WO2018076539A1 - 伪无线接入点识别方法及系统 - Google Patents
伪无线接入点识别方法及系统 Download PDFInfo
- Publication number
- WO2018076539A1 WO2018076539A1 PCT/CN2016/113631 CN2016113631W WO2018076539A1 WO 2018076539 A1 WO2018076539 A1 WO 2018076539A1 CN 2016113631 W CN2016113631 W CN 2016113631W WO 2018076539 A1 WO2018076539 A1 WO 2018076539A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- access point
- wireless access
- file
- target file
- electronic device
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/554—Detecting local intrusion or implementing counter-measures involving event detection and direct action
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/12—Detection or prevention of fraud
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
- G06F21/6245—Protecting personal data, e.g. for financial or medical purposes
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/02—Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/03—Protecting confidentiality, e.g. by encryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/12—Detection or prevention of fraud
- H04W12/121—Wireless intrusion detection systems [WIDS]; Wireless intrusion prevention systems [WIPS]
- H04W12/122—Counter-measures against attacks; Protection against rogue devices
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/12—Detection or prevention of fraud
- H04W12/126—Anti-theft arrangements, e.g. protection against subscriber identity module [SIM] cloning
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W24/00—Supervisory, monitoring or testing arrangements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W76/00—Connection management
- H04W76/30—Connection release
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W88/00—Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
- H04W88/08—Access point devices
Definitions
- the present invention relates to the field of wireless network technologies, and in particular, to a pseudo wireless access point identification method and system.
- Many electronic devices are currently equipped with wireless access point options. Users can connect to the wireless access point hotspot to browse the network world anytime and anywhere. However, people with ulterior motives will establish a phishing wireless access point through the wireless access point configuration in the electronic device to induce users to connect, thereby stealing the user's personal privacy, such as acquiring electronic Photos, contacts, information about financial related applications, etc. in the device. The user is basically unable to detect it. The user can only discover that the phishing wireless access point has been connected after the money is illegally transferred.
- a pseudo wireless access point identification method is applied to an electronic device, and the method includes:
- the file operation includes one or more of the following: an operation corresponding to the target file and a new file creation operation, the target file including a file related to user privacy or property security, the target file corresponding to
- the operations include any one or more of the following: a modification operation, a read operation, and a write operation on the target file.
- the abnormal operation comprises one or more of the following:
- the size of the target file read or written in the read operation or the write operation of the target file is greater than or equal to a preset value
- New files generated in the Generate New File action do not conform to the default naming rules.
- the warning instruction includes one or more of the following:
- the wireless access point is a pseudo wireless access point
- a pseudo wireless access point identification system running in an electronic device, the system comprising:
- the monitoring module is configured to monitor whether the file operation has an abnormal operation after the electronic device connects to the wireless network through the wireless access point;
- Determining a module configured to determine that the wireless access point is a pseudo wireless access point when the file operation has an abnormal operation
- the warning module is set to execute the warning command.
- the file operation includes one or more of the following: an operation corresponding to the target file and a new file creation operation, the target file including a file related to user privacy or property security, the target file corresponding to
- the operations include any one or more of the following: a modification operation, a read operation, and a write operation on the target file.
- the abnormal operation specifically includes one or more of the following:
- the size of the target file read or written in the read operation or the write operation of the target file is greater than or equal to a preset value
- New files generated in the Generate New File action do not conform to the default naming rules.
- the warning module is configured to execute the warning instruction including one or more of the following:
- the wireless access point is a pseudo wireless access point
- the present invention determines whether the file access operation has abnormal operation, and when the file operation has abnormal operation, determining that the wireless access point accessed by the electronic device is a pseudo wireless access point, and Execute a preset warning command. Therefore, the present invention can timely discover the phishing wireless access point and prevent the user's privacy and property from being lost.
- FIG. 1 is a flow chart of a preferred embodiment of a pseudo wireless access point identification method of the present invention.
- FIG. 2 is a schematic structural diagram of an electronic device according to a preferred embodiment of a method for implementing a pseudo wireless access point according to the present invention.
- FIG. 3 is a functional block diagram of an embodiment of a pseudo wireless access point identification system of the present invention.
- FIG. 1 it is a flowchart of a preferred embodiment of the pseudo wireless access point identification method of the present invention.
- the order of the steps in the flowchart may be changed according to different requirements, and some steps may be omitted.
- the pseudo wireless access point identification method of the present invention can be applied to a plurality of electronic devices.
- the electronic device is a device capable of automatically performing numerical calculation and/or information processing according to an instruction set or stored in advance, and the hardware thereof includes but is not limited to a microprocessor and an application specific integrated circuit (ASIC). , Field-Programmable Gate Array (FPGA), Digital Signal Processor (DSP), embedded devices, etc.
- ASIC application specific integrated circuit
- FPGA Field-Programmable Gate Array
- DSP Digital Signal Processor
- embedded devices etc.
- the electronic device can also be any electronic product that can interact with the user, such as a personal computer, a tablet computer, a smart phone, a personal digital assistant (PDA), a game machine, an interactive network television. (Internet Protocol Television, IPTV), smart wearable devices, etc.
- a personal computer a tablet computer
- a smart phone a personal digital assistant (PDA)
- PDA personal digital assistant
- game machine an interactive network television.
- IPTV Internet Protocol Television
- smart wearable devices etc.
- the electronic device After the electronic device connects to the wireless network through the wireless access point, the electronic device monitors whether the file operation has an abnormal operation.
- the electronic device includes various types of files, such as pictures, videos, installation files for various applications, various configuration files, and the like.
- the wireless access point includes, but is not limited to, a Wi-Fi access point.
- the file operation includes one or more of the following: an operation corresponding to the target file and a new file creation operation.
- the target file includes files related to user privacy or property security.
- the target files include: but are not limited to, pictures, videos, cookies files, application configuration files, and the like.
- the object file may be one or more.
- the operation corresponding to the target file includes any one or more of the following: a modification operation, a read operation, a write operation, and the like on the target file.
- the electronic device traverses the file operation according to a preset time interval to monitor whether the file operation has an abnormal operation.
- whether the file operation is abnormal or not can be determined by determining whether the modification operation, the read or write operation on the target file is abnormal, and whether the new file generated in the new file operation is abnormal. .
- the electronic device determines that the wireless access point is a pseudo wireless access point.
- the abnormal operation specifically includes one or more of the following:
- a malicious program modifies the rights setting data corresponding to the target file.
- a malicious program usually refers to a program written with an attack intention, which mainly includes: trapdoors, logic bombs, Trojan horses, worms, bacteria, viruses, and the like.
- the permission setting data includes access rights, read permissions, edit permissions, modify permissions, and the like.
- the size of the target file read or written in the read operation or the write operation of the target file is greater than or equal to a preset value.
- the user's privacy and property may be threatened.
- the new file generated in the operation of generating a new file does not conform to the preset naming rules.
- the preset naming rules are set according to user habits and/or according to system settings of the electronic device.
- the electronic device determines that the file operation has an abnormal operation.
- the electronic device executes an early warning instruction.
- the electronic device executes the warning instruction including one or more of the following:
- the operation associated with the target file when the operation associated with the target file is frozen after receiving the operation associated with the target file, the operation associated with the target file is thawed. .
- the electronic device first exits the login account of all applications in the electronic device, and then disconnects from the wireless access point. If the wireless access point in the wireless network is first disconnected from the login account of all applications in the electronic device, the cached network data will not be emptied, which will cause the malicious program to continue to manipulate the electronic device.
- the wireless access point is a pseudo wireless access point.
- the wireless access point is prompted to be a pseudo wireless access point by means of sound, vibration, interface, or the like.
- SD Secure Digital
- the invention detects whether the file operation has abnormal operation, and when the file operation has abnormal operation, determines that the wireless access point accessed by the electronic device is a pseudo wireless access point, and executes an early warning instruction. Therefore, the present invention can timely discover the phishing wireless access point and prevent the user's privacy and property from being lost.
- FIG. 2 is a schematic structural diagram of an electronic device according to a preferred embodiment of the method for implementing a pseudo wireless access point according to the present invention.
- the electronic device 1 includes a storage device 12 and a processing device 13.
- the electronic device 1 further includes, but is not limited to, any electronic product that can interact with a user through a keyboard, a mouse, a remote controller, a touch panel, or a voice control device, for example, a personal computer, a tablet computer, a smart phone, Personal Digital Assistant (PDA), game consoles, Internet Protocol Television (IPTV), smart wearable devices, etc.
- the network in which the electronic device 1 is located includes, but is not limited to, the Internet, a wide area network, a metropolitan area network, a local area network, a virtual private network (VPN), and the like.
- VPN virtual private network
- the storage device 12 is configured to store a program of the pseudo wireless access point identification method and various data, and realize high speed and automatic access of the program or data during the operation of the electronic device 1.
- the storage device 12 may be an external storage device and/or an internal storage device of the electronic device 1. Further, the storage device 12 may be a circuit having a storage function in a physical form, such as a RAM (Random-Access Memory), a FIFO (First In First Out), or the like. Alternatively, the storage device 12 may also be a storage device having a physical form, such as a memory stick, a TF card, or the like.
- the processing device 13 is also called a central processing unit (CPU). It is a very large-scale integrated circuit, and is a computing core (Core) and a control unit of the electronic device 1.
- the processing device 13 can execute an operating system of the electronic device 1 and various installed applications, program codes, and the like, such as a pseudo wireless access point identification system 11.
- the pseudo wireless access point identification system 11 includes a monitoring module 100, a determining module 101, and an early warning module 102.
- a module referred to in the present invention refers to a series of computer program segments that can be executed by the processing device 13 and that are capable of performing fixed functions, which are stored in the storage device 12. In the present embodiment, the functions of the respective modules will be described in detail in the subsequent embodiments.
- the monitoring module 100 monitors whether the file operation has an abnormal operation.
- the electronic device 1 includes various types of files, such as pictures, videos, installation files for various applications, various configuration files, and the like.
- the wireless access point includes, but is not limited to, a Wi-Fi access point.
- the file operation includes one or more of the following: an operation corresponding to the target file and a new file creation operation.
- the target file includes files related to user privacy or property security.
- the target files include: but are not limited to, pictures, videos, cookies files, application configuration files, and the like.
- the object file may be one or more.
- the operation corresponding to the target file includes any one or more of the following: a modification operation, a read operation, a write operation, and the like on the target file.
- the monitoring module 100 traverses the file operation according to a preset time interval to monitor whether the file operation has an abnormal operation.
- the monitoring module 100 can determine whether the new file generated in the new file operation is abnormal by determining whether the modification operation, the read or write operation on the target file is abnormal, and whether the new file generated in the new file operation is abnormal. Whether the file operation in the file management folder has abnormal operation.
- the determining module 101 determines that the wireless access point is a pseudo wireless access point.
- the abnormal operation specifically includes one or more of the following:
- a malicious program modifies the rights setting data corresponding to the target file.
- a malicious program usually refers to a program written with an attack intention, which mainly includes: trapdoors, logic bombs, Trojan horses, worms, bacteria, viruses, and the like.
- the permission setting data includes access rights, read permissions, edit permissions, modify permissions, and the like.
- the size of the target file read or written in the read operation or the write operation of the target file is greater than or equal to a preset value.
- the user's privacy and property may be threatened.
- the new file generated in the operation of generating a new file does not conform to the preset naming rules.
- the preset naming rules are set according to user habits and/or according to system settings of the electronic device.
- the determining module 101 determines that the file operation has an abnormal operation.
- the alert module 102 executes an alert command.
- the warning module 102 executes the warning instruction including one or more of the following:
- the operation associated with the target file when the operation associated with the target file is frozen after receiving the operation associated with the target file, the operation associated with the target file is thawed. .
- the electronic device first exits the login account of all applications in the electronic device, and then disconnects from the wireless access point. If the wireless access point in the wireless network is first disconnected from the login account of all applications in the electronic device, the cached network data will not be emptied, which will cause the malicious program to continue to manipulate the electronic device.
- the wireless access point is a pseudo wireless access point.
- the wireless access point is prompted to be a pseudo wireless access point by means of sound, vibration, interface, or the like.
- the invention detects whether the file operation has abnormal operation, and when the file operation has abnormal operation, determines that the wireless access point accessed by the electronic device is a pseudo wireless access point, and executes an early warning instruction. Therefore, the present invention can timely discover the phishing wireless access point and prevent the user's privacy and property from being lost.
- the above-described integrated unit implemented in the form of a software function module can be stored in a computer readable storage medium.
- the software function modules described above are stored in a storage medium and include instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor to perform the methods of the various embodiments of the present invention. Part of the steps.
- the storage device 12 in the electronic device 1 stores a plurality of instructions to implement a pseudo wireless access point identification method, and the processing device 13 can execute the plurality of instructions to implement: when After the electronic device connects to the wireless network through the wireless access point, it monitors whether the file operation has abnormal operation; when the file operation has abnormal operation, determines that the wireless access point is a pseudo wireless access point; and executes an early warning instruction.
- the file operation includes one or more of the following: an operation corresponding to the target file and a new file creation operation, the target file including a file related to user privacy or property security, the target file corresponding to
- the operations include any one or more of the following: a modification operation, a read operation, and a write operation on the target file.
- the abnormal operation specifically includes one or more of the following:
- the size of the target file read or written in the read operation or the write operation of the target file is greater than or equal to a preset value
- New files generated in the Generate New File action do not conform to the default naming rules.
- the processing device 13 further executes the following instructions:
- the wireless access point is a pseudo wireless access point
- modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of the embodiment.
- each functional module in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
- the above integrated unit can be implemented in the form of hardware or in the form of hardware plus software function modules.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Theoretical Computer Science (AREA)
- Software Systems (AREA)
- General Health & Medical Sciences (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Computer Hardware Design (AREA)
- Medical Informatics (AREA)
- Databases & Information Systems (AREA)
- Telephone Function (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
一种伪无线接入点识别方法,应用于电子设备中,所述方法包括:当所述电子设备通过无线接入点连接无线网络后,监测文件操作是否有异常操作;当所述文件操作有异常操作时,确定所述无线接入点为伪无线接入点;及执行预警指令。本发明还提供一种伪无线接入点识别系统。本发明能及时发现钓鱼无线接入点,防止用户的隐私及财产有损失。
Description
本申请要求于2016年10月31日提交中国专利局,申请号为201610932098.3、发明名称为“伪无线接入点识别方法及系统”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
本发明涉及无线网络技术领域,尤其涉及一种伪无线接入点识别方法及系统。
目前电子设备很多都配置有无线接入点选项。用户可随时随地连接无线接入点热点畅游网络世界,然而别有用心之人会通过电子设备中的无线接入点配置建立钓鱼无线接入点,诱使用户连接,从而窃取用户个人隐私,如获取电子设备中的照片、联系人、金融相关应用的信息等。用户基本上无法察觉。用户只有在网银等钱财遭到非法转移后才能发现连接过钓鱼无线接入点。
鉴于以上内容,有必要提供一种伪无线接入点识别方法及系统,能及时发现钓鱼无线接入点,防止用户的隐私及财产有损失。
一种伪无线接入点识别方法,应用于电子设备中,所述方法包括:
当所述电子设备通过无线接入点连接无线网络后,监测文件操作是否有异常操作;
当所述文件操作有异常操作时,确定所述无线接入点为伪无线接入点;及
执行预警指令。
根据本发明优选实施例,所述文件操作包括以下一种或者多种:目标文件对应的操作及生成新文件操作,所述目标文件包括与用户隐私或财产安全相关的文件,所述目标文件对应的操作包括以下任一种或者多种:对所述目标文件的修改操作、读操作和写操作。
根据本发明优选实施例,所述异常操作包括以下一种或者多种:
对所述目标文件对应的权限设置数据进行修改的操作;
对所述目标文件的读操作或写操作中所读或写的所述目标文件的大小大于或等于预设值;
在生成新文件操作中所生成的新文件不符合预设命名规则。
根据本发明优选实施例,所述预警指令包括以下一种或者多种:
退出所述电子设备中所有应用程序的登录账户;
冻结与所述目标文件相关联的操作;
断开与所述无线接入点的连接;
提示用户所述无线接入点是伪无线接入点;
禁止任何操作访问所述电子设备中的安全数位卡。
一种伪无线接入点识别系统,运行于电子设备中,所述系统包括:
监测模块,设置为当所述电子设备通过无线接入点连接无线网络后,监测文件操作是否有异常操作;
确定模块,设置为当所述文件操作有异常操作时,确定所述无线接入点为伪无线接入点;及
预警模块,设置为执行预警指令。
根据本发明优选实施例,所述文件操作包括以下一种或者多种:目标文件对应的操作及生成新文件操作,所述目标文件包括与用户隐私或财产安全相关的文件,所述目标文件对应的操作包括以下任一种或者多种:对所述目标文件的修改操作、读操作和写操作。
根据本发明优选实施例,所述异常操作具体包括以下一种或者多种:
对所述目标文件对应的权限设置数据进行修改的操作;
对所述目标文件的读操作或写操作中所读或写的所述目标文件的大小大于或等于预设值;
在生成新文件操作中所生成的新文件不符合预设命名规则。
根据本发明优选实施例,所述预警模块设置为执行预警指令包括以下一种或者多种:
退出所述电子设备中所有应用程序的登录账户;
冻结与所述目标文件相关联的操作;
断开与所述无线接入点的连接;
提示用户所述无线接入点是伪无线接入点;
禁止任何操作访问所述电子设备中的安全数位卡。
由以上技术方案可以看出,本发明通过监测文件操作是否有异常操作,当所述文件操作有异常操作时,确定所述电子设备所接入的无线接入点为伪无线接入点,并执行预设的预警指令。因此,本发明能及时发现钓鱼无线接入点,防止用户的隐私及财产有损失。
图1是本发明伪无线接入点识别方法的较佳实施例的流程图。
图2是本发明实现伪无线接入点识别方法的较佳实施例的电子设备的结构示意图。
图3是本发明伪无线接入点识别系统的实施例的功能模块图。
| 电子设备 | 1 |
| 存储设备 | 12 |
| 处理设备 | 13 |
| 伪无线接入点识别系统 | 11 |
| 监测模块 | 100 |
| 确定模块 | 101 |
| 预警模块 | 102 |
为了使本发明的目的、技术方案和优点更加清楚,下面结合附图和具体实施例对本发明进行详细描述。
如图1所示,是本发明伪无线接入点识别方法较佳实施例的流程图。根据不同的需求,该流程图中步骤的顺序可以改变,某些步骤可以省略。
优选地,本发明的伪无线接入点识别方法可以应用在多个电子设备中。所述电子设备是一种能够按照事先设定或存储的指令,自动进行数值计算和/或信息处理的设备,其硬件包括但不限于微处理器、专用集成电路(Application Specific Integrated Circuit,ASIC)、可编程门阵列(Field-Programmable Gate Array,FPGA)、数字处理器(Digital Signal Processor,DSP)、嵌入式设备等。
所述电子设备还可以是任何一种可与用户进行人机交互的电子产品,例如,个人计算机、平板电脑、智能手机、个人数字助理(Personal Digital Assistant,PDA)、游戏机、交互式网络电视(Internet Protocol Television,IPTV)、智能式穿戴式设备等。
S10,当所述电子设备通过无线接入点连接无线网络后,所述电子设备监测文件操作是否有异常操作。
在本发明的一个实施例中,所述电子设备包括各类文件,如图片、视频、各种应用程序的安装文件、各种配置文件等等。所述无线接入点包括,但不限于:Wi-Fi接入点。
在本发明的一个实施例中,所述文件操作包括以下一种或者多种:目标文件对应的操作及生成新文件操作。所述目标文件包括与用户隐私或财产安全相关的文件。所述目标文件包括:但不限于,图片、视频、cookies文件、应用程序的配置文件等等。所述目标文件可以是一个或者多个。所述目标文件对应的操作包括以下任一种或者多种:对所述目标文件的修改操作、读操作和写操作等等。
在本发明的一个实施例中,所述电子设备按照预设时间间隔遍历所述文件操作以监测所述文件操作是否有异常操作。
在本发明的一个实施例中,可以通过判断对所述目标文件的修改操作、读或写操作是否有异常,生成新文件操作中所生成的新文件是否有异常来判断文件操作是否有异常操作。
S11,当所述文件操作有异常操作时,所述电子设备确定所述无线接入点为伪无线接入点。
在本发明的一个实施例中,所述异常操作具体包括以下一种或者多种:
(1)对所述目标文件对应的权限设置数据进行修改的操作。
在本发明的一个实施例中,例如,恶意程序对所述目标文件对应的权限设置数据进行修改的操作。恶意程序通常是指带有攻击意图所编写的一段程序,所述恶意程序主要包括:陷门、逻辑炸弹、特洛伊木马、蠕虫、细菌、病毒等。权限设置数据包括访问权限、读取权限、编辑权限、修改权限等等与权限相关的设置数据。
(2)对所述目标文件的读操作或写操作中所读或写的所述目标文件的大小大于或等于预设值。
在本发明的一个实施例中,当所读或写的所述目标文件的大小大于或等于预设值,表示大量的目标文件正在被读或写,可能会对用户的隐私及财产有威胁。
(3)在生成新文件操作中所生成的新文件不符合预设命名规则。所述预设命名规则根据用户习惯设置及/或根据电子设备的系统设置。
因此,当所述电子设备检测到所述中文件操作有上述一种或者多种操作时,则所述电子设备确定所述文件操作有异常操作。
S12,所述电子设备执行预警指令。
在本发明的一个实施例中,所述电子设备执行预警指令包括以下一种或者多种:
(1)退出所述电子设备中所有应用程序的登录账户。
(2)冻结与所述目标文件相关联的操作。如读或写操作、复制操作等等。
在本发明的一个实施例中,当冻结与所述目标文件相关联的操作后,接收到用户对所述目标文件相关联的操作的解冻指令时,对所述目标文件相关联的操作进行解冻。
(3)断开与所述无线接入点的连接。
在本发明的一个实施例中,所述电子设备先退出所述电子设备中所有应用程序的登录账户,再断开与所述无线接入点的连接。若先断开无线网络中所述无线接入点再退出所述电子设备中所有应用程序的登录账户时,缓存的网络数据则不会被清空,将导致恶意程序可以继续操控所述电子设备。
(4)提示用户所述无线接入点是伪无线接入点。
在本发明的一个实施例中,以声音、震动、界面等方式提示所述无线接入点是伪无线接入点。
(5)禁止任何操作访问所述电子设备中的安全数位(Secure Digital,SD)卡。
本发明通过监测文件操作是否有异常操作,当所述文件操作有异常操作时,确定所述电子设备所接入的无线接入点为伪无线接入点,并执行预警指令。因此,本发明能及时发现钓鱼无线接入点,防止用户的隐私及财产有损失。
如图2所示,图2是本发明实现伪无线接入点识别方法的较佳实施例的电子设备的结构示意图。所述电子设备1包括存储设备12及处理设备13。
所述电子设备1还包括但不限于任何一种可与用户通过键盘、鼠标、遥控器、触摸板或声控设备等方式进行人机交互的电子产品,例如,个人计算机、平板电脑、智能手机、个人数字助理(Personal Digital Assistant,PDA)、游戏机、交互式网络电视(Internet Protocol Television,IPTV)、智能式穿戴式设备等。所述电子设备1所处的网络包括但不限于互联网、广域网、城域网、局域网、虚拟专用网络(Virtual Private Network,VPN)等。
所述存储设备12用于存储一种伪无线接入点识别方法的程序和各种数据,并在所述电子设备1运行过程中实现高速、自动地完成程序或数据的存取。所述存储设备12可以是电子设备1的外部存储设备和/或内部存储设备。进一步地,所述存储设备12可以是集成电路中没有实物形式的具有存储功能的电路,如RAM(Random-Access Memory,随机存取存储设备)、FIFO(First In First Out,)等。或者,所述存储设备12也可以是具有实物形式的存储设备,如内存条、TF卡(Trans-flash Card)等等。
所述处理设备13又称中央处理器(CPU,Central Processing Unit),是一块超大规模的集成电路,是电子设备1的运算核心(Core)和控制核心(Control Unit)。所述处理设备13可执行所述电子设备1的操作系统以及安装的各类应用程序、程序代码等,例如伪无线接入点识别系统11。
如图3所示,本发明伪无线接入点识别系统的实施例的功能模块图。所述伪无线接入点识别系统11包括监测模块100、确定模块101及预警模块102。本发明所称的模块是指一种能够被处理设备13所执行并且能够完成固定功能的一系列计算机程序段,其存储在存储设备12中。在本实施例中,关于各模块的功能将在后续的实施例中详述。
当所述电子设备1通过无线接入点连接无线网络后,所述监测模块100监测文件操作是否有异常操作。
在本发明的一个实施例中,所述电子设备1包括各类文件,如图片、视频、各种应用程序的安装文件、各种配置文件等等。所述无线接入点包括,但不限于:Wi-Fi接入点。
在本发明的一个实施例中,所述文件操作包括以下一种或者多种:目标文件对应的操作及生成新文件操作。所述目标文件包括与用户隐私或财产安全相关的文件。所述目标文件包括:但不限于,图片、视频、cookies文件、应用程序的配置文件等等。所述目标文件可以是一个或者多个。所述目标文件对应的操作包括以下任一种或者多种:对所述目标文件的修改操作、读操作和写操作等等。
在本发明的一个实施例中,所述所述监测模块100按照预设时间间隔遍历所述文件操作以监测所述文件操作是否有异常操作。
在本发明的一个实施例中,所述监测模块100可以通过判断对所述目标文件的修改操作、读或写操作是否有异常,生成新文件操作中所生成的新文件是否有异常来判断所述文件管理夹中文件操作是否有异常操作。
当所述文件操作有异常操作时,所述确定模块101确定所述无线接入点为伪无线接入点。
在本发明的一个实施例中,所述异常操作具体包括以下一种或者多种:
(1)对所述目标文件对应的权限设置数据进行修改的操作。
在本发明的一个实施例中,例如,恶意程序对所述目标文件对应的权限设置数据进行修改的操作。恶意程序通常是指带有攻击意图所编写的一段程序,所述恶意程序主要包括:陷门、逻辑炸弹、特洛伊木马、蠕虫、细菌、病毒等。权限设置数据包括访问权限、读取权限、编辑权限、修改权限等等与权限相关的设置数据。
(2)对所述目标文件的读操作或写操作中所读或写的所述目标文件的大小大于或等于预设值。
在本发明的一个实施例中,当所读或写的所述目标文件的大小大于或等于预设值,表示大量的所述目标文件正在被读或写,可能会对用户的隐私及财产有威胁。
(3)在生成新文件操作中所生成的新文件不符合预设命名规则。所述预设命名规则根据用户习惯设置及/或根据电子设备的系统设置。
因此,当所述确定模块101检测到所述文件管理夹中文件操作有上述一种或者多种操作时,则所述确定模块101确定所述文件操作有异常操作。
所述预警模块102执行预警指令。
在本发明的一个实施例中,所述预警模块102执行预警指令包括以下一种或者多种:
(1)退出所述电子设备中所有应用程序的登录账户。
(2)冻结与所述目标文件相关联的操作。如读或写操作、复制操作等等。
在本发明的一个实施例中,当冻结与所述目标文件相关联的操作后,接收到用户对所述目标文件相关联的操作的解冻指令时,对所述目标文件相关联的操作进行解冻。
(3)断开与所述无线接入点的连接。
在本发明的一个实施例中,所述电子设备先退出所述电子设备中所有应用程序的登录账户,再断开与所述无线接入点的连接。若先断开无线网络中所述无线接入点再退出所述电子设备中所有应用程序的登录账户时,缓存的网络数据则不会被清空,将导致恶意程序可以继续操控所述电子设备。
(4)提示用户所述无线接入点是伪无线接入点。
在本发明的一个实施例中,以声音、震动、界面等方式提示所述无线接入点是伪无线接入点。
(5)禁止任何操作访问所述电子设备中的安全数位卡,即sdcard(SD)卡。
本发明通过监测文件操作是否有异常操作,当所述文件操作有异常操作时,确定所述电子设备所接入的无线接入点为伪无线接入点,并执行预警指令。因此,本发明能及时发现钓鱼无线接入点,防止用户的隐私及财产有损失。
上述以软件功能模块的形式实现的集成的单元,可以存储在一个计算机可读取存储介质中。上述软件功能模块存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)或处理器(processor)执行本发明各个实施例所述方法的部分步骤。
结合图1,所述电子设备1中的所述存储设备12存储多个指令以实现一种伪无线接入点识别方法,所述处理设备13可执行所述多个指令从而实现:当所述电子设备通过无线接入点连接无线网络后,监测文件操作是否有异常操作;当所述文件操作有异常操作时,确定所述无线接入点为伪无线接入点;及执行预警指令。
根据本发明优选实施例,所述文件操作包括以下一种或者多种:目标文件对应的操作及生成新文件操作,所述目标文件包括与用户隐私或财产安全相关的文件,所述目标文件对应的操作包括以下任一种或者多种:对所述目标文件的修改操作、读操作和写操作。
根据本发明优选实施例,所述异常操作具体包括以下一种或者多种:
对所述目标文件对应的权限设置数据进行修改的操作;
对所述目标文件的读操作或写操作中所读或写的所述目标文件的大小大于或等于预设值;
在生成新文件操作中所生成的新文件不符合预设命名规则。
根据本发明优选实施例,所述处理设备13还执行以下指令包括:
退出所述电子设备中所有应用程序的登录账户;
冻结与所述目标文件相关联的操作;
断开与所述无线接入点的连接;
提示用户所述无线接入点是伪无线接入点;
禁止任何操作访问所述电子设备中的安全数位卡。
具体地,所述处理设备13对上述指令的具体实现方法可参考图1对应实施例中相关步骤的描述,在此不赘述。在本发明所提供的几个实施例中,应该理解到,所揭露的系统,装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述模块的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式。
所述作为分离部件说明的模块可以是或者也可以不是物理上分开的,作为模块显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部模块来实现本实施例方案的目的。
另外,在本发明各个实施例中的各功能模块可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用硬件加软件功能模块的形式实现。
对于本领域技术人员而言,显然本发明不限于上述示范性实施例的细节,而且在不背离本发明的精神或基本特征的情况下,能够以其他的具体形式实现本发明。因此,无论从哪一点来看,均应将实施例看作是示范性的,而且是非限制性的,本发明的范围由所附权利要求而不是上述说明限定,因此旨在将落在权利要求的等同要件的含义和范围内的所有变化涵括在本发明内。不应将权利要求中的任何附关联图标记视为限制所涉及的权利要求。此外,显然“包括”一词不排除其他单元或步骤,单数不排除复数。系统权利要求中陈述的多个单元或装置也可以由一个单元或装置通过软件或者硬件来实现。第二等词语用来表示名称,而并不表示任何特定的顺序。
最后应说明的是,以上实施例仅用以说明本发明的技术方案而非限制,尽管参照较佳实施例对本发明进行了详细说明,本领域的普通技术人员应当理解,可以对本发明的技术方案进行修改或等同替换,而不脱离本发明技术方案的精神和范围。
Claims (8)
- 一种伪无线接入点识别方法,应用于电子设备中,其特征在于,所述方法包括:当所述电子设备通过无线接入点连接无线网络后,监测文件操作是否有异常操作;当所述文件操作有异常操作时,确定所述无线接入点为伪无线接入点;及执行预警指令。
- 如权利要求1所述的伪无线接入点识别方法,其特征在于,所述文件操作包括以下一种或者多种:目标文件对应的操作及生成新文件操作,所述目标文件包括与用户隐私或财产安全相关的文件,所述目标文件对应的操作包括以下任一种或者多种:对所述目标文件的修改操作、读操作和写操作。
- 如权利要求2所述的伪无线接入点识别方法,其特征在于,所述异常操作包括以下一种或者多种:对所述目标文件对应的权限设置数据进行修改的操作;对所述目标文件的读操作或写操作中所读或写的所述目标文件的大小大于或等于预设值;在生成新文件操作中所生成的新文件不符合预设命名规则。
- 如权利要求1所述的伪无线接入点识别方法,其特征在于,所述预警指令包括以下一种或者多种:退出所述电子设备中所有应用程序的登录账户;冻结与所述目标文件相关联的操作;断开与所述无线接入点的连接;提示用户所述无线接入点是伪无线接入点;禁止任何操作访问所述电子设备中的安全数位卡。
- 一种伪无线接入点识别系统,运行于电子设备中,其特征在于,所述系统包括:监测模块,设置为当所述电子设备通过无线接入点连接无线网络后,监测文件操作是否有异常操作;确定模块,设置为当所述文件操作有异常操作时,确定所述无线接入点为伪无线接入点;及预警模块,设置为执行预警指令。
- 如权利要求5所述的伪无线接入点识别系统,其特征在于,所述文件操作包括以下一种或者多种:目标文件对应的操作及生成新文件操作,所述目标文件包括与用户隐私或财产安全相关的文件,所述目标文件对应的操作包括以下任一种或者多种:对所述目标文件的修改操作、读操作和写操作。
- 如权利要求6所述的伪无线接入点识别系统,其特征在于,所述异常操作具体包括以下一种或者多种:对所述目标文件对应的权限设置数据进行修改的操作;对所述目标文件的读操作或写操作中所读或写的所述目标文件的大小大于或等于预设值;在生成新文件操作中所生成的新文件不符合预设命名规则。
- 如权利要求5所述的伪无线接入点识别系统,其特征在于,所述预警模块设置为执行预警指令包括以下一种或者多种:退出所述电子设备中所有应用程序的登录账户;冻结与所述目标文件相关联的操作;断开与所述无线接入点的连接;提示用户所述无线接入点是伪无线接入点;禁止任何操作访问所述电子设备中的安全数位卡。
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US16/345,352 US11019496B2 (en) | 2016-10-31 | 2016-12-30 | Method and electronic device for identifying a pseudo wireless access point |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201610932098.3A CN106412915A (zh) | 2016-10-31 | 2016-10-31 | 伪无线接入点识别方法及系统 |
| CN201610932098.3 | 2016-10-31 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2018076539A1 true WO2018076539A1 (zh) | 2018-05-03 |
Family
ID=58012525
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2016/113631 Ceased WO2018076539A1 (zh) | 2016-10-31 | 2016-12-30 | 伪无线接入点识别方法及系统 |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US11019496B2 (zh) |
| CN (1) | CN106412915A (zh) |
| WO (1) | WO2018076539A1 (zh) |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN104639522B (zh) * | 2013-11-15 | 2018-12-14 | 华为终端(东莞)有限公司 | 一种网络访问控制方法及装置 |
| US12081985B2 (en) * | 2021-10-27 | 2024-09-03 | Hewlett Packard Enterprise Development Lp | Broadcast of intrusion detection information |
Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1623144A (zh) * | 2002-03-27 | 2005-06-01 | 国际商业机器公司 | 用于无线接入点的方法、设备和程序产品 |
| CN102273174A (zh) * | 2009-01-05 | 2011-12-07 | 高通股份有限公司 | 对伪造无线接入点的检测 |
| WO2013046849A1 (ja) * | 2011-09-30 | 2013-04-04 | インターナショナル・ビジネス・マシーンズ・コーポレーション | 不正なアクセスポイントを監視する監視システム、監視サーバ、方法およびプログラム |
| CN103891331A (zh) * | 2011-10-17 | 2014-06-25 | 迈可菲公司 | 移动风险评估 |
| CN105636048A (zh) * | 2014-11-04 | 2016-06-01 | 中兴通讯股份有限公司 | 一种终端及其识别伪基站的方法、装置 |
| CN105704718A (zh) * | 2014-11-25 | 2016-06-22 | 中兴通讯股份有限公司 | 鉴别伪基站的方法和装置 |
Family Cites Families (23)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7058796B2 (en) * | 2002-05-20 | 2006-06-06 | Airdefense, Inc. | Method and system for actively defending a wireless LAN against attacks |
| US7069024B2 (en) * | 2003-10-31 | 2006-06-27 | Symbol Technologies, Inc. | System and method for determining location of rogue wireless access point |
| CA2807829C (en) * | 2004-11-04 | 2017-10-10 | Topeer Corporation | System and method for creating a secure trusted social network |
| CN100374972C (zh) * | 2005-08-03 | 2008-03-12 | 珠海金山软件股份有限公司 | 一种检测和防御计算机恶意程序的系统和方法 |
| US20070039043A1 (en) * | 2005-08-11 | 2007-02-15 | Sbc Knowledge Ventures L.P. | Distributed global log off for a single sign-on account |
| US20070186276A1 (en) * | 2006-02-09 | 2007-08-09 | Mcrae Matthew | Auto-detection and notification of access point identity theft |
| US7865717B2 (en) * | 2006-07-18 | 2011-01-04 | Motorola, Inc. | Method and apparatus for dynamic, seamless security in communication protocols |
| US8069483B1 (en) * | 2006-10-19 | 2011-11-29 | The United States States of America as represented by the Director of the National Security Agency | Device for and method of wireless intrusion detection |
| US7991877B2 (en) * | 2007-10-05 | 2011-08-02 | International Business Machines Corporation | Rogue router hunter |
| US20100074112A1 (en) * | 2008-09-25 | 2010-03-25 | Battelle Energy Alliance, Llc | Network traffic monitoring devices and monitoring systems, and associated methods |
| WO2010150052A2 (en) * | 2009-06-24 | 2010-12-29 | Nokia Corporation | Methods and apparatuses for avoiding denial of service attacks by rogue access points |
| US9137255B2 (en) * | 2011-06-30 | 2015-09-15 | Marvell World Trade Ltd. | Verifying server identity |
| US9432402B1 (en) * | 2011-09-06 | 2016-08-30 | Utility Associates, Inc. | System and method for uploading files to servers utilizing GPS routing |
| EP2600648A1 (en) * | 2011-11-30 | 2013-06-05 | British Telecommunications public limited company | Rogue access point detection |
| US9578508B2 (en) * | 2013-03-13 | 2017-02-21 | Qualcomm Incorporated | Method and apparatus for wireless device countermeasures against malicious infrastructure |
| US8788405B1 (en) * | 2013-03-15 | 2014-07-22 | Palantir Technologies, Inc. | Generating data clusters with customizable analysis strategies |
| CN104135561B (zh) * | 2013-07-08 | 2016-03-16 | 腾讯科技(深圳)有限公司 | 一种终端的流量提醒方法、装置及终端 |
| US20150139211A1 (en) * | 2013-11-19 | 2015-05-21 | Huawei Technologies Co., Ltd. | Method, Apparatus, and System for Detecting Rogue Wireless Access Point |
| CN104113842B (zh) * | 2014-07-31 | 2017-10-24 | 北京金山安全软件有限公司 | 识别伪无线网络接入点的方法、装置、服务器及移动终端 |
| US20160112871A1 (en) * | 2014-10-17 | 2016-04-21 | Christopher Jules White | Method and Systems for Placing Physical Boundaries on Information Access/Storage, Transmission and Computation of Mobile Devices |
| US9609517B2 (en) * | 2014-12-19 | 2017-03-28 | Intel Corporation | Cooperative security in wireless sensor networks |
| CN105554762B (zh) * | 2015-12-10 | 2019-01-04 | 广东工业大学 | 基于rss的无线欺骗攻击定位方法 |
| CN105873068B (zh) * | 2016-06-17 | 2020-02-11 | 珠海市魅族科技有限公司 | 一种识别伪基站的方法和装置 |
-
2016
- 2016-10-31 CN CN201610932098.3A patent/CN106412915A/zh active Pending
- 2016-12-30 US US16/345,352 patent/US11019496B2/en active Active
- 2016-12-30 WO PCT/CN2016/113631 patent/WO2018076539A1/zh not_active Ceased
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1623144A (zh) * | 2002-03-27 | 2005-06-01 | 国际商业机器公司 | 用于无线接入点的方法、设备和程序产品 |
| CN102273174A (zh) * | 2009-01-05 | 2011-12-07 | 高通股份有限公司 | 对伪造无线接入点的检测 |
| WO2013046849A1 (ja) * | 2011-09-30 | 2013-04-04 | インターナショナル・ビジネス・マシーンズ・コーポレーション | 不正なアクセスポイントを監視する監視システム、監視サーバ、方法およびプログラム |
| CN103891331A (zh) * | 2011-10-17 | 2014-06-25 | 迈可菲公司 | 移动风险评估 |
| CN105636048A (zh) * | 2014-11-04 | 2016-06-01 | 中兴通讯股份有限公司 | 一种终端及其识别伪基站的方法、装置 |
| CN105704718A (zh) * | 2014-11-25 | 2016-06-22 | 中兴通讯股份有限公司 | 鉴别伪基站的方法和装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| US20190251285A1 (en) | 2019-08-15 |
| CN106412915A (zh) | 2017-02-15 |
| US11019496B2 (en) | 2021-05-25 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2016190476A1 (ko) | 클라우드 서비스를 위한 암호화 키 관리 방법 및 그 장치 | |
| WO2012015171A2 (ko) | 해커 바이러스 보안통합관리기 | |
| JP6596596B2 (ja) | ドメイン名サービストラフィック分析を介してマルウェア感染を検出するためのシステム及び方法 | |
| WO2018056601A1 (ko) | 콘텐츠 파일 접근 제어를 이용한 랜섬웨어 차단 장치 및 차단 방법 | |
| WO2018107811A1 (zh) | 网络安全联合防御方法、装置、服务器和存储介质 | |
| WO2016169390A1 (zh) | 应用安全防护方法、终端、存储介质 | |
| WO2013100320A1 (ko) | 시스템 파일 보호 및 복구를 위한 장치, 방법, 사용자 단말기 및 시스템 | |
| WO2017034072A1 (ko) | 네트워크 보안 시스템 및 보안 방법 | |
| WO2019212111A1 (ko) | 비정상 프로세스 감시 및 통제 시스템 및 방법, 상기 방법을 수행하기 위한 기록 매체 | |
| WO2018030667A1 (ko) | 피싱 또는 랜섬웨어 공격을 차단하는 방법 및 시스템 | |
| WO2018094809A1 (zh) | 一种资源共享方法及装置 | |
| EP3850521A1 (en) | Electronic apparatus managing data based on block chain and method for managing data | |
| WO2018164503A1 (ko) | 상황 인식 기반의 랜섬웨어 탐지 | |
| WO2018212474A1 (ko) | 독립된 복원영역을 갖는 보조기억장치 및 이를 적용한 기기 | |
| WO2019039730A1 (ko) | 랜섬웨어 방지 장치 및 방법 | |
| WO2020077832A1 (zh) | 云桌面的访问方法、装置、设备及存储介质 | |
| WO2016072760A1 (ko) | 전가상화 시스템에서 자원을 감시하는 장치 및 방법 | |
| WO2020258672A1 (zh) | 网络访问的异常检测方法和装置 | |
| WO2019225849A1 (ko) | 게스트 운영체제의 무결성과 파일 입출력 제어를 통해서 보안 서비스를 제공하는 보안 장치 및 방법 | |
| WO2018053903A1 (zh) | 文件管理方法、文件管理装置及移动终端 | |
| WO2018043832A1 (ko) | 보안 웹브라우저 동작 방법 | |
| WO2014077615A1 (en) | Anti-malware system, method of processing packet in the same, and computing device | |
| WO2018076539A1 (zh) | 伪无线接入点识别方法及系统 | |
| WO2019103443A1 (en) | Method, apparatus and system for managing electronic fingerprint of electronic file | |
| WO2019124770A1 (ko) | 단말 장치 및 단말 장치의 제어 방법 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 16919893 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 16919893 Country of ref document: EP Kind code of ref document: A1 |