Spoofed Probe Responses Block Unauthorized Access Points

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unauthorized access points can connect to wireless devices without authorization, compromising network security and bandwidth, as existing techniques fail to prevent initial connections effectively.

Innovation Solution

Identifying unauthorized access points through periodic scans and broadcasting spoofed probe responses with channel switching elements to prevent association with wireless stations, allowing authorized access points to initiate connections instead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If unauthorized access points are allowed to broadcast beacons, then wireless devices can discover and connect to them, but network security is compromised and data theft can occur

Engineering Contradiction:
ImproveWireless device connection capabilityVSAvoidNetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system applies preliminary anti-action by detecting unauthorized access points before they can establish connections with wireless devices. The network administrator configures the system with authorized AP identifiers, and the system proactively identifies and blocks rogue APs by preventing association between wireless devices and unauthorized APs, thus securing the network before threats can materialize

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system introduces an intermediary component that sits between wireless devices and access points. This intermediary monitors beacon broadcasts and probe requests, verifies whether target APs are authorized, and either permits or blocks association attempts. The intermediary acts as a security gatekeeper that allows legitimate connections while blocking unauthorized ones

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If unauthorized access points are introduced to improve coverage in poor coverage areas, then wireless connectivity is enhanced, but network policies and bandwidth management are violated

Engineering Contradiction:
ImproveWireless coverage areaVSAvoidNetwork bandwidth theft
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The system implements feedback mechanisms where wireless devices report detected access points to the network administrator. The administrator reviews these reports, identifies unauthorized APs, and configures the system to block them. The system continuously monitors for new unauthorized APs and updates blocking rules accordingly, creating a closed-loop feedback system that adapts to changing network conditions

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10785703B1Preventing connections to unauthorized access points with channel switch announcements
Publication Date: 2020.09.22 FORTINET INC
  • US10785703B1 patent drawing
  • US10785703B1 patent drawing
  • US10785703B1 patent drawing

AI summary

An unauthorized access point is identified during a periodic scan on the wireless network and storing a MAC address for the unauthorized access point and monitored for connection attempts. In response to an attempt by the unauthorized access point to connect to a wireless station or in response to the wireless station attempt to connect to the unauthorized access point, a spoofed probe response is transmitted to prevent a connection. The probe response can include a channel switching element and the MAC address of the unauthorized access point.