Wireless Network Illegitimate Device Detection via Traceroute Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users connecting to public wireless networks are at risk of having their accounts compromised due to the inability of traditional security systems to detect illegitimate devices intercepting network traffic, such as Wi-Fi PINEAPPLEs, which can steal sensitive information.
Innovation Solution
A computer-implemented method and system that identifies an initial set of hops relaying network traffic between a computing device and a destination, periodically re-examines these hops, and compares them to detect any abnormalities indicating the presence of an illegitimate device, alerting the user if changes are found, thereby preventing sensitive information from being sent over compromised networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewalls and security applications are used to inspect incoming and outgoing traffic, then device security is improved, but the ability to detect illegitimate devices intercepting traffic is lost
Solution Approach 1:
The patent transitions from traditional endpoint security inspection to network path analysis by examining traceroute hops. This dimensional shift from device-level to network-level detection enables identification of illegitimate devices that traditional firewalls cannot detect, as it observes the network topology rather than just inspecting traffic content.
Solution Approach 2:
The system uses traceroute technology as an intermediary tool to indirectly detect illegitimate devices. Instead of directly monitoring traffic for signs of interception, the system employs traceroute packets to map the network path and identify unexpected hops, serving as a mediator between the security system and potential threats.
2Reliability
If encryption ciphers are used to protect sensitive traffic, then security is improved, but detection of illegitimate devices becomes more difficult
Solution Approach 1:
The patent segments the security approach into two independent components: (1) encryption for protecting traffic content, and (2) traceroute-based path analysis for detecting illegitimate devices. This segmentation allows both functions to operate simultaneously without interfering with each other, as the detection mechanism does not depend on analyzing encrypted traffic content.
Solution Approach 2:
The traceroute mechanism serves as an intermediary detection layer that operates independently of traffic encryption. By using network path mapping rather than traffic content analysis, the system can detect illegitimate devices even when traffic is encrypted, as the detection occurs at the network topology level rather than the application data level.
3Difficulty of detecting and measuring
If continuous monitoring of network hops is performed to detect illegitimate devices, then detection capability is improved, but system resource consumption increases
Solution Approach 1:
The system implements periodic traceroute monitoring at predetermined intervals rather than continuous monitoring. This periodic approach maintains detection capability by regularly checking for changes in network path topology while significantly reducing system resource consumption compared to continuous monitoring, as the detection mechanism is activated only at scheduled intervals.
Solution Approach 2:
The system leverages existing network infrastructure and protocols (traceroute) to perform detection without requiring dedicated monitoring hardware or excessive processing resources. By using standard network tools already present in the system, the detection mechanism serves itself using existing resources rather than consuming additional system capacity.
Data Source
AI summary
The disclosed computer-implemented method for detecting illegitimate devices on wireless networks may include (1) identifying an initial set of hops that represent devices on a wireless network that relay network traffic between the computing device and a destination, (2) identifying, after identifying the initial set of hops, a new set of hops that relay the network traffic between the computing device and the destination, (3) comparing the initial set of hops to the new set of hops, and (4) determining, based on the comparison, that the new set of hops comprises an abnormality that indicates an illegitimate device is intercepting the network traffic on the wireless network between the computing device and the destination. Various other methods, systems, and computer-readable media are also disclosed.


