WO2014094489A1 - Preventing clients from accessing a rogue access point - Google Patents

Preventing clients from accessing a rogue access point Download PDF

Info

Publication number
WO2014094489A1
WO2014094489A1 PCT/CN2013/085448 CN2013085448W WO2014094489A1 WO 2014094489 A1 WO2014094489 A1 WO 2014094489A1 CN 2013085448 W CN2013085448 W CN 2013085448W WO 2014094489 A1 WO2014094489 A1 WO 2014094489A1
Authority
WO
WIPO (PCT)
Prior art keywords
rogue
channel
detecting
client
wireless
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2013/085448
Other languages
French (fr)
Inventor
Tao Zheng
Haitao Zhang
Guoxiang XU
Zhenyu Fu
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Hangzhou H3C Technologies Co Ltd
Original Assignee
Hangzhou H3C Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hangzhou H3C Technologies Co Ltd filed Critical Hangzhou H3C Technologies Co Ltd
Priority to US14/652,768 priority Critical patent/US20150341789A1/en
Publication of WO2014094489A1 publication Critical patent/WO2014094489A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/12Detection or prevention of fraud
    • H04W12/121Wireless intrusion detection systems [WIDS]; Wireless intrusion prevention systems [WIPS]
    • H04W12/122Counter-measures against attacks; Protection against rogue devices
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W88/00Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
    • H04W88/08Access point devices

Definitions

  • WLAN Wireless Local Area Network
  • AP rogue Access Point
  • a malicious user may obtain information of the legal user via the rogue AP.
  • FIG. 1 is a flowchart illustrating a method for preventing clients from accessing a rogue AP in a wireless network according to an example of the present disclosure.
  • FIG. 2 is a schematic diagram illustrating a channel switch instruction according to an example of the present disclosure.
  • FIG. 3 is a schematic diagram illustrating a method for preventing clients from accessing a rogue AP in a wireless network according to another example of the present disclosure.
  • FIG. 4 is a schematic diagram illustrating a detecting AP that may be implemented to prevent clients from accessing a rogue AP in a wireless network, according to an example of the present disclosure.
  • FIG. 5 is a schematic diagram illustrating a detecting AP according to another example of the present disclosure.
  • the present disclosure is described by referring to examples. It will be readily apparent however, that the present disclosure may be practiced without limitation to these specific details. In other instances, some methods and structures have not been described in detail so as not to unnecessarily obscure the present disclosure.
  • the term “includes” means includes but not limited to, the term “including” means including but not limited to.
  • the term “based on” means based at least in part on.
  • the terms "a” and “an” are intended to denote at least one of a particular element.
  • conventional techniques for preventing clients from accessing rogue APs in a wireless network usually include the scanning of wireless channels periodically by a detecting AP and determining whether there is a rogue AP based on certain filtering conditions. If it is determined that there is a rogue AP, the detecting AP simulates the rogue AP to transmit a large amount of deassociation packets to clients to force the clients to be deassociated from the rogue AP. However, the clients will associate with the rogue AP again within a relatively short period of time. Thus, continuous transmission of the deassociation packets is required to keep the clients from continuing to associate with the rogue AP. The continuous transmission of the deassociation packets, however, occupies a great amount of radio resources and disrupts normal services to users associated with the rogue AP.
  • the method may include determining, by a detecting AP, whether there is a rogue AP in the wireless network. In response to a determination that there is a rogue AP in the wireless network, the detecting AP may obtain a wireless channel of the rogue AP.
  • the detecting AP may transmit, on the wireless channel of the rogue AP, a channel switch instruction to a client associated with the rogue AP by simulating an identity of the rogue AP to instruct the client to switch to a designated new channel.
  • the detecting AP may simulate the identity of the rogue AP to transmit a channel switch instruction to the client associated with the rogue AP to instruct the client to switch to the designated new channel, so as to remove the association between the client and the rogue AP and further provide a normal service for the user of the client.
  • a determination may be made by a detecting AP as to whether there is a rogue AP in the wireless network.
  • a "detecting AP" is an AP which is able to detect a rogue AP.
  • the detecting AP may transmit a channel switch instruction to the client associated with the rogue AP by simulating the identity of the rogue AP.
  • the channel switch instruction may instruct the client to switch to the designated new channel, so as to remove the association between the client the rogue AP.
  • the detecting AP may simulate the identity of the rogue AP to broadcast Beacon packets on the designated new channel to instruct wireless clients that previously associated with the rogue AP to associate with the detecting AP.
  • the client may be a Wi-Fi terminal such as a laptop computer, a tablet computer, a cell phone, etc.
  • FIG. 1 is a flowchart illustrating a method for preventing clients from accessing a rogue AP in a wireless network according to an example of the present disclosure.
  • the wireless network may include a detecting AP which may determine whether a rogue AP is in the wireless network.
  • the detecting AP may determine whether a rogue AP is in the wireless network through periodic scanning of wireless channels.
  • the wireless network may be a WLAN network.
  • the method may include the following operations.
  • the detecting AP may determine whether a rogue AP is in the wireless network.
  • block 102 may be performed; otherwise, block 101 may be repeated.
  • block 101 may be a scanning operation of wireless channels.
  • the detecting AP may determine whether a rogue AP is in the WLAN network through periodic scanning of wireless channels at multiple iterations of block 101 .
  • the detecting AP may determine whether a rogue AP is in the WLAN network through monitoring measures such as channel listening.
  • the detecting AP may determine the existence of a rogue AP according to a certain filtering condition.
  • the detecting AP may implement a determination process and configuration of the filtering condition that are similar to those in conventional systems and thus this process will not be described in detail herein.
  • the detecting AP may be a legal AP, e.g., an authorized AP in the wireless network, which is responsible for practical data forwarding services or may be a legal AP that is dedicated for the detection of rogue APs.
  • the detecting AP may be a detecting module inside a legal AP.
  • the detecting AP may obtain the wireless channel of the rogue AP.
  • the detecting AP may further obtain Basic Service Set Identifier (BSSID) information of the rogue AP and a list of users associated with the rogue AP (i.e., a wireless user list), and may save the above information.
  • BSSID information includes a MAC address of the rogue AP.
  • the detecting AP may transmit, on the wireless channel of the rogue AP, a channel switch instruction to a client associated with the rogue AP by simulating an identity of the rogue AP to instruct the client to switch to a designated new channel.
  • FIG. 2 is a schematic diagram illustrating a channel switch instruction according to an example of the present disclosure.
  • the channel switch instruction may be implemented by an existing channel switch announcement element.
  • the detecting AP may use the MAC address of the rogue AP as a source MAC address to transmit the channel switch instruction, so as to simulate the identity of the rogue AP, i.e., the SA field in FIG.
  • the channel switch instruction is also depicted as including an index of the designated new channel and a time for switching to the new channel.
  • the channel switch announcement element may be used to notify each client preparing to switch to the designated new channel.
  • the field “New channel” denotes the index of the designated new channel
  • the field “Channel switch count” denotes the time for switching.
  • the detecting AP may determine all of the clients associated with the rogue AP according to the wireless user list obtained at block 102, and may transmit the channel switch instruction to all of the determined clients.
  • the detecting AP may transmit a channel switch instruction to the client associated with the rogue AP by simulating the identity of the rogue AP to instruct the client to switch to a designated new channel.
  • the association between the client and the rogue AP may be removed and the client may be prevented from associating with the rogue AP again on the wireless channel of the rogue AP.
  • the method may further include a procedure of instructing the client to associate with the detecting AP.
  • FIG. 3 is a flowchart illustrating a method for preventing clients from accessing a rogue AP in a wireless network according to an example of the present disclosure.
  • blocks 301 -303 are similar to blocks 101 -103, respectively, and descriptions of blocks 301 -303 will be not be presented herein.
  • the detecting AP may switch to the designated new channel and may broadcast a beacon packet on the designated new channel by simulating the identity of the rogue AP.
  • the detecting AP may thus instruct the wireless client, which is associated with the rogue AP, to associate with the detecting AP.
  • the client After the client switches to the designated new channel, the client is not to transmit an association request on its own initiative. Therefore, in order to cause the client to associate with the detecting AP, the detecting AP may transmit a beacon packet on the designated new channel by simulating the identity of the rogue AP and may respond to a probe request of the user by simulating the rogue AP. After receiving the beacon packet broadcasted by the detecting AP on the designated new channel, the client establishes an association with the detecting AP. In one regard, therefore, because the client does not transmit an association request on its own initiative, the client may be prevented from associating with the rogue AP again after switching to the designated new channel.
  • the client may also receive beacon packets transmitted by other legal APs and may establish associations with the other legal APs.
  • the client may also establish an association with another rogue AP on the designated new channel. If the client associates with a rogue AP again, the detecting AP may continue to transmit the channel switch instruction to the client by simulating the identity of the rogue AP to direct the client to another designated new channel.
  • the wireless client may perform data packet transmission and receipt operations via the detecting AP and may enter into a normal operating procedure.
  • FIG. 4 is a schematic diagram illustrating a structure of a detecting AP that may be implemented to prevent a rogue AP from operating in a wireless network according to an example of the present disclosure.
  • the detecting AP may be a detecting module of a legal AP or a dedicated detecting AP.
  • the detecting AP may also be another legal AP responsible for data forwarding services.
  • the detecting AP may include a determining unit 401 , a recording unit 402, and a switch indicating unit 403.
  • the determining unit 401 may determine whether a rogue AP is in the wireless network. In particular, the determining unit 401 may determine whether a rogue AP is in the wireless network by periodically scanning wireless channels in the wireless network. In addition, the detecting AP may also determine whether a rogue AP is in the wireless network through implementation of monitoring measures such as channel listening. The detecting AP may determine the existence of the rogue AP according to a conventional filtering condition.
  • the recording unit 402 may record the wireless channel of the rogue AP if the determining unit 401 determines that a rogue AP is in the wireless network.
  • the recording unit 402 may record the BSSID information of the rogue AP and a list of wireless users associated with the rogue AP (i.e., a wireless user list).
  • the BSSID information includes a MAC address of the rogue AP.
  • the switch indicating unit 403 may transmit, on the wireless channel of the rogue AP, a channel switch instruction to each client associated with the rogue AP by simulating the identity of the rogue AP according to the wireless channel recorded by the recording unit 402.
  • the channel switch instruction may instruct the client associated with the rogue AP to switch to a designated new channel.
  • the switch indicating unit 403 may determine the client associated with the rogue AP according to the wireless user list recorded by the recording unit 402, so as to transmit the channel switch instruction to the client.
  • the switch indicating unit 403 may simulate the rogue AP by using the MAC address of the rogue AP as a source MAC address of the channel switch instruction.
  • the channel switch instruction may include an index of the designated new channel and time for switching to the designated new channel.
  • the field "New channel” denotes the index of the designated new channel
  • the field "Channel switch count” denotes the time for switching.
  • SA denotes the MAC address of the rogue AP.
  • the detecting AP may transmit a channel switch instruction to the client associated with the rogue AP by simulating the identity of the rogue AP.
  • the channel switch instruction is to instruct the client to switch to a designated new channel, which removes the association between the client and the rogue AP and prevents the client from associating with the rogue AP again on the wireless channel of the rogue AP.
  • FIG. 5 is a schematic diagram illustrating a structure of a detecting AP that is to prevent a rogue AP from operating in a wireless network according to an example of the present disclosure.
  • the detecting AP includes a determining unit 401 , a recording unit 402, a switch indicating unit 403, and a packet broadcasting unit 504.
  • the functions of the determining unit 401 , recording unit 402, and the switch indicating unit 403 are similar to corresponding units shown in FIG. 4 and descriptions of those units will not be repeated herein.
  • the packet broadcasting unit 504 may broadcast a beacon packet on the designated new channel by simulating the identity of the rogue AP to instruct the wireless client, which is associated with the rogue AP, to associate with the detecting AP
  • the client After the client switches to the designated new channel, the client is not to transmit an association request on its own initiative. Therefore, in order to cause the client to associate with the detecting AP, the detecting AP may transmit a beacon packet on the designated new channel by simulating the identity of the rogue AP and may respond to a probe request of the user by simulating the identity of the rogue AP. After receiving the beacon packet broadcasted by the detecting AP on the designated new channel, the client establishes an association with the detecting AP. In one regard, therefore, because the client does not transmit an association request on its own initiative, the client may be prevented from associating with the rogue AP again after switching to the designated new channel.
  • the client may also receive beacon packets transmitted by other legal APs and may establish associations with the other legal APs.
  • the client may also establish an association with another rogue AP on the designated new channel. If the client associates with a rogue AP again, the detecting AP may continue to transmit the channel switch instruction to the client by simulating the identity of the rogue AP to direct the client to another designated new channel.
  • the wireless client may perform data packet transmission and receipt operations through the detecting AP and may enter into a normal operating procedure.
  • a problem in the conventional method for preventing clients from accessing the rogue AP in a wireless network i.e., the continuous transmission of deassociation packets to prevent the client from associating with the rogue AP again after being deassociated from the rogue AP, the large amount of radio resources required by the continuous transmission of the deassociation packets, and the prevention of services provided for the user, may be resolved.
  • the above examples may be implemented by hardware, software, firmware, or a combination thereof.
  • processor the term processor is to be interpreted broadly to include a CPU, processing module, ASIC, logic module, or programmable gate array, etc.
  • the processes, methods, and functional modules may all be performed by a single processor or split between several processors; reference in this disclosure or the claims to a 'processor' should thus be interpreted to mean One or more processors'.
  • the processes, methods and functional modules may be implemented as machine readable instructions executable by one or more processors, hardware logic circuitry of the one or more processors or a combination thereof. Further, the examples disclosed herein may be implemented in the form of a software product.
  • the computer software product may be stored in a non-transitory computer readable storage medium and may include a plurality of instructions for making a computer device (which may be a personal computer, a server or a network device, such as a router, switch, access point, etc.) implement the method recited in the examples of the present disclosure.
  • a computer device which may be a personal computer, a server or a network device, such as a router, switch, access point, etc.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

According to an example, a detecting AP may determine whether a rogue AP is in the wireless network. In response to a determination that a rogue AP is in the wireless network, the detecting AP may obtain a wireless channel of the rogue AP and according to the wireless channel of the rogue AP, the detecting AP may transmit on the wireless channel of the rogue AP, a channel switch instruction to a client associated with the rogue AP by simulating an identity of the rogue AP. The channel switch instruction is to instruct the client to switch to a designated new channel.

Description

PREVENTING CLIENTS FROM ACCESSING A ROGUE ACCESS POINT
BACKGROUND
[0001 ] Conventional Wireless Local Area Network (WLAN) techniques are typically flexible to implement and convenient to deploy. However, often due to the openness of the transmission media and inadequate security, WLAN faces threats from various kinds of attacks. One type of attack is an attack by a rogue Access Point (AP), which may be defined as an AP that has not been authorized and/or lacks the appropriate credentials to operate on a WLAN. In this type of attack, when a legal (or authorized) user connects to a rogue AP, a malicious user may obtain information of the legal user via the rogue AP.
BRIEF DESCRIPTION OF THE DRAWINGS
[0002] Features of the present disclosure are illustrated by way of example and not limited in the following figure(s), in which like numerals indicate like elements, in which:
[0003] FIG. 1 is a flowchart illustrating a method for preventing clients from accessing a rogue AP in a wireless network according to an example of the present disclosure.
[0004] FIG. 2 is a schematic diagram illustrating a channel switch instruction according to an example of the present disclosure.
[0005] FIG. 3 is a schematic diagram illustrating a method for preventing clients from accessing a rogue AP in a wireless network according to another example of the present disclosure.
[0006] FIG. 4 is a schematic diagram illustrating a detecting AP that may be implemented to prevent clients from accessing a rogue AP in a wireless network, according to an example of the present disclosure.
[0007] FIG. 5 is a schematic diagram illustrating a detecting AP according to another example of the present disclosure.
DETAILED DESCRIPTION
[0008] For simplicity and illustrative purposes, the present disclosure is described by referring to examples. It will be readily apparent however, that the present disclosure may be practiced without limitation to these specific details. In other instances, some methods and structures have not been described in detail so as not to unnecessarily obscure the present disclosure. As used herein, the term "includes" means includes but not limited to, the term "including" means including but not limited to. The term "based on" means based at least in part on. In addition, the terms "a" and "an" are intended to denote at least one of a particular element.
[0009] In order to avoid potential security risks and provide normal services to wireless users, conventional techniques for preventing clients from accessing rogue APs in a wireless network usually include the scanning of wireless channels periodically by a detecting AP and determining whether there is a rogue AP based on certain filtering conditions. If it is determined that there is a rogue AP, the detecting AP simulates the rogue AP to transmit a large amount of deassociation packets to clients to force the clients to be deassociated from the rogue AP. However, the clients will associate with the rogue AP again within a relatively short period of time. Thus, continuous transmission of the deassociation packets is required to keep the clients from continuing to associate with the rogue AP. The continuous transmission of the deassociation packets, however, occupies a great amount of radio resources and disrupts normal services to users associated with the rogue AP.
[0010] In contrast, disclosed herein is a method for preventing clients from accessing a rogue AP in a wireless network, so as to avoid potential security risks caused by the rogue AP and provide normal services to wireless users. Particularly, the method may include determining, by a detecting AP, whether there is a rogue AP in the wireless network. In response to a determination that there is a rogue AP in the wireless network, the detecting AP may obtain a wireless channel of the rogue AP. In addition, the detecting AP may transmit, on the wireless channel of the rogue AP, a channel switch instruction to a client associated with the rogue AP by simulating an identity of the rogue AP to instruct the client to switch to a designated new channel.
[0011 ] Compared with conventional systems, in examples of the present disclosure, if a detecting AP detects the presence of a rogue AP in the wireless network, the detecting AP may simulate the identity of the rogue AP to transmit a channel switch instruction to the client associated with the rogue AP to instruct the client to switch to the designated new channel, so as to remove the association between the client and the rogue AP and further provide a normal service for the user of the client.
[0012] According to an example, in the method disclosed herein, a determination may be made by a detecting AP as to whether there is a rogue AP in the wireless network. A "detecting AP" is an AP which is able to detect a rogue AP. In response to a determination that there is a rogue AP, the detecting AP may transmit a channel switch instruction to the client associated with the rogue AP by simulating the identity of the rogue AP. The channel switch instruction may instruct the client to switch to the designated new channel, so as to remove the association between the client the rogue AP. In addition, in order to prevent the client from associating with the rogue AP again, the detecting AP may simulate the identity of the rogue AP to broadcast Beacon packets on the designated new channel to instruct wireless clients that previously associated with the rogue AP to associate with the detecting AP. The client may be a Wi-Fi terminal such as a laptop computer, a tablet computer, a cell phone, etc.
[0013] FIG. 1 is a flowchart illustrating a method for preventing clients from accessing a rogue AP in a wireless network according to an example of the present disclosure. The wireless network may include a detecting AP which may determine whether a rogue AP is in the wireless network. In particular, the detecting AP may determine whether a rogue AP is in the wireless network through periodic scanning of wireless channels. In examples of the present disclosure, the wireless network may be a WLAN network. The method may include the following operations. [0014] At block 101 , the detecting AP may determine whether a rogue AP is in the wireless network. In response to the detecting AP detecting a rogue AP in the wireless network, block 102 may be performed; otherwise, block 101 may be repeated. In one regard, block 101 may be a scanning operation of wireless channels.
[0015] In particular, according to an example, the detecting AP may determine whether a rogue AP is in the WLAN network through periodic scanning of wireless channels at multiple iterations of block 101 . In addition, the detecting AP may determine whether a rogue AP is in the WLAN network through monitoring measures such as channel listening. In any regard, the detecting AP may determine the existence of a rogue AP according to a certain filtering condition. The detecting AP may implement a determination process and configuration of the filtering condition that are similar to those in conventional systems and thus this process will not be described in detail herein.
[0016] It should be noted that the detecting AP may be a legal AP, e.g., an authorized AP in the wireless network, which is responsible for practical data forwarding services or may be a legal AP that is dedicated for the detection of rogue APs. In addition or alternatively, the detecting AP may be a detecting module inside a legal AP.
[0017] At block 102, following the detection of a rogue AP in the wireless network, the detecting AP may obtain the wireless channel of the rogue AP. In addition, the detecting AP may further obtain Basic Service Set Identifier (BSSID) information of the rogue AP and a list of users associated with the rogue AP (i.e., a wireless user list), and may save the above information. The BSSID information includes a MAC address of the rogue AP.
[0018] At block 103, the detecting AP may transmit, on the wireless channel of the rogue AP, a channel switch instruction to a client associated with the rogue AP by simulating an identity of the rogue AP to instruct the client to switch to a designated new channel. [0019] FIG. 2 is a schematic diagram illustrating a channel switch instruction according to an example of the present disclosure. The channel switch instruction may be implemented by an existing channel switch announcement element. As shown in FIG. 2, the detecting AP may use the MAC address of the rogue AP as a source MAC address to transmit the channel switch instruction, so as to simulate the identity of the rogue AP, i.e., the SA field in FIG. 2 is filled with the MAC address of the rogue AP. The channel switch instruction is also depicted as including an index of the designated new channel and a time for switching to the new channel. The channel switch announcement element may be used to notify each client preparing to switch to the designated new channel. In FIG. 2, the field "New channel" denotes the index of the designated new channel, and the field "Channel switch count" denotes the time for switching.
[0020] At block 103, the detecting AP may determine all of the clients associated with the rogue AP according to the wireless user list obtained at block 102, and may transmit the channel switch instruction to all of the determined clients.
[0021 ] Through implementation of blocks 101 -103, when a detecting AP determines that a rogue AP is in the wireless network, the detecting AP may transmit a channel switch instruction to the client associated with the rogue AP by simulating the identity of the rogue AP to instruct the client to switch to a designated new channel. As such, the association between the client and the rogue AP may be removed and the client may be prevented from associating with the rogue AP again on the wireless channel of the rogue AP.
[0022] In addition, after block 103, in order to further avoid security risks brought on by the rogue AP and to reduce the probability that the client associates with the rogue AP again, the method may further include a procedure of instructing the client to associate with the detecting AP. This procedure is shown in FIG. 3, which is a flowchart illustrating a method for preventing clients from accessing a rogue AP in a wireless network according to an example of the present disclosure. [0023] In FIG. 3, blocks 301 -303 are similar to blocks 101 -103, respectively, and descriptions of blocks 301 -303 will be not be presented herein.
[0024] At block 304, the detecting AP may switch to the designated new channel and may broadcast a beacon packet on the designated new channel by simulating the identity of the rogue AP. The detecting AP may thus instruct the wireless client, which is associated with the rogue AP, to associate with the detecting AP.
[0025] After the client switches to the designated new channel, the client is not to transmit an association request on its own initiative. Therefore, in order to cause the client to associate with the detecting AP, the detecting AP may transmit a beacon packet on the designated new channel by simulating the identity of the rogue AP and may respond to a probe request of the user by simulating the rogue AP. After receiving the beacon packet broadcasted by the detecting AP on the designated new channel, the client establishes an association with the detecting AP. In one regard, therefore, because the client does not transmit an association request on its own initiative, the client may be prevented from associating with the rogue AP again after switching to the designated new channel. After switching to the designated new channel, the client may also receive beacon packets transmitted by other legal APs and may establish associations with the other legal APs. The client may also establish an association with another rogue AP on the designated new channel. If the client associates with a rogue AP again, the detecting AP may continue to transmit the channel switch instruction to the client by simulating the identity of the rogue AP to direct the client to another designated new channel.
[0026] After the association between the wireless client and the detecting AP is established, the wireless client may perform data packet transmission and receipt operations via the detecting AP and may enter into a normal operating procedure.
[0027] As such, a problem in the conventional method for preventing clients from accessing the rogue AP in a wireless network, i.e., the continuous transmission of deassociation packets to prevent the client from associating with the rogue AP again after being deassociated from the rogue AP, the large amount of radio resources required by the continuous transmission of the deassociation packets, and the prevention of services provided for the user, may be resolved.
[0028] FIG. 4 is a schematic diagram illustrating a structure of a detecting AP that may be implemented to prevent a rogue AP from operating in a wireless network according to an example of the present disclosure. According to an example, the detecting AP may be a detecting module of a legal AP or a dedicated detecting AP. The detecting AP may also be another legal AP responsible for data forwarding services. As shown in FIG. 4, the detecting AP may include a determining unit 401 , a recording unit 402, and a switch indicating unit 403.
[0029] The determining unit 401 may determine whether a rogue AP is in the wireless network. In particular, the determining unit 401 may determine whether a rogue AP is in the wireless network by periodically scanning wireless channels in the wireless network. In addition, the detecting AP may also determine whether a rogue AP is in the wireless network through implementation of monitoring measures such as channel listening. The detecting AP may determine the existence of the rogue AP according to a conventional filtering condition.
[0030] The recording unit 402 may record the wireless channel of the rogue AP if the determining unit 401 determines that a rogue AP is in the wireless network. In particular, the recording unit 402 may record the BSSID information of the rogue AP and a list of wireless users associated with the rogue AP (i.e., a wireless user list). The BSSID information includes a MAC address of the rogue AP.
[0031 ] The switch indicating unit 403 may transmit, on the wireless channel of the rogue AP, a channel switch instruction to each client associated with the rogue AP by simulating the identity of the rogue AP according to the wireless channel recorded by the recording unit 402. The channel switch instruction may instruct the client associated with the rogue AP to switch to a designated new channel. [0032] The switch indicating unit 403 may determine the client associated with the rogue AP according to the wireless user list recorded by the recording unit 402, so as to transmit the channel switch instruction to the client. The switch indicating unit 403 may simulate the rogue AP by using the MAC address of the rogue AP as a source MAC address of the channel switch instruction. The channel switch instruction may include an index of the designated new channel and time for switching to the designated new channel. In the channel switch instruction as shown in FIG. 2, the field "New channel" denotes the index of the designated new channel, and the field "Channel switch count" denotes the time for switching. "SA" denotes the MAC address of the rogue AP.
[0033] According to the above, when the detecting AP detects that a rogue AP is in the wireless network, the detecting AP may transmit a channel switch instruction to the client associated with the rogue AP by simulating the identity of the rogue AP. The channel switch instruction is to instruct the client to switch to a designated new channel, which removes the association between the client and the rogue AP and prevents the client from associating with the rogue AP again on the wireless channel of the rogue AP.
[0034] In addition, in order to further eliminate security risks brought on by the rogue AP and to reduce the probability that the client associates with the rogue AP again, the detecting AP may further instruct the client to associate with the detecting AP. FIG. 5 is a schematic diagram illustrating a structure of a detecting AP that is to prevent a rogue AP from operating in a wireless network according to an example of the present disclosure.
[0035] As shown in FIG. 5, the detecting AP includes a determining unit 401 , a recording unit 402, a switch indicating unit 403, and a packet broadcasting unit 504. The functions of the determining unit 401 , recording unit 402, and the switch indicating unit 403 are similar to corresponding units shown in FIG. 4 and descriptions of those units will not be repeated herein. [0036] The packet broadcasting unit 504 may broadcast a beacon packet on the designated new channel by simulating the identity of the rogue AP to instruct the wireless client, which is associated with the rogue AP, to associate with the detecting AP
[0037] After the client switches to the designated new channel, the client is not to transmit an association request on its own initiative. Therefore, in order to cause the client to associate with the detecting AP, the detecting AP may transmit a beacon packet on the designated new channel by simulating the identity of the rogue AP and may respond to a probe request of the user by simulating the identity of the rogue AP. After receiving the beacon packet broadcasted by the detecting AP on the designated new channel, the client establishes an association with the detecting AP. In one regard, therefore, because the client does not transmit an association request on its own initiative, the client may be prevented from associating with the rogue AP again after switching to the designated new channel. After switching to the designated new channel, the client may also receive beacon packets transmitted by other legal APs and may establish associations with the other legal APs. The client may also establish an association with another rogue AP on the designated new channel. If the client associates with a rogue AP again, the detecting AP may continue to transmit the channel switch instruction to the client by simulating the identity of the rogue AP to direct the client to another designated new channel.
[0038] After the association between the wireless client and the detecting AP is established, the wireless client may perform data packet transmission and receipt operations through the detecting AP and may enter into a normal operating procedure. As such, a problem in the conventional method for preventing clients from accessing the rogue AP in a wireless network, i.e., the continuous transmission of deassociation packets to prevent the client from associating with the rogue AP again after being deassociated from the rogue AP, the large amount of radio resources required by the continuous transmission of the deassociation packets, and the prevention of services provided for the user, may be resolved. [0039] The above examples may be implemented by hardware, software, firmware, or a combination thereof. For example, the various methods, processes, and functional modules described herein may be implemented by a processor (the term processor is to be interpreted broadly to include a CPU, processing module, ASIC, logic module, or programmable gate array, etc.). The processes, methods, and functional modules may all be performed by a single processor or split between several processors; reference in this disclosure or the claims to a 'processor' should thus be interpreted to mean One or more processors'. The processes, methods and functional modules may be implemented as machine readable instructions executable by one or more processors, hardware logic circuitry of the one or more processors or a combination thereof. Further, the examples disclosed herein may be implemented in the form of a software product. The computer software product may be stored in a non-transitory computer readable storage medium and may include a plurality of instructions for making a computer device (which may be a personal computer, a server or a network device, such as a router, switch, access point, etc.) implement the method recited in the examples of the present disclosure.
[0040] What has been described and illustrated herein is an example of the disclosure along with some of its variations. The terms, descriptions and figures used herein are set forth by way of illustration. Many variations are possible within the spirit and scope of the disclosure, which is intended to be defined by the following claims and their equivalents.

Claims

CLAIMS WHAT IS CLAIMED IS:
1 . A method for preventing clients from accessing a rogue Access Point (AP) in a wireless network, wherein the wireless network comprises a detecting AP, the method comprising:
determining, by the detecting AP, whether a rogue AP is in the wireless network; in response to a determination that a rogue AP is in the wireless network, obtaining, by the detecting AP, a wireless channel of the rogue AP; and
transmitting, by the detecting AP, on the wireless channel of the rogue AP, a channel switch instruction to a client associated with the rogue AP by simulating an identity of the rogue AP to instruct the client to switch to a designated new channel.
2. The method of claim 1 , further comprising:
following transmission of the channel switch instruction to the client, broadcasting a beacon packet on the designated new channel by simulating the identity of the rogue AP to instruct the client to associate with the detecting AP.
3. The method of claim 1 , wherein transmitting the channel switch instruction on the wireless channel of the rogue AP to the client associated with the rogue AP by simulating the identity of the rogue AP comprises:
obtaining, by the detecting AP, basic service set identifier (BSSID) information of the rogue AP and a wireless user list of the rogue AP;
determining, by the detecting AP, the client associated with the rogue AP according to the wireless user list of the rogue AP; and
simulating, by the detecting AP, the identity of the rogue AP according to the
BSSID information of the rogue AP and transmitting the channel switch instruction to the determined client associated with the rogue AP.
4. The method of claim 3, wherein the BSSID information of the rogue AP comprises a MAC address of the rogue AP and wherein simulating the identity of the rogue AP further comprises simulating the identity of the rogue AP by using the MAC address of the rogue AP as a source MAC address of the channel switch instruction.
5. The method of claim 1 , wherein transmitting the channel switch instruction further comprises transmitting the channel switch instruction via a channel switch announcement element.
6. The method of claim 1 , wherein the channel switch instruction comprises an index of the designated new channel and a time for switching to the designated new channel.
7. A detecting Access Point (AP) to prevent clients from accessing a rogue AP in a wireless network, comprising:
a determining unit to determine whether a rogue AP is in the wireless network; a recording unit to record a wireless channel of the rogue AP;
a channel switch indicating unit to transmit on the wireless channel of the rogue AP recorded by the recording unit a channel switch instruction to a client associated with the rogue AP by simulating an identity of the rogue AP to instruct the client to switch to a designated new channel; and
a processor to implement the determining unit, the recording unit, and the channel switch indicating unit.
8. The detecting AP of claim 7, further comprising:
a packet broadcasting unit to broadcast, on the designated new channel, a beacon packet by simulating the identity of the rogue AP after the detecting AP switches to the designated new channel to instruct the client to associate with the detecting AP.
9. The detecting AP of claim 7, wherein the recording unit is to record basic service set identifier (BSSID) information of the rogue AP and a wireless user list of the rogue AP;
the switch indicating unit is further to determine the client associated with the rogue AP according to the wireless user list of the rogue AP, simulate the identity of the rogue AP according to the BSSID information of the rogue AP and transmit the channel switch instruction to the client associated with the rogue AP.
10. The detecting AP of claim 9, wherein the BSSI D information of the detecting AP comprises a MAC address of the rogue AP and wherein the switch indicating unit is further to use the MAC address of the rogue AP as a source MAC address of the channel switch instruction to simulate the identity of the rogue AP.
11 . The detecting AP of claim 7, wherein the channel switch indicating unit is to transmit the channel switch instruction via a channel switch announcement element.
12. The detecting AP of claim 7, wherein the channel switch instruction comprises an index of the designated new channel and a time for switching to the designated new channel.
13. A non-transitory computer readable storage medium on which is store machine readable instructions that when executed by a processor, cause the processor to:
determine whether a rogue AP is in the wireless network;
in response to a determination that a rogue AP is in the wireless network, obtain a wireless channel of the rogue AP; and
transmit on the wireless channel of the rogue AP, a channel switch instruction to a client associated with the rogue AP by simulating an identity of the rogue AP to instruct the client to switch to a designated new channel.
14. The non-transitory computer readable storage medium of claim 13, wherein the machine readable instructions are further to cause the processor to:
broadcast a beacon packet on the designated new channel by simulating the identity of the rogue AP to instruct the client to associate with the detecting AP.
15. The non-transitory computer readable storage medium of claim 13, wherein the machine readable instructions are further to cause the processor to:
obtain basic service set identifier (BSSID) information of the rogue AP and a wireless user list of the rogue AP;
determine the client associated with the rogue AP according to the wireless user list of the rogue AP; and
simulate the identity of the rogue AP according to the BSSID information of the rogue AP and transmit the channel switch instruction to the determined client associated with the rogue AP.
PCT/CN2013/085448 2012-12-19 2013-10-18 Preventing clients from accessing a rogue access point Ceased WO2014094489A1 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US14/652,768 US20150341789A1 (en) 2012-12-19 2013-10-18 Preventing clients from accessing a rogue access point

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201210556408.8A CN103888949A (en) 2012-12-19 2012-12-19 Illegal AP prevention method and device
CN201210556408.8 2012-12-19

Publications (1)

Publication Number Publication Date
WO2014094489A1 true WO2014094489A1 (en) 2014-06-26

Family

ID=50957633

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/085448 Ceased WO2014094489A1 (en) 2012-12-19 2013-10-18 Preventing clients from accessing a rogue access point

Country Status (3)

Country Link
US (1) US20150341789A1 (en)
CN (1) CN103888949A (en)
WO (1) WO2014094489A1 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20210014689A1 (en) * 2018-09-21 2021-01-14 Tencent Technology (Shenzhen) Company Limited Device behavior detection method, blocking processing method, medium, and electronic device

Families Citing this family (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106131845A (en) * 2016-08-23 2016-11-16 大连网月科技股份有限公司 A kind of illegal wireless access-point attacks method and device
CN106454843B (en) * 2016-11-14 2020-12-22 金华市智甄通信设备有限公司 Method and system for suppressing illegal AP in wireless local area network, wireless AP
CN108134996A (en) * 2017-12-22 2018-06-08 成都飞鱼星科技股份有限公司 A kind of detection of illegal wireless access point and blocking-up method
CN110324832B (en) * 2018-03-30 2022-09-27 南宁富联富桂精密工业有限公司 Wireless scanning method, network device and computer readable storage medium
CN108901025B (en) * 2018-07-10 2021-07-06 迈普通信技术股份有限公司 Illegal access point countercheck method and equipment
US10785703B1 (en) * 2019-06-26 2020-09-22 Fortinet, Inc. Preventing connections to unauthorized access points with channel switch announcements
US11601813B2 (en) * 2021-06-30 2023-03-07 Fortinet, Inc. Preventing wireless connections to an unauthorized access point on a data communication network using NAV values
CN116266911A (en) * 2021-12-16 2023-06-20 迈普通信技术股份有限公司 An illegal wireless access point countermeasure device, system and method

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1853393A (en) * 2003-09-15 2006-10-25 英特尔公司 Method, apparatus and system for detection of and reaction to rogue access points
CN1996893A (en) * 2006-12-25 2007-07-11 杭州华为三康技术有限公司 Method, device and system for monitoring illegal access point in the wireless LAN

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7453840B1 (en) * 2003-06-30 2008-11-18 Cisco Systems, Inc. Containment of rogue systems in wireless network environments
JP2005303788A (en) * 2004-04-14 2005-10-27 Matsushita Electric Ind Co Ltd Wireless device
CN102075934A (en) * 2009-11-19 2011-05-25 中国移动通信集团江苏有限公司 AP (Access Point) monitor and method and system for monitoring illegal APs
CN102014378B (en) * 2010-11-29 2014-04-02 北京星网锐捷网络技术有限公司 Method and system for detecting rogue access point device and access point device
US20120272276A1 (en) * 2011-04-19 2012-10-25 Ouellet-Belanger Alex System and method for providing video on demand over a quadrature amplitude modulation network
CN102231887A (en) * 2011-06-21 2011-11-02 深圳市融创天下科技股份有限公司 Method, system for finding AP (access point) with hidden SSID (service set identifier) and terminal device
CN102438238A (en) * 2011-12-28 2012-05-02 武汉虹旭信息技术有限责任公司 Method for detecting illegal AP in centralized WLAN environment

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1853393A (en) * 2003-09-15 2006-10-25 英特尔公司 Method, apparatus and system for detection of and reaction to rogue access points
CN1996893A (en) * 2006-12-25 2007-07-11 杭州华为三康技术有限公司 Method, device and system for monitoring illegal access point in the wireless LAN

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20210014689A1 (en) * 2018-09-21 2021-01-14 Tencent Technology (Shenzhen) Company Limited Device behavior detection method, blocking processing method, medium, and electronic device
US12225381B2 (en) * 2018-09-21 2025-02-11 Tencent Technology (Shenzhen) Company Limited Device behavior detection method, blocking processing method, medium, and electronic device

Also Published As

Publication number Publication date
US20150341789A1 (en) 2015-11-26
CN103888949A (en) 2014-06-25

Similar Documents

Publication Publication Date Title
US20150341789A1 (en) Preventing clients from accessing a rogue access point
KR102441861B1 (en) Beam information in early measurements
US12446070B2 (en) Systems and methods for UE operation in presence of CCA
EP3298814B1 (en) System and method for faked base station detection
KR102129642B1 (en) Inter-system call switching between co-existence wireless systems
EP3070970B1 (en) Detection of rogue access points
CN110741661B (en) Method, mobile device and computer readable storage medium for pseudo base station detection
KR101453521B1 (en) Wireless access point apparatus and method for detecting unauthorized wireless lan node
US11044276B2 (en) Cellular security framework
EP2702784B1 (en) Method and apparatus for providing a public warning
EP3780690A1 (en) Device behavior detection method, blocking processing method, medium and electronic device
US20150080040A1 (en) Terminal device discovery method, device and system
US20140130155A1 (en) Method for tracking out attack device driving soft rogue access point and apparatus performing the method
CN105681272B (en) The detection of mobile terminal fishing WiFi a kind of and resist method
US20190387408A1 (en) Wireless access node detecting method, wireless network detecting system and server
CN103648094A (en) Method, device and system for detecting illegal wireless access point
CN115943660A (en) Radio Resource Management Slack for Radio Resource Control Connected Mode
EP2826304B1 (en) Method and system for preventing the propagation of ad -hoc networks
CN106134117A (en) The detection of undelegated Wireless Telecom Equipment
CN104115530A (en) Proximity indication using out-of-band links
US11250172B2 (en) Handling wireless client devices associated with a role indicating a stolen device
WO2019144399A1 (en) Cell reselection method and device, and computer storage medium
US20150139211A1 (en) Method, Apparatus, and System for Detecting Rogue Wireless Access Point
US10999738B2 (en) Detection of internet-of-things devices in enterprise networks
CN107197456A (en) A kind of client-based identification puppet AP detection method and detection means

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13866163

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 14652768

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 13866163

Country of ref document: EP

Kind code of ref document: A1

122 Ep: pct application non-entry in european phase

Ref document number: 13866163

Country of ref document: EP

Kind code of ref document: A1