Home Wi-Fi Gateway Detection of Drive-By Hijack Attempts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Home Wi-Fi networks are vulnerable to drive-by hijack attacks where attackers gain unauthorized access from outside the premises, posing risks to sensitive information and IoT devices.

Innovation Solution

A war driving activity correlation system that includes a processor and memory to analyze Wi-Fi device reports, determine attacker routes, and generate mitigation actions, such as blacklisting suspicious MAC addresses, using machine learning to distinguish between benign and malicious devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If home Wi-Fi networks provide Internet access within home premises, then network functionality is improved, but vulnerability to drive-by hijack attacks increases

Engineering Contradiction:
Improvenetwork functionalityVSAvoidvulnerability to attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary detection of suspicious devices attempting to connect to the Wi-Fi network before full unauthorized access occurs. The home gateway system identifies and reports suspicious connection attempts to the war driving activity correlation system, enabling preemptive security measures to be taken before the attacker can compromise network devices or steal sensitive information.

Inventive Principle:
Principle #10Preliminary action

2Area of stationary object

If Wi-Fi signals extend beyond home premises, then network coverage is improved, but detectability by attackers increases

Engineering Contradiction:
Improvenetwork coverageVSAvoiddetectability by attackers
Core Design Contradiction:
Area of stationary objectVSDifficulty of detecting and measuring

Solution Approach 1:

The system establishes a feedback loop where the home gateway continuously monitors for suspicious devices attempting to connect to the extended Wi-Fi signal. When suspicious activity is detected, the system reports back to the war driving activity correlation system, which then sends instructions back to the gateway to implement mitigation actions. This feedback mechanism allows the network to maintain extended coverage while actively responding to security threats.

Inventive Principle:
Principle #23Feedback

3Reliability

If the system monitors and detects suspicious devices, then security detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The war driving activity correlation system acts as an intermediary between multiple home gateway systems. Individual gateways report suspicious activity to this central correlation system, which then processes the information, determines attacker routes, and coordinates mitigation actions across multiple gateways. This intermediary approach distributes the complexity rather than requiring each individual gateway to perform all security functions independently.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If mitigation actions are implemented against suspicious devices, then network security is improved, but potential false positives affecting benign devices may increase

Engineering Contradiction:
Improvenetwork securityVSAvoidfalse positive impact
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system allows benign devices to automatically establish trust relationships with home gateways through normal connection procedures. Once a device successfully connects and is recognized as legitimate, it is added to a trusted list, preventing false positive mitigation actions. The blacklisting mechanism specifically targets devices that fail to establish proper authentication or exhibit suspicious behavior patterns, while trusted devices continue to operate without restriction.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12574736B2Detecting and mitigating drive-by home Wi-Fi hijack attacks
Publication Date: 2026.03.10 AT&T INTELLECTUAL PROPERTY I L P
  • US12574736B2 patent drawing
  • US12574736B2 patent drawing
  • US12574736B2 patent drawing

AI summary

The concepts and technologies disclosed herein are directed to detecting and mitigating drive-by home WI-FI hijack attacks. According to one aspect, a war driving activity correlation system can obtain a report from a home gateway system. The report can identify a suspicious device attempting to connect to a WI-FI network provided, at least in part, by the home gateway system. The war driving activity correlation system can determine, based upon the report, a route of an attacker who uses the suspicious device. The war driving activity correlation system can send instructions to the home gateway system. The instructions can include the route and can specify one or more mitigation actions to be performed by the home gateway system, such as blacklisting a media access control address associated with the suspicious device. The mitigation action(s) can be based upon one or more policies.