Wi-Fi Access Point Security Assessment via Crowdsourced BSSID Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges in evaluating the security and connection quality of Wi-Fi access points, particularly those that announce strong security protocols but may have vulnerabilities, and currently, there is no reliable method to distinguish between legitimate and malicious access points or to select the best connection based on quality.
Innovation Solution
A system that collects and reports Wi-Fi data using cellular communication before connection, leveraging multiple user reports to identify security risks and connection quality, and assesses security risks based on persistence, client isolation, and other characteristics, providing users with informed decisions on network selection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users connect to Wi-Fi access points that announce strong security protocols, then security protection is improved, but users remain vulnerable to attacks such as honeypots, ARP cache poisoning, and man-in-the-middle attacks
Solution Approach 1:
The system performs preliminary security assessment of access points before users connect. Mobile devices collect and report data about detected access points to a server, which assesses security risks in advance and provides recommendations to users before connection occurs, preventing exposure to honeypots and malicious APs
Solution Approach 2:
The system implements feedback loops where mobile devices continuously report access point data to the server, and the server returns security assessments and recommendations. This feedback mechanism allows users to make informed decisions about which access points to connect to based on aggregated community data and expert analysis
2Reliability
If users use Virtual Private Network (VPN) for protection on unsecure networks, then security is improved, but connection performance deteriorates due to longer path through VPN server
Solution Approach 1:
The system changes the parameter of security assessment from binary (secure/unsecure based on protocol announcement) to a continuous risk score based on multiple factors including persistence, client isolation, and community reports. This allows users to selectively apply VPN only when necessary, optimizing the balance between security and performance
3Ease of operation
If users rely on security protocol announcements to assess Wi-Fi security, then assessment simplicity is improved, but detection precision deteriorates due to honeypots and compromised access points
Solution Approach 1:
The system creates a universal security assessment framework that works across different access point types and security protocols. The server aggregates data from multiple sources including community reports, persistence analysis, and client isolation detection to provide a comprehensive security assessment that transcends individual protocol limitations
Solution Approach 2:
The system adds new dimensions to security assessment beyond protocol type. It incorporates temporal dimension (persistence over time), spatial dimension (location-based clustering), and community dimension (aggregated user reports), creating a multi-dimensional assessment that greatly improves detection accuracy
4Device complexity
If no security assessment system is implemented, then device complexity is reduced, but loss of information increases as users cannot identify security risks or connection quality differences
Solution Approach 1:
The system enables self-service security assessment where mobile devices automatically collect, report, and receive security assessments without requiring user configuration or expertise. The server handles the complex analysis and provides simple, actionable recommendations to users, maintaining simplicity while eliminating information loss
Data Source
AI summary
A computer-implemented method for security risk assessment of wireless access point devices, the computer-implemented method comprising: receiving signals from one or more wireless access points by two or more mobile wireless devices visiting said access points, obtaining Basic Service Set Identifiers (BSSID) of visited access points and reporting values derived from BSSID and from an identifier of corresponding mobile device to a first database, receiving a request for a security risk assessment of evaluated wireless access point, said request containing value derived from BSSID of the evaluated access point, searching the first database for one or more entries corresponding to the evaluated access point, and processing search results to assess security risk of the evaluated access point, said processing comprises computing a component of said risk dependent on the count of unique identifiers of mobile devices reported for the evaluated access point.


