Home Wi-Fi Gateway Detection of Drive-By Hijack Attempts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Home Wi-Fi networks are vulnerable to drive-by hijack attacks where attackers gain unauthorized access from outside the premises, posing risks to sensitive information and IoT devices.
Innovation Solution
A war driving activity correlation system that includes a processor and memory to analyze Wi-Fi device reports, determine attacker routes, and generate mitigation actions, such as blacklisting suspicious MAC addresses, using machine learning to distinguish between benign and malicious devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If home Wi-Fi networks provide Internet access within home premises, then network functionality is improved, but vulnerability to drive-by hijack attacks increases
Solution Approach 1:
The system performs preliminary detection of suspicious devices attempting to connect to the Wi-Fi network before full unauthorized access occurs. The home gateway system identifies and reports suspicious connection attempts to the war driving activity correlation system, enabling preemptive security measures to be taken before the attacker can compromise network devices or steal sensitive information.
2Area of stationary object
If Wi-Fi signals extend beyond home premises, then network coverage is improved, but detectability by attackers increases
Solution Approach 1:
The system establishes a feedback loop where the home gateway continuously monitors for suspicious devices attempting to connect to the extended Wi-Fi signal. When suspicious activity is detected, the system reports back to the war driving activity correlation system, which then sends instructions back to the gateway to implement mitigation actions. This feedback mechanism allows the network to maintain extended coverage while actively responding to security threats.
3Reliability
If the system monitors and detects suspicious devices, then security detection capability is improved, but system complexity increases
Solution Approach 1:
The war driving activity correlation system acts as an intermediary between multiple home gateway systems. Individual gateways report suspicious activity to this central correlation system, which then processes the information, determines attacker routes, and coordinates mitigation actions across multiple gateways. This intermediary approach distributes the complexity rather than requiring each individual gateway to perform all security functions independently.
4Reliability
If mitigation actions are implemented against suspicious devices, then network security is improved, but potential false positives affecting benign devices may increase
Solution Approach 1:
The system allows benign devices to automatically establish trust relationships with home gateways through normal connection procedures. Once a device successfully connects and is recognized as legitimate, it is added to a trusted list, preventing false positive mitigation actions. The blacklisting mechanism specifically targets devices that fail to establish proper authentication or exhibit suspicious behavior patterns, while trusted devices continue to operate without restriction.
Data Source
AI summary
The concepts and technologies disclosed herein are directed to detecting and mitigating drive-by home WI-FI hijack attacks. According to one aspect, a war driving activity correlation system can obtain a report from a home gateway system. The report can identify a suspicious device attempting to connect to a WI-FI network provided, at least in part, by the home gateway system. The war driving activity correlation system can determine, based upon the report, a route of an attacker who uses the suspicious device. The war driving activity correlation system can send instructions to the home gateway system. The instructions can include the route and can specify one or more mitigation actions to be performed by the home gateway system, such as blacklisting a media access control address associated with the suspicious device. The mitigation action(s) can be based upon one or more policies.


