element independently, rather than attempting to analyze the entire authentication flow with complex signatures.

Inventive Principle:
Principle #1Segmentation

2Difficulty of detecting and measuring

If conventional wireless intrusion detection systems monitor authentication traffic, then attack detection capability is improved, but false positives and false negatives increase due to complex signature requirements

Engineering Contradiction:
Improveattack detection capabilityVSAvoidalarm accuracy
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent introduces a detection system that acts as an intermediary, monitoring the Server Hello message independently of the client-server authentication exchange. This intermediary detection layer validates the server public key without interfering with the normal authentication process, providing reliable attack detection without the false positives and negatives associated with complex signature-based monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The detection system performs preliminary validation of the server public key in the Server Hello message before the actual authentication credentials are exchanged. By detecting attacks at this preliminary stage through public key validation, the system prevents false positives that would occur if monitoring attempted to analyze the entire authentication process including credential exchange.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If clients are configured to authenticate server public keys, then security against spoofing attacks is improved, but client configuration complexity and potential connection failures increase

Engineering Contradiction:
Improvespoofing attack resistanceVSAvoidclient configuration simplicity
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements self-service security by enabling the detection system to automatically validate server public keys without requiring clients to be configured with certificate authorities or public key validation settings. The detection system performs this validation autonomously by monitoring the Server Hello message, providing spoofing attack resistance while maintaining client configuration simplicity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The detection system serves as an intermediary that performs public key validation on behalf of clients that lack this capability. By monitoring the Server Hello message and validating the server public key independently, the intermediary provides security against spoofing attacks without requiring changes to client configuration, thus maintaining ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8756690B2Extensible authentication protocol attack detection systems and methods
Publication Date: 2014.06.17 EXTREME NETWORKS INC
  • US8756690B2 patent drawing
  • US8756690B2 patent drawing
  • US8756690B2 patent drawing

AI summary

The present disclosure provides systems and methods for detecting attacks against authentication mechanisms that generate Transport Layer Security (TLS) tunnels using a server public key. Such attacks can include misconfigured wireless local area network (WLAN) clients that fail to authenticate the server public key prior to creating the TLS tunnels and exchanging credentials. In an exemplary embodiment, an intrusion detection system (IDS) or intrusion prevention system (IPS) is aware of the server public key and monitors for authentication handshakes to detect invalid keys.