Wireless Access Point Deauthentication Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless network security is vulnerable to deauthentication attacks, where attackers transmit illegitimate deauthentication signals to disconnect devices from a network, compromising security and allowing potential data theft.

Innovation Solution

A computer-implemented method and system that detects illegitimate deauthentication signals at a wireless access point, determines their origin, and performs security actions to mitigate the attack, including generating device fingerprints to pre-emptively block future signals and notify administrators or users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless networks use standard deauthentication protocols, then devices can be legitimately disconnected from the network, but attackers can exploit these same protocols to transmit illegitimate deauthentication signals and compromise network security

Engineering Contradiction:
Improvenetwork disconnection capabilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a backend device fingerprinting system as an intermediary between wireless access points and attackers. This system receives device fingerprints from multiple access points, maintains a database of malicious devices, and provides fingerprint matching services to prevent illegitimate deauthentication attacks while preserving legitimate network management functions

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by generating device fingerprints proactively and storing them in a backend database before attacks occur. When a deauthentication signal is received, the system pre-emptively checks the sender's fingerprint against the database to identify and block malicious devices, rather than reacting after the attack has succeeded

Inventive Principle:
Principle #10Preliminary action

2Reliability

If wireless access points monitor and analyze deauthentication signals to identify attacks, then network security can be improved, but the complexity of the access point system increases

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess point system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security system into two parts: a simplified local component at the wireless access point that only needs to generate and send device fingerprints, and a complex backend system that handles fingerprint storage, management, and matching. This segmentation reduces the complexity burden on individual access points while maintaining comprehensive security capabilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The backend device fingerprinting system serves multiple functions: it stores device fingerprints from various access points, performs fingerprint matching to identify malicious devices, and provides security decisions to multiple access points simultaneously. This multi-functional approach consolidates complexity into a single universal system rather than duplicating complex logic at each access point

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If device fingerprints are generated and stored for every transmitting device, then attackers can be identified and blocked, but the amount of data that must be stored and processed increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoiddata storage volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system applies local quality by storing complete device fingerprint data locally at each wireless access point for immediate use, while the backend server stores only aggregated and processed fingerprint information. This differentiation in data storage quality and completeness based on location reduces overall data redundancy while maintaining detection accuracy where it is most needed

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10462672B1Systems and methods for managing wireless-network deauthentication attacks
Publication Date: 2019.10.29 GEN DIGITAL INC
  • US10462672B1 patent drawing
  • US10462672B1 patent drawing
  • US10462672B1 patent drawing

AI summary

The disclosed computer-implemented method for managing wireless-network deauthentication attacks may include (1) detecting, at the wireless access point, a deauthentication signal, transmitted over a wireless network that is managed at least in part by the wireless access point, that prompts a target computing device to disconnect from the wireless network, (2) determining both that the deauthentication signal is directed to the target computing device and that the deauthentication signal was not initiated by the wireless access point, (3) determining, based at least in part on the determination that the deauthentication signal was not initiated by the wireless access point, that the deauthentication signal represents an illegitimate deauthentication signal, and (4) performing, in response to determining that the deauthentication signal represents an illegitimate deauthentication signal, a security action to mitigate effects of the illegitimate deauthentication signal on the target computing device. Various other methods, systems, and computer-readable media are also disclosed.