Spoofed Management Frames Disconnect Rogue Access Points

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unauthorized access points can compromise network security by intercepting confidential information and consuming bandwidth, and existing methods are inefficient for manually disconnecting them due to the limitations of IEEE 802.11 protocols.

Innovation Solution

The use of spoofed management frames, such as unprotected association and disassociation requests, is employed to automatically disconnect unauthorized access points by triggering security association queries and channel switching, allowing for the disconnection of rogue APs from stations without requiring encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual methods are used to find and shut down unauthorized access points, then network administrators can disconnect rogue APs, but it takes a great deal of time and effort

Engineering Contradiction:
Improvenetwork securityVSAvoidtime and effort to disconnect rogue APs
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary detection of unauthorized access points and pre-configures spoofed management frames in advance. When a rogue AP is detected, the pre-prepared spoofed frames are immediately transmitted to disconnect it, eliminating the need for manual intervention and reducing response time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authorized access point automatically detects unauthorized access points and autonomously transmits spoofed management frames to disconnect them. The system serves itself by implementing the disconnection process without requiring network administrator intervention, thereby saving time and effort.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If direct orders are sent to wireless devices to disconnect from unauthorized APs, then disconnection can be achieved, but communications must occur over secured channels between authenticated devices

Engineering Contradiction:
Improveability to disconnect devices from rogue APsVSAvoidauthentication and channel security requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The authorized access point acts as an intermediary between the network administrator and wireless devices. Instead of requiring direct authenticated communication between the administrator and each device, the authorized AP transmits spoofed management frames that automatically instruct devices to disconnect from rogue APs, simplifying the operation while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of having the network administrator directly communicate with wireless devices to disconnect them, the system inverts the approach by having the authorized access point transmit spoofed disconnection frames to the devices. This reversal eliminates the need for complex authenticated communication channels between administrators and devices.

Inventive Principle:
Principle #13The other way round (Inversion)

3Adaptability or versatility

If unauthorized access points are allowed to operate, then they can provide additional network coverage, but they become privy to confidential information and allow data theft

Engineering Contradiction:
Improvenetwork coverageVSAvoiddata theft and confidential information exposure
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by detecting unauthorized access points and immediately transmitting spoofed management frames to disconnect them before they can compromise network security. This preemptive measure eliminates the harmful effects of rogue APs while maintaining legitimate network coverage through authorized access points.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10129755B2Deauthenticating and disassociating unauthorized access points with spoofed management frames
Publication Date: 2018.11.13 FORTINET INC
  • US10129755B2 patent drawing
  • US10129755B2 patent drawing
  • US10129755B2 patent drawing

AI summary

A spoofed management frame is sent to an unauthorized access point (AP) on behalf of a station from an authorized AP, using a media access control (MAC) address of the station. The spoofed frame triggers a security association (SA) query from an unauthorized AP to reestablish valid communications. An acknowledgment (ACK) frame sent from the client to the unauthorized AP responsive to the SA query request is detected by the AP. A probe response is sent to the client. The probe response includes a channel switching element. The channel switching prevents the client from completing the SA process before a time out.