WO2010027121A1 - System and method for preventing wireless lan intrusion - Google Patents
System and method for preventing wireless lan intrusion Download PDFInfo
- Publication number
- WO2010027121A1 WO2010027121A1 PCT/KR2008/005765 KR2008005765W WO2010027121A1 WO 2010027121 A1 WO2010027121 A1 WO 2010027121A1 KR 2008005765 W KR2008005765 W KR 2008005765W WO 2010027121 A1 WO2010027121 A1 WO 2010027121A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- wlan
- wlan device
- malicious
- sensor
- monitoring information
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/28—Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/12—Detection or prevention of fraud
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/12—Discovery or management of network topologies
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/60—Context-dependent security
- H04W12/63—Location-dependent; Proximity-dependent
Definitions
- the present invention relates to a wireless local area network (WLAN) intrusion preventing system.
- WLAN wireless local area network
- the present invention relates to a WLAN intrusion preventing system for sensing and intercepting an illegal trial regarding a WLAN system in a security area.
- a wireless local area network (WLAN) system includes a WLAN access point (AP) and a WLAN terminal.
- AP WLAN access point
- WLAN terminal a WLAN terminal
- the AP in the WLAN system and the WLAN terminal are authenticated and encrypted. Accordingly, an AP outside the WLAN system or a WLAN terminal may problematically access a WLAN terminal in the WLAN security area to take information in the WLAN security area. Disclosure of Invention Technical Problem
- the present invention has been made in an effort to provide a system and method for preventing intrusion to the WLAN system by sensing and monitoring WLAN devices in the WLAN area.
- An exemplary embodiment of the present invention provides a WLAN intrusion preventing method including: receiving a plurality of WLAN monitoring information on a WLAN device from a plurality of sensors; determining whether the WLAN device is a malicious WLAN device based on the plurality of WLAN monitoring information; generating position information of the malicious WLAN device based on the plurality of WLAN monitoring information when the WLAN device is a malicious WLAN device; generating a communication intercepting message on the malicious WLAN device; and transmitting the communication intercepting message to the plurality of sensors so that the malicious WLAN device may stop communication according to the communication intercepting message.
- the plurality of WLAN monitoring information respectively includes signal strength on the WLAN device, and the generating of position information includes generating the position information based on a plurality of distances corresponding to a plurality of signal strengths included in the plurality of WLAN monitoring information.
- the transmitting of a communication intercepting message includes transmitting the communication intercepting message to a sensor that is the nearest sensor from the malicious WLAN device from among the plurality of sensors based on the position information.
- Another embodiment of the present invention provides a WLAN intrusion preventing method including: receiving a plurality of WLAN monitoring information respectively corresponding to a plurality of WLAN devices from a plurality of sensors; detecting a malicious WLAN device from among the plurality of WLAN devices based on the plurality of WLAN monitoring information; generating a communication intercepting message corresponding to the malicious WLAN device; and transmitting the communication intercepting message to some of sensors from among the plurality of sensors so that some of sensors transmit the communication intercepting message to the plurality of WLAN devices.
- the detecting includes determining a WLAN device using a hacking tool to be the malicious WLAN device when the WLAN device using the hacking tool is found from among the plurality of WLAN devices.
- the detecting includes determining a WLAN device performing a denial of service attack to be the malicious WLAN device when the WLAN device performing a denial of service attack is found from among the plurality of WLAN devices.
- the detecting includes determining a WLAN device that does not use an authentication method or an encryption method included in an allowed authentication method list or an allowed encryption method list to be the malicious WLAN device from among the plurality of WLAN devices.
- the detecting includes determining a WLAN device that does not use a communication protocol included in an allowed communication protocol list to be the malicious WLAN device from among the plurality of WLAN devices.
- the detecting includes determining a WLAN device communicating with another
- WLAN device that is not included in the allowed device list to be the malicious WLAN device from among the plurality of WLAN devices.
- Yet another embodiment of the present invention provides a WLAN intrusion preventing system including: a WLAN device for transmitting a packet through a radio channel; a sensor for generating WLAN monitoring information based on the packet transmitted by the WLAN device, and controlling the WLAN device; and a sensor management server for generating WLAN intrusion information corresponding to the WLAN monitoring information, and controlling the sensor.
- the WLAN intrusion preventing system further includes a surveillance terminal for controlling the sensor management server according to a WLAN control instruction corresponding to the WLAN intrusion information.
- the sensor management server includes: a WLAN system monitor for receiving the WLAN monitoring information from the sensor, generating the WLAN intrusion information corresponding to the WLAN monitoring information, and transmitting the WLAN intrusion information to the surveillance terminal; and a sensor controller for receiving the WLAN control instruction from the surveillance terminal, generating a WLAN control message corresponding to the WLAN control instruction, and transmitting the WLAN control message to the sensor.
- the sensor includes: a WLAN device monitor for collecting the packet transmitted by the WLAN device, extracting the WLAN monitoring information corresponding to the WLAN device from the collected packet, and transmitting the WLAN monitoring information to the sensor management server; and a WLAN device controller for receiving the WLAN control message from the sensor management server, and transmitting the WLAN control message to the WLAN device.
- the WLAN intrusion preventing system monitors packets of WLAN devices by using a sensor to intercept communication of malicious WLAN devices and prevent leakage of information outside the WLAN system.
- FIG. 1 shows a schematic diagram of a wireless local area network (WLAN) intrusion preventing system according to an exemplary embodiment of the present invention.
- WLAN wireless local area network
- FIG. 2 shows a schematic diagram of a sensor according to an exemplary embodiment of the present invention.
- FIG. 3 shows a schematic diagram of a sensor management server according to an exemplary embodiment of the present invention.
- FIG. 4 shows a schematic diagram of a surveillance terminal according to an exemplary embodiment of the present invention.
- FIG. 5 shows a flowchart of a wireless local area network (WLAN) intrusion preventing method according to an exemplary embodiment of the present invention.
- WLAN wireless local area network
- FIG. 6 shows a method for a position information generator according to an exemplary embodiment of the present invention to generate position information of a malicious wireless local area network (WLAN) device.
- WLAN wireless local area network
- a wireless local area network (WLAN) intrusion preventing system and method according to an exemplary embodiment of the present invention will now be described in detail with reference to accompanying drawings.
- a wireless local area network (WLAN) intrusion preventing system according to an exemplary embodiment of the present invention will now be described with reference to FIG. 1.
- FIG. 1 A wireless local area network (WLAN) intrusion preventing system according to an exemplary embodiment of the present invention will now be described with reference to FIG. 1.
- the WLAN intrusion preventing system includes a WLAN system 100, a sensor management server 200, and a surveillance terminal 300.
- the WLAN system 100 includes a plurality of WLAN devices 110 and a plurality of sensors 130.
- the WLAN system 100 forms a wireless network including the plurality of WLAN devices 110.
- the WLAN device 110 forms the wireless network, and communicates data with another WLAN device 110 through the wireless network.
- the WLAN device 110 can encrypt data and transmit the encrypted data according to a predefined encryption method.
- the WLAN device 110 includes an access point (AP), a wire/wireless IP router, a wireless LAN card, a wireless printer, an antenna, and a wireless network camera.
- AP access point
- the sensor 130 monitors and controls the WLAN device 110.
- the sensor 130 monitors the WLAN device 110 through the packets transmitted by the WLAN device
- the sensor management server 200 monitors the WLAN system 100 through the sensor 130, and controls the sensor 130 according to control by the surveillance terminal 300.
- the surveillance terminal 300 controls the server 200. In this instance, the surveillance terminal 300 can control the sensor management server 200 through the communication network. Also, the surveillance terminal 300 can be included in the sensor management server 200.
- FIG. 2 shows a schematic diagram of a sensor according to an exemplary embodiment of the present invention.
- the sensor 130 includes a WLAN device monitor 131 and a
- WLAN device controller 133
- the WLAN device monitor 131 monitors the WLAN device 110 through the packets transmitted by the WLAN device 110.
- the WLAN device monitor 131 includes a packet collector 131a, a WLAN monitoring information extractor 131b, and a WLAN monitoring information transmitter 131c.
- the packet collector 131a collects the packets transmitted by the WLAN device 110.
- the WLAN monitoring information extractor 131b extracts WLAN monitoring information corresponding to the WLAN device 110 from the packets collected by the packet collector 131a.
- the WLAN monitoring information transmitter 131c transmits the WLAN monitoring information extracted by the WLAN monitoring information extractor 131b to the sensor management server 200.
- the WLAN device controller 133 controls the WLAN device 110 according to control by the sensor management server 200.
- the WLAN device controller 133 includes a WLAN control message receiver 133a and a WLAN control message transmitter 133b.
- the WLAN control message receiver 133a receives a WLAN control message from the sensor management server 200.
- the WLAN control message transmitter 133b transmits the WLAN control message received by the WLAN control message receiver 133a to the WLAN device 110.
- a sensor management server of a WLAN intrusion preventing system will now be described with reference to FIG. 3.
- FIG. 3 shows a schematic diagram of a sensor management server according to an exemplary embodiment of the present invention.
- the sensor management server 200 includes a WLAN system monitor 210 and a sensor controller 230.
- the WLAN system monitor 210 monitors the WLAN system 100 through the plurality of sensors 130.
- WLAN system monitor 210 includes a WLAN monitoring information receiver 211, a malicious WLAN device detector 213, a position information generator 215, a WLAN intrusion information generator 217, and a WLAN intrusion information transmitter 219.
- the WLAN monitoring information receiver 211 receives WLAN monitoring information from the sensors 130.
- the WLAN monitoring information receiver 211 can receive WLAN monitoring information on a WLAN device 110 from the plurality of sensors 130.
- the WLAN monitoring information receiver 211 can receive WLAN monitoring information corresponding to a plurality of WLAN devices 100 from one sensor 130.
- the malicious WLAN device detector 213 detects a WLAN device (hereinafter, a malicious WLAN device) violating a security level of the WLAN system 100 based on WLAN monitoring information received by the WLAN monitoring information receiver 211.
- a WLAN device hereinafter, a malicious WLAN device
- the position information generator 215 generates position information of the malicious WLAN device detected by the malicious WLAN device detector 213 based on WLAN monitoring information.
- the WLAN intrusion information generator 217 generates WLAN intrusion information based on WLAN monitoring information and position information of the malicious WLAN device.
- the WLAN intrusion information transmitter 219 transmits WLAN intrusion information to the surveillance terminal 300.
- the sensor controller 230 controls the sensor 130 according to control by the surveillance terminal 300.
- the sensor controller 230 includes a WLAN control instruction receiver 231, a WLAN control message generator 233, and a WLAN control message transmitter 235.
- the WLAN control instruction receiver 231 receives a WLAN control instruction from the surveillance terminal 300.
- the WLAN control message generator 233 generates a WLAN control message corresponding to the WLAN control instruction received by the WLAN control instruction receiver 231.
- the WLAN control message transmitter 235 transmits the WLAN control message generated by the WLAN control message generator 233 to the sensor 130.
- a surveillance terminal of a WLAN intrusion preventing system will now be described with reference to FIG. 4.
- FIG. 4 shows a schematic diagram of a surveillance terminal according to an exemplary embodiment of the present invention.
- the surveillance terminal 300 includes a WLAN intrusion information receiver 310, a WLAN intrusion information output unit 330, a WLAN control instruction input unit 350, and a WLAN control instruction transmitter 370.
- the WLAN intrusion information receiver 310 receives WLAN intrusion information from the sensor management server 200.
- the WLAN intrusion information output unit 330 outputs the WLAN intrusion information received by the WLAN intrusion information receiver 310.
- the WLAN control instruction input unit 350 receives a WLAN control instruction on WLAN intrusion information.
- the WLAN control instruction transmitter 370 transmits the WLAN control instruction to the sensor management server 200.
- FIG. 5 shows a flowchart of a WLAN intrusion preventing method according to an exemplary embodiment of the present invention.
- the WLAN device monitor 131 of the sensor 130 collects the packets (S 103).
- the packet collector 131a of the WLAN device monitor 131 collects the packets transmitted by the WLAN device 110.
- a plurality of sensors 130 can collect the packets transmitted by the WLAN device 110.
- the WLAN device monitor 131 of the sensor 130 extracts WLAN monitoring information from the collected packets (S 105).
- the WLAN monitoring information extractor 131b of the WLAN device monitor 131 extracts WLAN monitoring information from the packets collected by the packet collector 131a.
- the WLAN monitoring information extracted by the WLAN monitoring information extractor 131b includes WLAN device information and WLAN danger detecting information.
- the WLAN device information includes a WLAN device type, a MAC address, an
- IP address a communication method, signal strength, an encryption method, channel information, and a found time.
- the WLAN device type indicates a type of the WLAN device 110 having transmitted the packets.
- the MAC address represents a physical address of the WLAN device 110 having transmitted the packets.
- the IP address shows a network address of the WLAN device 110 having transmitted the packets.
- the communication method represents a communication method which is used when the WLAN device 110 transmits packets, and includes IEEE 802.1 Ia, IEEE 802.1 Ib, and IEEE 802.1 Ig.
- the signal strength indicates signal strength of the packets collected by the sensor.
- the encryption method represents the method by which the packets are encrypted, and includes wired equivalent privacy (WEP), temporal key integrity protocol (TKIP), phase shift keying (PSK), advanced encryption standard (AES), transport layer security (TLS), tunneled TLS (TTLS), and protected extensible authentication protocol (PEAP).
- the channel information indicates information on the channel used for the WLAN device 100 to transmit the packets.
- the found time is a time when the sensor 130 has found the WLAN device 110.
- the WLAN danger detecting information includes packet destination information, a hacking tool using state, authentication and encryption information, access point (AP) setting information, and a denial of service (DoS) attacking state.
- AP access point
- DoS denial of service
- the packet destination information represents the final destination of the packet.
- the hacking tool using state indicates whether the WLAN device 110 having transmitted the packet hacks information of another WLAN device 110 or uses a hacking tool so as to intrude on the network.
- the authentication and encryption information represents whether the WLAN device 110 having transmitted the packet performs authentication or encryption.
- the AP predetermined information indicates setting information on the AP for communicating with the WLAN device 110 having transmitted the packet.
- the DoS attacking state represents whether the WLAN device 110 transmitting the packets is attacked by a denial of service or attempts to attack by a denial of service.
- the WLAN system monitor 210 of the sensor management server 200 receives the WLAN monitoring information (S 107).
- the WLAN monitoring information transmitter 131c of the WLAN device monitor 131 transmits the WLAN monitoring information to the sensor management server 200
- the WLAN monitoring information receiver 211 of the WLAN system monitor 210 receives the WLAN monitoring information from the sensor 200.
- the sensor management server 200 can receive WLAN monitoring information corresponding to a plurality of WLAN devices 110 from the sensor 130. Further, the sensor management server 200 can receive WLAN monitoring information for one WLAN device 110 from a plurality of sensors 130.
- the WLAN system monitor 210 of the sensor management server 200 detects a malicious WLAN device based on the WLAN monitoring information (S 109).
- the malicious WLAN device detector 213 of the WLAN system monitor 210 detects a malicious WLAN device based on the WLAN monitoring information.
- the malicious WLAN device detector 213 detects a malicious WLAN device from among the plurality of WLAN devices 110 by searching for WLAN monitoring information.
- the malicious WLAN device is predefined depending on the security level of the WLAN system 100.
- WLAN device detector to detect a malicious WLAN device will now be described.
- Cases corresponding to a malicious WLAN device includes a case in which the
- WLAN device 110 communicates with a disallowed WLAN device, a case in which the WLAN device 110 follows a disallowed authentication method or a disallowed en- cryption method, a case in which the WLAN device 110 uses a WLAN hacking tool, a case in which the WLAN device 110 uses a WLAN DoS attack, and a case in which the WLAN device 110 uses a disallowed communication protocol.
- the WLAN device 110 can communicate with a terminal or an AP outside the WLAN system 100, and the WLAN device 110 can communicate with an authenticated terminal or an AP inside the WLAN system 100.
- the malicious WLAN device detector 213 determines the WLAN device 110 communicating with a WLAN device not included in a communication allowable device list as a malicious illegal WLAN device based on WLAN monitoring information.
- the communication allowable device list can be predefined.
- the malicious WLAN device detector 213 can receive the communication allowable device list from the surveillance terminal 300.
- the surveillance terminal 300 can periodically update the communication allowable device list.
- the case in which the WLAN device 110 follows a disallowed authentication method or a disallowed encryption method includes a case in which the WLAN device 110 does not follow a predefined authentication method and inner information of the WLAN device 110 is leaked, and a case in which the WLAN device 110 does not follow a predefined encryption method but transmits packets to leak packet information.
- the malicious WLAN device detector 213 determines a WLAN device 110 that does not use an authentication method or an encryption method included in the allowed authentication method list or the allowed encryption method list based on WLAN monitoring information to be a malicious WLAN device.
- the allowed authentication method list or the allowed encryption method list can be predefined.
- the malicious WLAN device detector 213 can receive the allowed authentication method list or the allowed encryption method list from the surveillance terminal 300. Further, the surveillance terminal 300 can periodically update the allowed authentication method list and the allowed encryption method list.
- a case in which the WLAN device 110 uses a WLAN hacking tool includes a case in which a WLAN hacking tool is installed in the WLAN device 110 to leak information on the WLAN device 110 to the outside of the WLAN system 100.
- the malicious WLAN device detector 213 determines the WLAN device 110 using a WLAN hacking tool as a malicious WLAN device based on WLAN monitoring information.
- the case in which the WLAN device 110 attacks the WLAN DoS includes a case in which the WLAN device 110 directly performs the WLAN DoS attack and a case in which the WLAN device outside the WLAN system 100 controls the WLAN device 110 to perform a DoS attack.
- the malicious WLAN device detector 213 determines the WLAN device 110 performing a DoS attack to be a malicious WLAN device based on WLAN monitoring information.
- the malicious WLAN device detector 213 determines the WLAN device 110 that does not use a communication protocol included in the allowed communication protocol list to be a malicious WLAN device based on WLAN monitoring information.
- the allowed communication protocol list can be predefined.
- the malicious WLAN device detector 213 can receive the allowed communication protocol list from the surveillance terminal 300. Further, the surveillance terminal 300 can periodically update the allowed communication protocol list.
- the WLAN system monitor 210 of the sensor management server 200 generates position information of the malicious WLAN device (Si l l).
- the position information generator 215 of the WLAN system monitor 210 generates position information on the malicious WLAN device detected by the malicious WLAN device detector 213 based on WLAN monitoring information.
- a method for a position information generator of a WLAN system monitor according to an exemplary embodiment of the present invention to generate position information of a malicious WLAN device will now be described with reference to FIG. 6.
- FIG. 6 shows a method for a position information generator according to an exemplary embodiment of the present invention to generate position information of a malicious WLAN device.
- the position information generator 215 generates position information of the malicious WLAN device through signal strength included in the WLAN monitoring information.
- the position information generator 215 converts the three types of signal strength into respective distances to generate distances d u d 2 , and d 3 from the three sensors to the device corresponding to the three sensors S 1 , S 2 , and S 3 .
- the position information generator 290 sets positions of the three sensors S 1 , S 2 , and
- S 3 respectively corresponding to the three sensors 130 as central points, and determines a cross point through which three circles with the three distances d u d 2 , and d 3 as their radii corresponding to the three sensors 130 pass to be the position of the WLAN device 110.
- sensor positions corresponding to the respective sensors 130 are predefined. Further, the distances depending on the signal strength can be predefined.
- the WLAN system monitor 210 of the sensor management server 200 generates
- the WLAN intrusion information generator 217 of the WLAN system monitor 210 generates WLAN intrusion information on the malicious WLAN device based on WLAN monitoring information and position information of the malicious WLAN device.
- the WLAN intrusion information includes WLAN monitoring information and position information of the malicious WLAN device.
- the surveillance terminal 300 receives the WLAN intrusion information (Sl 15).
- the WLAN intrusion information transmitter 219 of the WLAN system monitor 210 transmits WLAN intrusion information
- the WLAN intrusion information receiver 310 of the surveillance terminal 300 receives WLAN intrusion information.
- the WLAN intrusion information output unit 330 of the surveillance terminal 300 outputs the WLAN intrusion information received by the WLAN intrusion information receiver 310 (Sl 17).
- the WLAN intrusion information output unit 330 outputs the WLAN intrusion information so that the user may view it.
- the WLAN control instruction input unit 350 of the surveillance terminal 300 inputs a communication intercepting instruction (Sl 19).
- the WLAN control instruction input unit 350 interfaces with the user to input a communication intercepting instruction for the malicious WLAN device according to WLAN intrusion information.
- the WLAN control instruction input unit 350 inputs the communication intercepting instruction for preventing communication by the malicious WLAN device.
- the sensor controller 230 of the sensor management server 200 receives the communication intercepting instruction (S 121).
- the WLAN control instruction receiver 231 of the sensor controller 230 performs the communication intercepting instruction.
- the sensor controller 230 of the sensor management server 200 generates a communication intercepting message (S 123).
- the WLAN control message generator 233 of the sensor controller 230 generates a communication intercepting message according to the communication intercepting instruction.
- the communication intercepting message can include a MAC address or IP address of the malicious WLAN device.
- the WLAN device controller 133 of the sensor 130 receives the communication intercepting message (S 125).
- the WLAN control message transmitter 235 of the sensor controller 230 transmits the communication intercepting message to the sensor 130, and the WLAN control message receiver 133a of the WLAN device controller 133 receives the communication intercepting message from the sensor management server 200.
- the WLAN control message transmitter 235 can transmit the communication intercepting message to the sensor that is nearest the malicious WLAN device based on the position information of the malicious WLAN device.
- the WLAN device controller 133 of the sensor 130 transmits the communication intercepting message to the WLAN device 110
- the WLAN device 110 receives the communication intercepting message (S 127).
- the WLAN control message transmitter 133b of the WLAN device controller 133 can transmit the communication intercepting message to the WLAN device 110 corresponding to the MAC address or IP address included in the communication intercepting message.
- the sensor 130 can transmit the communication intercepting message to the WLAN device communicating with the malicious WLAN device.
- the sensor 130 can transmit the communication intercepting message to the WLAN devices 110 in the WLAN system 100.
- the WLAN device 110 stops communication according to the communication intercepting message (S 129).
- the WLAN intrusion preventing system monitors the packets of the WLAN device through the sensor to intercept communication of the malicious WLAN device and prevent information from being leaked outside the WLAN system.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Small-Scale Networks (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
A WLAN intrusion preventing system receives a plurality of WLAN monitoring information on a WLAN device from a plurality of sensors installed in a security area, and determines whether the WLAN device is a malicious WLAN device based on the plurality of WLAN monitoring information. When the WLAN device is a malicious WLAN device, the system generates position information of the malicious WLAN device based on the plurality of WLAN monitoring information and generates a communication intercepting message for the malicious WLAN device. The system transmits the communication intercepting message to the plurality of sensors to stop communication of the malicious WLAN device according to the communication intercepting message. Therefore, the WLAN intrusion preventing system prevents information in the security area from being leaked to the outside through the WLAN.
Description
Description
SYSTEM AND METHOD FOR PREVENTING WIRELESS LAN
INTRUSION
Technical Field
[1] The present invention relates to a wireless local area network (WLAN) intrusion preventing system. Particularly, the present invention relates to a WLAN intrusion preventing system for sensing and intercepting an illegal trial regarding a WLAN system in a security area. Background Art
[2] A wireless local area network (WLAN) system includes a WLAN access point (AP) and a WLAN terminal. In this instance, when the WLAN system follows the WLAN security standard proposed by the IEEE 802.1 Ii, the AP in the WLAN system and the WLAN terminal are authenticated and encrypted. Accordingly, an AP outside the WLAN system or a WLAN terminal may problematically access a WLAN terminal in the WLAN security area to take information in the WLAN security area. Disclosure of Invention Technical Problem
[3] The present invention has been made in an effort to provide a system and method for preventing intrusion to the WLAN system by sensing and monitoring WLAN devices in the WLAN area. Technical Solution
[4] An exemplary embodiment of the present invention provides a WLAN intrusion preventing method including: receiving a plurality of WLAN monitoring information on a WLAN device from a plurality of sensors; determining whether the WLAN device is a malicious WLAN device based on the plurality of WLAN monitoring information; generating position information of the malicious WLAN device based on the plurality of WLAN monitoring information when the WLAN device is a malicious WLAN device; generating a communication intercepting message on the malicious WLAN device; and transmitting the communication intercepting message to the plurality of sensors so that the malicious WLAN device may stop communication according to the communication intercepting message.
[5] The plurality of WLAN monitoring information respectively includes signal strength on the WLAN device, and the generating of position information includes generating the position information based on a plurality of distances corresponding to a plurality of signal strengths included in the plurality of WLAN monitoring information.
[6] The transmitting of a communication intercepting message includes transmitting the
communication intercepting message to a sensor that is the nearest sensor from the malicious WLAN device from among the plurality of sensors based on the position information.
[7] Another embodiment of the present invention provides a WLAN intrusion preventing method including: receiving a plurality of WLAN monitoring information respectively corresponding to a plurality of WLAN devices from a plurality of sensors; detecting a malicious WLAN device from among the plurality of WLAN devices based on the plurality of WLAN monitoring information; generating a communication intercepting message corresponding to the malicious WLAN device; and transmitting the communication intercepting message to some of sensors from among the plurality of sensors so that some of sensors transmit the communication intercepting message to the plurality of WLAN devices.
[8] The detecting includes determining a WLAN device using a hacking tool to be the malicious WLAN device when the WLAN device using the hacking tool is found from among the plurality of WLAN devices.
[9] The detecting includes determining a WLAN device performing a denial of service attack to be the malicious WLAN device when the WLAN device performing a denial of service attack is found from among the plurality of WLAN devices.
[10] The detecting includes determining a WLAN device that does not use an authentication method or an encryption method included in an allowed authentication method list or an allowed encryption method list to be the malicious WLAN device from among the plurality of WLAN devices.
[11] The detecting includes determining a WLAN device that does not use a communication protocol included in an allowed communication protocol list to be the malicious WLAN device from among the plurality of WLAN devices.
[12] The detecting includes determining a WLAN device communicating with another
WLAN device that is not included in the allowed device list to be the malicious WLAN device from among the plurality of WLAN devices.
[13] Yet another embodiment of the present invention provides a WLAN intrusion preventing system including: a WLAN device for transmitting a packet through a radio channel; a sensor for generating WLAN monitoring information based on the packet transmitted by the WLAN device, and controlling the WLAN device; and a sensor management server for generating WLAN intrusion information corresponding to the WLAN monitoring information, and controlling the sensor.
[14] The WLAN intrusion preventing system further includes a surveillance terminal for controlling the sensor management server according to a WLAN control instruction corresponding to the WLAN intrusion information.
[15] The sensor management server includes: a WLAN system monitor for receiving the
WLAN monitoring information from the sensor, generating the WLAN intrusion information corresponding to the WLAN monitoring information, and transmitting the WLAN intrusion information to the surveillance terminal; and a sensor controller for receiving the WLAN control instruction from the surveillance terminal, generating a WLAN control message corresponding to the WLAN control instruction, and transmitting the WLAN control message to the sensor.
[16] The sensor includes: a WLAN device monitor for collecting the packet transmitted by the WLAN device, extracting the WLAN monitoring information corresponding to the WLAN device from the collected packet, and transmitting the WLAN monitoring information to the sensor management server; and a WLAN device controller for receiving the WLAN control message from the sensor management server, and transmitting the WLAN control message to the WLAN device.
Advantageous Effects
[17] According to an embodiment of the present invention, the WLAN intrusion preventing system monitors packets of WLAN devices by using a sensor to intercept communication of malicious WLAN devices and prevent leakage of information outside the WLAN system. Brief Description of Drawings
[18] FIG. 1 shows a schematic diagram of a wireless local area network (WLAN) intrusion preventing system according to an exemplary embodiment of the present invention.
[19] FIG. 2 shows a schematic diagram of a sensor according to an exemplary embodiment of the present invention.
[20] FIG. 3 shows a schematic diagram of a sensor management server according to an exemplary embodiment of the present invention.
[21] FIG. 4 shows a schematic diagram of a surveillance terminal according to an exemplary embodiment of the present invention.
[22] FIG. 5 shows a flowchart of a wireless local area network (WLAN) intrusion preventing method according to an exemplary embodiment of the present invention.
[23] FIG. 6 shows a method for a position information generator according to an exemplary embodiment of the present invention to generate position information of a malicious wireless local area network (WLAN) device. Mode for the Invention
[24] In the following detailed description, only certain exemplary embodiments of the present invention have been shown and described, simply by way of illustration. As those skilled in the art would realize, the described embodiments may be modified in various different ways, all without departing from the spirit or scope of the present
invention. Accordingly, the drawings and description are to be regarded as illustrative in nature and not restrictive. Like reference numerals designate like elements throughout the specification. [25] Throughout the specification, unless explicitly described to the contrary, the word
"comprise" and variations such as "comprises" or "comprising" will be understood to imply the inclusion of stated elements but not the exclusion of any other elements. In addition, the terms "Der", "Dor", and "module" described in the specification mean units for processing at least one function and operation and can be implemented by hardware components or software components and combinations thereof. [26] A wireless local area network (WLAN) intrusion preventing system and method according to an exemplary embodiment of the present invention will now be described in detail with reference to accompanying drawings. [27] A wireless local area network (WLAN) intrusion preventing system according to an exemplary embodiment of the present invention will now be described with reference to FIG. 1. [28] FIG. 1 shows a schematic diagram of a wireless local area network (WLAN) intrusion preventing system according to an exemplary embodiment of the present invention. [29] As shown in FIG. 1, the WLAN intrusion preventing system includes a WLAN system 100, a sensor management server 200, and a surveillance terminal 300. [30] The WLAN system 100 includes a plurality of WLAN devices 110 and a plurality of sensors 130. The WLAN system 100 forms a wireless network including the plurality of WLAN devices 110. [31] The WLAN device 110 forms the wireless network, and communicates data with another WLAN device 110 through the wireless network. The WLAN device 110 can encrypt data and transmit the encrypted data according to a predefined encryption method. The WLAN device 110 includes an access point (AP), a wire/wireless IP router, a wireless LAN card, a wireless printer, an antenna, and a wireless network camera. [32] The sensor 130 monitors and controls the WLAN device 110. The sensor 130 monitors the WLAN device 110 through the packets transmitted by the WLAN device
110, and controls the WLAN device 110 according to control by the sensor management server 200. [33] The sensor management server 200 monitors the WLAN system 100 through the sensor 130, and controls the sensor 130 according to control by the surveillance terminal 300. [34] The surveillance terminal 300 controls the server 200. In this instance, the surveillance terminal 300 can control the sensor management server 200 through the
communication network. Also, the surveillance terminal 300 can be included in the sensor management server 200.
[35] A sensor of a WLAN system according to an exemplary embodiment of the present invention will now be described with reference to FIG. 2.
[36] FIG. 2 shows a schematic diagram of a sensor according to an exemplary embodiment of the present invention.
[37] As shown in FIG. 2, the sensor 130 includes a WLAN device monitor 131 and a
WLAN device controller 133.
[38] The WLAN device monitor 131 monitors the WLAN device 110 through the packets transmitted by the WLAN device 110. The WLAN device monitor 131 includes a packet collector 131a, a WLAN monitoring information extractor 131b, and a WLAN monitoring information transmitter 131c.
[39] The packet collector 131a collects the packets transmitted by the WLAN device 110.
[40] The WLAN monitoring information extractor 131b extracts WLAN monitoring information corresponding to the WLAN device 110 from the packets collected by the packet collector 131a.
[41] The WLAN monitoring information transmitter 131c transmits the WLAN monitoring information extracted by the WLAN monitoring information extractor 131b to the sensor management server 200.
[42] The WLAN device controller 133 controls the WLAN device 110 according to control by the sensor management server 200. The WLAN device controller 133 includes a WLAN control message receiver 133a and a WLAN control message transmitter 133b.
[43] The WLAN control message receiver 133a receives a WLAN control message from the sensor management server 200.
[44] The WLAN control message transmitter 133b transmits the WLAN control message received by the WLAN control message receiver 133a to the WLAN device 110.
[45] A sensor management server of a WLAN intrusion preventing system according to an exemplary embodiment of the present invention will now be described with reference to FIG. 3.
[46] FIG. 3 shows a schematic diagram of a sensor management server according to an exemplary embodiment of the present invention.
[47] As shown in FIG. 3, the sensor management server 200 includes a WLAN system monitor 210 and a sensor controller 230.
[48] The WLAN system monitor 210 monitors the WLAN system 100 through the plurality of sensors 130. WLAN system monitor 210 includes a WLAN monitoring information receiver 211, a malicious WLAN device detector 213, a position information generator 215, a WLAN intrusion information generator 217, and a WLAN intrusion
information transmitter 219.
[49] The WLAN monitoring information receiver 211 receives WLAN monitoring information from the sensors 130. Here, the WLAN monitoring information receiver 211 can receive WLAN monitoring information on a WLAN device 110 from the plurality of sensors 130. Also, the WLAN monitoring information receiver 211 can receive WLAN monitoring information corresponding to a plurality of WLAN devices 100 from one sensor 130.
[50] The malicious WLAN device detector 213 detects a WLAN device (hereinafter, a malicious WLAN device) violating a security level of the WLAN system 100 based on WLAN monitoring information received by the WLAN monitoring information receiver 211.
[51] The position information generator 215 generates position information of the malicious WLAN device detected by the malicious WLAN device detector 213 based on WLAN monitoring information.
[52] The WLAN intrusion information generator 217 generates WLAN intrusion information based on WLAN monitoring information and position information of the malicious WLAN device.
[53] The WLAN intrusion information transmitter 219 transmits WLAN intrusion information to the surveillance terminal 300.
[54] The sensor controller 230 controls the sensor 130 according to control by the surveillance terminal 300. The sensor controller 230 includes a WLAN control instruction receiver 231, a WLAN control message generator 233, and a WLAN control message transmitter 235.
[55] The WLAN control instruction receiver 231 receives a WLAN control instruction from the surveillance terminal 300.
[56] The WLAN control message generator 233 generates a WLAN control message corresponding to the WLAN control instruction received by the WLAN control instruction receiver 231.
[57] The WLAN control message transmitter 235 transmits the WLAN control message generated by the WLAN control message generator 233 to the sensor 130.
[58] A surveillance terminal of a WLAN intrusion preventing system according to an exemplary embodiment of the present invention will now be described with reference to FIG. 4.
[59] FIG. 4 shows a schematic diagram of a surveillance terminal according to an exemplary embodiment of the present invention.
[60] As shown in FIG. 4, the surveillance terminal 300 includes a WLAN intrusion information receiver 310, a WLAN intrusion information output unit 330, a WLAN control instruction input unit 350, and a WLAN control instruction transmitter 370.
[61] The WLAN intrusion information receiver 310 receives WLAN intrusion information from the sensor management server 200.
[62] The WLAN intrusion information output unit 330 outputs the WLAN intrusion information received by the WLAN intrusion information receiver 310.
[63] The WLAN control instruction input unit 350 receives a WLAN control instruction on WLAN intrusion information.
[64] The WLAN control instruction transmitter 370 transmits the WLAN control instruction to the sensor management server 200.
[65] A WLAN intrusion preventing method according to an exemplary embodiment of the present invention will now be described with reference to FIG. 5 and FIG. 6.
[66] FIG. 5 shows a flowchart of a WLAN intrusion preventing method according to an exemplary embodiment of the present invention.
[67] As shown in FIG. 5, when the WLAN device 110 of the WLAN system 100 transmits packets (SlOl), the WLAN device monitor 131 of the sensor 130 collects the packets (S 103). The packet collector 131a of the WLAN device monitor 131 collects the packets transmitted by the WLAN device 110. In this instance, a plurality of sensors 130 can collect the packets transmitted by the WLAN device 110.
[68] The WLAN device monitor 131 of the sensor 130 extracts WLAN monitoring information from the collected packets (S 105). The WLAN monitoring information extractor 131b of the WLAN device monitor 131 extracts WLAN monitoring information from the packets collected by the packet collector 131a. The WLAN monitoring information extracted by the WLAN monitoring information extractor 131b includes WLAN device information and WLAN danger detecting information.
[69] The WLAN device information includes a WLAN device type, a MAC address, an
IP address, a communication method, signal strength, an encryption method, channel information, and a found time.
[70] The WLAN device type indicates a type of the WLAN device 110 having transmitted the packets. The MAC address represents a physical address of the WLAN device 110 having transmitted the packets. The IP address shows a network address of the WLAN device 110 having transmitted the packets. The communication method represents a communication method which is used when the WLAN device 110 transmits packets, and includes IEEE 802.1 Ia, IEEE 802.1 Ib, and IEEE 802.1 Ig. The signal strength indicates signal strength of the packets collected by the sensor. The encryption method represents the method by which the packets are encrypted, and includes wired equivalent privacy (WEP), temporal key integrity protocol (TKIP), phase shift keying (PSK), advanced encryption standard (AES), transport layer security (TLS), tunneled TLS (TTLS), and protected extensible authentication protocol (PEAP). The channel information indicates information on the channel used for the WLAN device 100 to
transmit the packets. The found time is a time when the sensor 130 has found the WLAN device 110.
[71] The WLAN danger detecting information includes packet destination information, a hacking tool using state, authentication and encryption information, access point (AP) setting information, and a denial of service (DoS) attacking state.
[72] The packet destination information represents the final destination of the packet. The hacking tool using state indicates whether the WLAN device 110 having transmitted the packet hacks information of another WLAN device 110 or uses a hacking tool so as to intrude on the network. The authentication and encryption information represents whether the WLAN device 110 having transmitted the packet performs authentication or encryption. The AP predetermined information indicates setting information on the AP for communicating with the WLAN device 110 having transmitted the packet. The DoS attacking state represents whether the WLAN device 110 transmitting the packets is attacked by a denial of service or attempts to attack by a denial of service.
[73] When the WLAN device monitor 131 of the sensor 130 transmits WLAN monitoring information to the sensor management server 200, the WLAN system monitor 210 of the sensor management server 200 receives the WLAN monitoring information (S 107). The WLAN monitoring information transmitter 131c of the WLAN device monitor 131 transmits the WLAN monitoring information to the sensor management server 200, and the WLAN monitoring information receiver 211 of the WLAN system monitor 210 receives the WLAN monitoring information from the sensor 200. In this instance, the sensor management server 200 can receive WLAN monitoring information corresponding to a plurality of WLAN devices 110 from the sensor 130. Further, the sensor management server 200 can receive WLAN monitoring information for one WLAN device 110 from a plurality of sensors 130.
[74] The WLAN system monitor 210 of the sensor management server 200 detects a malicious WLAN device based on the WLAN monitoring information (S 109). The malicious WLAN device detector 213 of the WLAN system monitor 210 detects a malicious WLAN device based on the WLAN monitoring information. In this instance, the malicious WLAN device detector 213 detects a malicious WLAN device from among the plurality of WLAN devices 110 by searching for WLAN monitoring information. Here, the malicious WLAN device is predefined depending on the security level of the WLAN system 100.
[75] Cases corresponding to a malicious WLAN device and a method for a malicious
WLAN device detector to detect a malicious WLAN device will now be described.
[76] Cases corresponding to a malicious WLAN device includes a case in which the
WLAN device 110 communicates with a disallowed WLAN device, a case in which the WLAN device 110 follows a disallowed authentication method or a disallowed en-
cryption method, a case in which the WLAN device 110 uses a WLAN hacking tool, a case in which the WLAN device 110 uses a WLAN DoS attack, and a case in which the WLAN device 110 uses a disallowed communication protocol.
[77] First, in the case in which the WLAN device 110 communicates with a disallowed
WLAN device, the WLAN device 110 can communicate with a terminal or an AP outside the WLAN system 100, and the WLAN device 110 can communicate with an authenticated terminal or an AP inside the WLAN system 100. The malicious WLAN device detector 213 determines the WLAN device 110 communicating with a WLAN device not included in a communication allowable device list as a malicious illegal WLAN device based on WLAN monitoring information. In this instance, the communication allowable device list can be predefined. Also, the malicious WLAN device detector 213 can receive the communication allowable device list from the surveillance terminal 300. In addition, the surveillance terminal 300 can periodically update the communication allowable device list.
[78] Next, the case in which the WLAN device 110 follows a disallowed authentication method or a disallowed encryption method includes a case in which the WLAN device 110 does not follow a predefined authentication method and inner information of the WLAN device 110 is leaked, and a case in which the WLAN device 110 does not follow a predefined encryption method but transmits packets to leak packet information. The malicious WLAN device detector 213 determines a WLAN device 110 that does not use an authentication method or an encryption method included in the allowed authentication method list or the allowed encryption method list based on WLAN monitoring information to be a malicious WLAN device. In this instance, the allowed authentication method list or the allowed encryption method list can be predefined. Also, the malicious WLAN device detector 213 can receive the allowed authentication method list or the allowed encryption method list from the surveillance terminal 300. Further, the surveillance terminal 300 can periodically update the allowed authentication method list and the allowed encryption method list.
[79] A case in which the WLAN device 110 uses a WLAN hacking tool includes a case in which a WLAN hacking tool is installed in the WLAN device 110 to leak information on the WLAN device 110 to the outside of the WLAN system 100. The malicious WLAN device detector 213 determines the WLAN device 110 using a WLAN hacking tool as a malicious WLAN device based on WLAN monitoring information.
[80] The case in which the WLAN device 110 attacks the WLAN DoS includes a case in which the WLAN device 110 directly performs the WLAN DoS attack and a case in which the WLAN device outside the WLAN system 100 controls the WLAN device 110 to perform a DoS attack. The malicious WLAN device detector 213 determines the WLAN device 110 performing a DoS attack to be a malicious WLAN device based on
WLAN monitoring information.
[81] In the case in which the WLAN device 110 uses a disallowed communication protocol, the malicious WLAN device detector 213 determines the WLAN device 110 that does not use a communication protocol included in the allowed communication protocol list to be a malicious WLAN device based on WLAN monitoring information. In this instance, the allowed communication protocol list can be predefined. Also, the malicious WLAN device detector 213 can receive the allowed communication protocol list from the surveillance terminal 300. Further, the surveillance terminal 300 can periodically update the allowed communication protocol list.
[82] A WLAN intrusion preventing method according to an exemplary embodiment of the present invention will now be described with reference to FIG. 5.
[83] The WLAN system monitor 210 of the sensor management server 200 generates position information of the malicious WLAN device (Si l l). The position information generator 215 of the WLAN system monitor 210 generates position information on the malicious WLAN device detected by the malicious WLAN device detector 213 based on WLAN monitoring information.
[84] A method for a position information generator of a WLAN system monitor according to an exemplary embodiment of the present invention to generate position information of a malicious WLAN device will now be described with reference to FIG. 6.
[85] FIG. 6 shows a method for a position information generator according to an exemplary embodiment of the present invention to generate position information of a malicious WLAN device.
[86] The position information generator 215 generates position information of the malicious WLAN device through signal strength included in the WLAN monitoring information.
[87] As shown in FIG. 6, when the three sensors 130 extract three types of signal strength corresponding to the three sensors from the packet transmitted by the malicious WLAN device, the position information generator 215 converts the three types of signal strength into respective distances to generate distances du d2, and d3 from the three sensors to the device corresponding to the three sensors S1, S2, and S3.
[88] The position information generator 290 sets positions of the three sensors S1, S2, and
S3 respectively corresponding to the three sensors 130 as central points, and determines a cross point through which three circles with the three distances du d2, and d3 as their radii corresponding to the three sensors 130 pass to be the position of the WLAN device 110. In this instance, sensor positions corresponding to the respective sensors 130 are predefined. Further, the distances depending on the signal strength can be predefined.
[89] Referring to FIG. 5 again, a WLAN intrusion preventing method according to an
exemplary embodiment of the present invention will now be described.
[90] The WLAN system monitor 210 of the sensor management server 200 generates
WLAN intrusion information (Sl 13). The WLAN intrusion information generator 217 of the WLAN system monitor 210 generates WLAN intrusion information on the malicious WLAN device based on WLAN monitoring information and position information of the malicious WLAN device. The WLAN intrusion information includes WLAN monitoring information and position information of the malicious WLAN device.
[91] When the WLAN system monitor 210 of the sensor management server 200 transmits the WLAN intrusion information to the surveillance terminal 300, the surveillance terminal 300 receives the WLAN intrusion information (Sl 15). The WLAN intrusion information transmitter 219 of the WLAN system monitor 210 transmits WLAN intrusion information, and the WLAN intrusion information receiver 310 of the surveillance terminal 300 receives WLAN intrusion information.
[92] The WLAN intrusion information output unit 330 of the surveillance terminal 300 outputs the WLAN intrusion information received by the WLAN intrusion information receiver 310 (Sl 17). The WLAN intrusion information output unit 330 outputs the WLAN intrusion information so that the user may view it.
[93] The WLAN control instruction input unit 350 of the surveillance terminal 300 inputs a communication intercepting instruction (Sl 19). The WLAN control instruction input unit 350 interfaces with the user to input a communication intercepting instruction for the malicious WLAN device according to WLAN intrusion information. The WLAN control instruction input unit 350 inputs the communication intercepting instruction for preventing communication by the malicious WLAN device.
[94] When the WLAN control instruction transmitter 370 of the surveillance terminal 300 transmits the communication intercepting instruction to the sensor management server 200, the sensor controller 230 of the sensor management server 200 receives the communication intercepting instruction (S 121). The WLAN control instruction receiver 231 of the sensor controller 230 performs the communication intercepting instruction.
[95] The sensor controller 230 of the sensor management server 200 generates a communication intercepting message (S 123). The WLAN control message generator 233 of the sensor controller 230 generates a communication intercepting message according to the communication intercepting instruction. In this instance, the communication intercepting message can include a MAC address or IP address of the malicious WLAN device.
[96] When the sensor controller 230 of the sensor management server 200 transmits the communication intercepting message to the sensor 130, the WLAN device controller 133 of the sensor 130 receives the communication intercepting message (S 125). The
WLAN control message transmitter 235 of the sensor controller 230 transmits the communication intercepting message to the sensor 130, and the WLAN control message receiver 133a of the WLAN device controller 133 receives the communication intercepting message from the sensor management server 200. In this instance, the WLAN control message transmitter 235 can transmit the communication intercepting message to the sensor that is nearest the malicious WLAN device based on the position information of the malicious WLAN device.
[97] When the WLAN device controller 133 of the sensor 130 transmits the communication intercepting message to the WLAN device 110, the WLAN device 110 receives the communication intercepting message (S 127). In this instance, the WLAN control message transmitter 133b of the WLAN device controller 133 can transmit the communication intercepting message to the WLAN device 110 corresponding to the MAC address or IP address included in the communication intercepting message. Also, the sensor 130 can transmit the communication intercepting message to the WLAN device communicating with the malicious WLAN device. Also, the sensor 130 can transmit the communication intercepting message to the WLAN devices 110 in the WLAN system 100.
[98] The WLAN device 110 stops communication according to the communication intercepting message (S 129).
[99] The above-described embodiments can be realized through a program for realizing functions corresponding to the configuration of the embodiments or a recording medium for recording the program in addition to through the above-described device and/or method, which is easily realized by a person skilled in the art.
[100] While this invention has been described in connection with what is presently considered to be practical exemplary embodiments, it is to be understood that the invention is not limited to the disclosed embodiments, but, on the contrary, is intended to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims. Industrial Applicability
[101] The WLAN intrusion preventing system according to the embodiments of the present invention monitors the packets of the WLAN device through the sensor to intercept communication of the malicious WLAN device and prevent information from being leaked outside the WLAN system.
Claims
[1] A WLAN intrusion preventing method comprising: receiving a plurality of WLAN monitoring information on a WLAN device from a plurality of sensors; determining whether the WLAN device is a malicious WLAN device based on the plurality of WLAN monitoring information; generating position information of the malicious WLAN device based on the plurality of WLAN monitoring information when the WLAN device is a malicious WLAN device; generating a communication intercepting message on the malicious WLAN device; and transmitting the communication intercepting message to the plurality of sensors so that the malicious WLAN device may stop communication according to the communication intercepting message.
[2] The WLAN intrusion preventing method of claim 1, wherein the plurality of WLAN monitoring information respectively includes signal strength on the WLAN device, and the generating of position information comprises generating the position information based on a plurality of distances corresponding to a plurality of signal strengths included in the plurality of WLAN monitoring information.
[3] The WLAN intrusion preventing method of claim 2, wherein the transmitting of a communication intercepting message comprises transmitting the communication intercepting message to a sensor that is the nearest sensor from the malicious WLAN device from among the plurality of sensors based on the position information.
[4] A WLAN intrusion preventing method comprising: receiving a plurality of WLAN monitoring information respectively corresponding to a plurality of WLAN devices from a plurality of sensors; detecting a malicious WLAN device from among the plurality of WLAN devices based on the plurality of WLAN monitoring information; generating a communication intercepting message corresponding to the malicious WLAN device; and transmitting the communication intercepting message to some of sensors from among the plurality of sensors so that the some of sensors transmit the communication intercepting message to the plurality of WLAN devices.
[5] The WLAN intrusion preventing method of claim 4, wherein
the detecting comprises determining a WLAN device using a hacking tool to be the malicious WLAN device when the WLAN device using the hacking tool is found from among the plurality of WLAN devices.
[6] The WLAN intrusion preventing method of claim 4, wherein the detecting comprises determining a WLAN device performing a denial of service attack to be the malicious WLAN device when the WLAN device performing a denial of service attack is found from among the plurality of WLAN devices.
[7] The WLAN intrusion preventing method of claim 4, wherein the detecting comprises determining a WLAN device that does not use an authentication method or an encryption method included in an allowed authentication method list or an allowed encryption method list to be the malicious WLAN device from among the plurality of WLAN devices.
[8] The WLAN intrusion preventing method of claim 4, wherein the detecting comprises determining a WLAN device that does not use a communication protocol included in an allowed communication protocol list to be the malicious WLAN device from among the plurality of WLAN devices.
[9] The WLAN intrusion preventing method of claim 4, wherein the detecting includes determining a WLAN device communicating with another WLAN device that is not included in an allowed device list to be the malicious WLAN device from among the plurality of WLAN devices.
[10] A WLAN intrusion preventing system comprising: a WLAN device for transmitting a packet through a radio channel; a sensor for generating WLAN monitoring information based on the packet transmitted by the WLAN device, and controlling the WLAN device; and a sensor management server for generating WLAN intrusion information corresponding to the WLAN monitoring information and controlling the sensor.
[11] The WLAN intrusion preventing system of claim 10, further comprising a surveillance terminal for controlling the sensor management server according to a WLAN control instruction corresponding to the WLAN intrusion information.
[12] The WLAN intrusion preventing system of claim 11, wherein the sensor management server includes: a WLAN system monitor for receiving the WLAN monitoring information from
the sensor, generating the WLAN intrusion information corresponding to the WLAN monitoring information, and transmitting the WLAN intrusion information to the surveillance terminal; and a sensor controller for receiving the WLAN control instruction from the surveillance terminal, generating a WLAN control message corresponding to the WLAN control instruction, and transmitting the WLAN control message to the sensor.
[13] The WLAN intrusion preventing system of claim 12, wherein the sensor includes: a WLAN device monitor for collecting the packet transmitted by the WLAN device, extracting the WLAN monitoring information corresponding to the WLAN device from the collected packet, and transmitting the WLAN monitoring information to the sensor management server; and a WLAN device controller for receiving the WLAN control message from the sensor management server, and transmitting the WLAN control message to the WLAN device.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR1020080086473A KR20100027529A (en) | 2008-09-02 | 2008-09-02 | System and method for preventing wireless lan intrusion |
| KR10-2008-0086473 | 2008-09-02 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2010027121A1 true WO2010027121A1 (en) | 2010-03-11 |
Family
ID=41797278
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/KR2008/005765 Ceased WO2010027121A1 (en) | 2008-09-02 | 2008-10-01 | System and method for preventing wireless lan intrusion |
Country Status (2)
| Country | Link |
|---|---|
| KR (1) | KR20100027529A (en) |
| WO (1) | WO2010027121A1 (en) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103401691A (en) * | 2013-07-18 | 2013-11-20 | 山东省计算中心 | Portable WiFi equipment invasion precautionary method |
Families Citing this family (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR101279909B1 (en) * | 2011-12-16 | 2013-07-30 | (주)시큐리티존 | Intrusion protecting system manufactured as an integral package |
| KR101382526B1 (en) * | 2012-11-30 | 2014-04-07 | 유넷시스템주식회사 | Network security method and system for preventing mac spoofing |
| KR101382525B1 (en) * | 2012-11-30 | 2014-04-07 | 유넷시스템주식회사 | Wireless network security system |
| KR101429180B1 (en) * | 2012-11-30 | 2014-08-12 | 유넷시스템주식회사 | Control sensor of wireless network security system |
| KR101429178B1 (en) * | 2013-03-05 | 2014-08-12 | 유넷시스템주식회사 | System and method of wireless network security |
| KR102479425B1 (en) * | 2021-06-18 | 2022-12-20 | 주식회사 이너트론 | Method and apparatus for detecting and blocking illegal devices in wired and wireless networks |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20030200455A1 (en) * | 2002-04-18 | 2003-10-23 | Chi-Kai Wu | Method applicable to wireless lan for security control and attack detection |
| US20030202662A1 (en) * | 2002-04-25 | 2003-10-30 | International Business Machines Corporation | Protecting wireless local area networks from intrusion by eavesdropping on the eavesdroppers and dynamically reconfiguring encryption upon detection of intrusion |
| US20070090944A1 (en) * | 2005-10-25 | 2007-04-26 | Du Breuil Thomas L | Home-monitoring system |
-
2008
- 2008-09-02 KR KR1020080086473A patent/KR20100027529A/en not_active Withdrawn
- 2008-10-01 WO PCT/KR2008/005765 patent/WO2010027121A1/en not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20030200455A1 (en) * | 2002-04-18 | 2003-10-23 | Chi-Kai Wu | Method applicable to wireless lan for security control and attack detection |
| US20030202662A1 (en) * | 2002-04-25 | 2003-10-30 | International Business Machines Corporation | Protecting wireless local area networks from intrusion by eavesdropping on the eavesdroppers and dynamically reconfiguring encryption upon detection of intrusion |
| US20070090944A1 (en) * | 2005-10-25 | 2007-04-26 | Du Breuil Thomas L | Home-monitoring system |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103401691A (en) * | 2013-07-18 | 2013-11-20 | 山东省计算中心 | Portable WiFi equipment invasion precautionary method |
| CN103401691B (en) * | 2013-07-18 | 2016-06-08 | 山东省计算中心 | A kind of portable WiFi equipment intrusion defense method |
Also Published As
| Publication number | Publication date |
|---|---|
| KR20100027529A (en) | 2010-03-11 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US7970894B1 (en) | Method and system for monitoring of wireless devices in local area computer networks | |
| Lounis et al. | Attacks and defenses in short-range wireless technologies for IoT | |
| US7640585B2 (en) | Intrusion detection sensor detecting attacks against wireless network and system and method of detecting wireless network intrusion | |
| US8281392B2 (en) | Methods and systems for wired equivalent privacy and Wi-Fi protected access protection | |
| EP1834466B1 (en) | Method and system for detecting attacks in wireless data communication networks | |
| US9363675B2 (en) | Distributed wireless security system | |
| EP2023571A1 (en) | Method and system for wireless communications characterized by IEEE 802.11W and related protocols | |
| US20090016529A1 (en) | Method and system for prevention of unauthorized communication over 802.11w and related wireless protocols | |
| US20060002331A1 (en) | Automated sniffer apparatus and method for wireless local area network security | |
| US7710933B1 (en) | Method and system for classification of wireless devices in local area computer networks | |
| KR102323712B1 (en) | Wips sensor and method for preventing an intrusion of an illegal wireless terminal using wips sensor | |
| EP2923476B1 (en) | Intrusion prevention and detection in a wireless network | |
| KR20140035600A (en) | Dongle apparatus for preventing wireless intrusion | |
| Plósz et al. | Security vulnerabilities and risks in industrial usage of wireless communication | |
| US7333800B1 (en) | Method and system for scheduling of sensor functions for monitoring of wireless communication activity | |
| KR100874015B1 (en) | WLAN intrusion prevention system and method | |
| KR20070054067A (en) | Wireless access point device and network traffic intrusion detection and blocking method using same | |
| KR20100027529A (en) | System and method for preventing wireless lan intrusion | |
| KR101429179B1 (en) | Combination security system for wireless network | |
| KR101447469B1 (en) | System and method of wireless intrusion prevention and wireless service | |
| KR101725129B1 (en) | Apparatus for analyzing vulnerableness of wireless lan | |
| Letsoalo et al. | Survey of Media Access Control address spoofing attacks detection and prevention techniques in wireless networks | |
| KR101186876B1 (en) | Realtime intrusion protecting method for network system connected to wire and wireless integrated environment | |
| Shourbaji et al. | Wireless intrusion detection systems (WIDS) | |
| Skorpil et al. | Internet of things security overview and practical demonstration |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 08812257 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 15/06/2011) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 08812257 Country of ref document: EP Kind code of ref document: A1 |