KR101626567B1 - Wireless security apparatus and method - Google Patents
Wireless security apparatus and method Download PDFInfo
- Publication number
- KR101626567B1 KR101626567B1 KR1020140127624A KR20140127624A KR101626567B1 KR 101626567 B1 KR101626567 B1 KR 101626567B1 KR 1020140127624 A KR1020140127624 A KR 1020140127624A KR 20140127624 A KR20140127624 A KR 20140127624A KR 101626567 B1 KR101626567 B1 KR 101626567B1
- Authority
- KR
- South Korea
- Prior art keywords
- building
- access point
- outside
- frame
- access
- Prior art date
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W24/00—Supervisory, monitoring or testing arrangements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W48/00—Access restriction; Network selection; Access point selection
- H04W48/02—Access restriction performed under specific conditions
- H04W48/04—Access restriction performed under specific conditions based on user or terminal location or mobility data, e.g. moving direction, speed
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
The wireless security device according to an embodiment of the present invention collects traffic from a device in a building, an access point inside the building, and an access point outside the building, and generates an access list An AP access blocking device, and an AP position determining device for determining an access point outside the building based on a signal received from the first access point list and the access point inside the building, wherein the AP access blocking device is an access point And disconnects the device inside the building connected to the network.
Description
A wireless security device and method are provided.
The wireless device inside the building can access various APs (Access Point) inside or outside the building and transmit / receive various information. The wireless device inside the building may have information that should not be leaked to the outside. Information leakage may occur through communication between the wireless device inside the building and an external AP.
However, it is important to improve the security of the wireless device inside the building, since the communication between the wireless device inside the building and the AP outside the building can not be effectively blocked.
One embodiment of the present invention is to improve the security of a wireless device within a building.
Embodiments according to the present invention can be used to accomplish other tasks not specifically mentioned other than the above-described tasks.
The wireless security device according to an embodiment of the present invention collects traffic from a device in a building, an access point inside the building, and an access point outside the building, and generates an access list An AP access blocking device, and an AP position determining device for determining an access point outside the building based on a signal received from the first access point list and the access point inside the building, wherein the AP access blocking device is an access point And disconnects the device inside the building connected to the network.
The external AP access blocking device includes a traffic collecting unit for collecting traffic from a device in a building, an access point inside the building, and an access point outside the building, a traffic analyzing unit for analyzing the traffic and generating the first access point list, And an external AP access blocking unit for blocking access to an access point outside the building and a device inside the building.
A wireless security apparatus according to an embodiment of the present invention includes a traffic collecting unit for collecting traffic from a device in a building, an access point inside a building, and an access point outside the building, An external AP discrimination unit for discriminating an access point outside the building based on a signal received from a first access point list and an access point inside the building, And an external AP connection blocking unit for blocking connection of an internal device.
Here, a frame generation unit that generates a probe request frame based on the first access point list, a frame transmission unit that transmits a probe request frame to an access point in the building, and a frame collection unit that collects probe response frames from an access point in the building And the external AP discriminator may compare the first access point list with the probe response frame to determine an access point outside the building.
The traffic analyzer may analyze the traffic to determine a beacon frame, and generate a first access point list based on the beacon frame.
In addition, the external AP access blocking unit can block the connection with the access point outside the building by transmitting the authentication release frame to the device inside the building.
In addition, the external AP access blocking unit can block the connection with the access point outside the building by transmitting the authentication release frame to the device inside the building connected to the access point outside the building.
In addition, the wireless security device extracts an authorized device among the devices in the building, transmits an authentication release frame to an authorized device connected to an access point outside the building among the authorized devices, and blocks connection with an access point outside the building .
The AP position determination apparatus includes a frame generation unit that generates a probe request frame based on the first access point list, a frame transmission unit that transmits a probe request frame to an access point in the building, a probe response frame And an external AP discrimination unit for comparing the first access point list and the probe response frame to determine an access point outside the building.
In addition, the wireless security device can use the directional antenna to determine the access point outside the building.
A wireless security method according to an embodiment of the present invention includes a step of collecting traffic from a device inside a building, an access point inside a building and an access point outside the building, analyzing traffic, A step of discriminating an access point outside the building based on a signal received from a first access point list and a signal received from an access point inside the building, And disconnecting the connection of the device.
Here, the step of generating the first access point list may analyze the traffic to determine the beacon frame, and may generate the first access point list based on the beacon frame.
Also, the wireless security method can use the directional antenna to determine the access point outside the building.
In addition, in the step of blocking the connection, the authentication release frame is transmitted to the device inside the building, thereby blocking the connection with the access point outside the building.
In the step of blocking the connection, the authentication release frame is transmitted to the device inside the building connected to the access point outside the building, thereby blocking the connection with the access point outside the building.
In addition, the wireless security method extracts an authorized device among the devices in the building, transmits an authentication release frame to an authorized device connected to an access point outside the building among the authorized devices, and blocks access to an access point outside the building .
The step of determining an access point outside the building may further comprise the steps of generating a probe request frame based on the first access point list, transmitting a probe request frame to an access point in the building, Collecting a probe response frame, and comparing the first access point list and the probe response frame to determine an access point outside the building.
One embodiment of the present invention can improve the security of a wireless device within a building.
FIG. 1 is a conceptual diagram for blocking access to an access point outside a building and a device inside a building using a wireless security device according to an embodiment of the present invention.
2 is a block diagram of a wireless security device in accordance with one embodiment of the present invention.
3A is an illustration showing a detailed configuration of a frame transmitted from an access point according to an embodiment of the present invention.
3B is an illustration of a probe request frame generated by a wireless security device according to an embodiment of the present invention.
3C is an illustration of a probe response frame that a wireless security device according to one embodiment of the present invention collects from a wireless access point that received a probe request frame.
4 is an illustration of an authentication release frame transmitted by the wireless security device according to one embodiment of the present invention.
5 is a block diagram of a wireless security device in accordance with one embodiment of the present invention.
6 is a flowchart of a wireless security method according to one embodiment of the present invention.
7 is a flow diagram illustrating a wireless security method in accordance with one embodiment of the present invention.
BRIEF DESCRIPTION OF THE DRAWINGS The above and other features and advantages of the present invention will be more apparent from the following detailed description taken in conjunction with the accompanying drawings, in which: FIG. The present invention may be embodied in many different forms and is not limited to the embodiments described herein. In order to clearly illustrate the present invention, parts not related to the description are omitted, and the same reference numerals are used for the same or similar components throughout the specification. In the case of publicly known technologies, a detailed description thereof will be omitted.
Whenever a component is referred to as "including" an element throughout the specification, it is to be understood that the element may include other elements, not the exclusion of any other element, unless the context clearly dictates otherwise. Also, the term "part" in the description means a unit for processing at least one function or operation, which may be implemented by hardware, software, or a combination of hardware and software.
FIG. 1 is a conceptual diagram for blocking access to an access point outside a building and a device inside a building using a wireless security device according to an embodiment of the present invention.
Inside the
The connection between the
2 is a block diagram of a wireless security device in accordance with one embodiment of the present invention.
The
The external AP
The AP
The traffic collecting
The
The traffic analyzing
In this case, according to the embodiment of the present invention, it is not possible to determine whether the
A method of generating the access point list by the
3A is an illustration showing a detailed configuration of a frame transmitted from an access point according to an embodiment of the present invention.
The frame of FIG. 3A consists of a header, a body, and a frame check sequence (FCS). The frame of FIG. 3A includes a frame control (FC), a duration (Duration) D, a destination address (DA), a source address (SA) Basic Service Set ID (BSSID), and Sequence Control (SC) information. The
The frame body may include a time stamp, a beacon interval, capability information, an SSID (Service Set Identifier), and optional fields.
The
The
The
3B is an illustration of a probe request frame generated by a wireless security device according to an embodiment of the present invention.
The
The
Since the
The
The
3C is an illustration of a probe response frame that a wireless security device according to one embodiment of the present invention collects from a wireless access point that received a probe request frame.
The
The external
As shown in FIG. 3C, the external
The external AP
The external AP
4 is an illustration of an authentication release frame transmitted by the wireless security device according to one embodiment of the present invention.
4, the authentication release frame can be transmitted to the
The
The external AP
A method for determining a device inside a building connected to an access point (40) outside the building can be performed by the traffic analysis unit (120). The
Accordingly, the address of the
The external AP
In addition, the external AP
Although not shown in FIG. 2, the list of devices in the authorized building can be stored and managed in a separate database. When the external AP
The AP
Accordingly, the
5 is a block diagram of a wireless security device in accordance with one embodiment of the present invention.
The
5 includes a
6 is a flowchart of a wireless security method according to one embodiment of the present invention.
The contents overlapping with those described in the
First, the
The step of generating the access point list (S102) may analyze the traffic to determine a beacon frame, and generate a list of access points inside and outside the building based on the beacon frame.
The
The
Then, the
The
Then, the
In addition, the step of blocking the connection (S107) may block the connection with the
Then, an authorized device among the
7 is a flow diagram illustrating a wireless security method in accordance with one embodiment of the present invention.
The wireless security method of FIG. 7 is a wireless security method in a case where the
The external AP
The external AP
The AP
The AP
The AP
The AP
The external AP
While the present invention has been particularly shown and described with reference to exemplary embodiments thereof, it is to be understood that the invention is not limited to the disclosed exemplary embodiments, Of the right.
10: inside the building 20: device inside the building
30: Access point inside the building 40: Access point outside the building
100: wireless security device 110: traffic collecting unit
120: traffic analysis unit 130: frame generation unit
140: frame transmitting unit 150: frame receiving unit
160: external AP discrimination unit 170: external AP connection blocking unit
200: External AP access blocking device 300: AP position determination device
Claims (17)
And an AP position determination device for determining an access point outside the building based on a signal received from the first access point list and an access point inside the building,
The AP position determination apparatus transmits a probe request frame to an access point in the building using a directional antenna and receives a probe response frame transmitted from an access point in the building receiving the probe request frame, And compares the first access point list with the second access point list to determine an access point outside the building,
And the AP connection blocking device blocks connection between the access point outside the identified building and the device inside the building.
The external AP access blocking device,
A traffic collector for collecting the traffic from a device inside the building, an access point inside the building, and an access point outside the building,
A traffic analyzing unit for analyzing the traffic to generate the first access point list, and
And an external AP connection blocking unit for blocking connection between an access point outside the building and a device inside the building.
A traffic analyzer for analyzing the traffic to generate a first access point list having no distinction between inside and outside buildings,
A frame transmitter for transmitting a probe request frame to an access point inside the building using a directional antenna,
A frame collecting unit for collecting a probe response frame transmitted from an access point inside the building receiving the probe request frame and generating a second access point list,
An external AP discriminator for comparing the first access point list with the second access point list to determine an access point outside the building; and
And an external AP connection blocking unit for blocking connection between an access point outside the identified building and a device inside the building
Lt; / RTI >
And a frame generator for generating a probe request frame based on the first access point list.
Wherein the traffic analyzer analyzes the traffic to determine a beacon frame, and generates the first access point list based on the beacon frame.
Wherein the external AP access blocking unit transmits an authentication release frame to a device inside the building to block access to an access point outside the building.
Wherein the external AP access blocking unit transmits an authentication release frame to a device in which information required for security is stored among devices in a building connected to an access point outside the building to block access to an access point outside the building Device.
A wireless security device that extracts an authorized device among the devices in the building and transmits an authentication release frame to an authorized device connected to an access point outside the building to block access to an access point outside the building Device.
The AP position determination apparatus,
And a frame generator for generating a probe request frame based on the first access point list.
Collecting traffic from a device inside the building, an access point inside the building and an access point outside the building,
Analyzing the traffic to generate a first access point list without distinction between inside and outside buildings,
Determining an access point outside the building based on a signal received from the first access point list and an access point inside the building; and
And disconnecting the access point outside the identified building from the device inside the building,
The access point discrimination step outside the building comprises:
Transmitting a probe request frame to an access point in the building using a directional antenna;
Receiving a probe response frame transmitted from an access point in the building receiving the probe request frame to generate a second access point list, and
And comparing the first access point list with the second access point list to determine an access point outside the building.
Wherein the generating of the first access point list comprises analyzing the traffic to determine a beacon frame and generating the first access point list based on the beacon frame.
Wherein the step of intercepting the connection is to disconnect an access point outside the building by transmitting an authentication release frame to a device inside the building.
Wherein the step of intercepting the connection is to disconnect the access point from the access point outside the building by sending an authentication release frame to a device in the building connected to the access point outside the building, Wireless security method.
A wireless security device that extracts an authorized device among the devices in the building and transmits an authentication release frame to an authorized device connected to an access point outside the building to block access to an access point outside the building Way.
The access point discrimination step outside the building comprises:
And generating a probe request frame based on the first access point list.
Priority Applications (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
KR1020140127624A KR101626567B1 (en) | 2014-09-24 | 2014-09-24 | Wireless security apparatus and method |
PCT/KR2014/009843 WO2016047843A1 (en) | 2014-09-24 | 2014-10-20 | Wireless security apparatus and method |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
KR1020140127624A KR101626567B1 (en) | 2014-09-24 | 2014-09-24 | Wireless security apparatus and method |
Publications (2)
Publication Number | Publication Date |
---|---|
KR20160035823A KR20160035823A (en) | 2016-04-01 |
KR101626567B1 true KR101626567B1 (en) | 2016-06-01 |
Family
ID=55581352
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
KR1020140127624A KR101626567B1 (en) | 2014-09-24 | 2014-09-24 | Wireless security apparatus and method |
Country Status (2)
Country | Link |
---|---|
KR (1) | KR101626567B1 (en) |
WO (1) | WO2016047843A1 (en) |
Families Citing this family (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR101879345B1 (en) * | 2017-03-29 | 2018-07-17 | 김동석 | Method for sharing wireless data according to usage amount of wireless data |
Citations (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR101360348B1 (en) * | 2013-09-13 | 2014-02-10 | 지니네트웍스(주) | Method for detecting wireless access point |
Family Cites Families (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR101198329B1 (en) * | 2011-07-29 | 2012-11-08 | 킹스정보통신(주) | Wireless network security system of client foundation and method thereof |
KR20130019892A (en) * | 2011-08-18 | 2013-02-27 | 주식회사 퓨쳐시스템 | Method and wips for security of wireless network |
KR101429177B1 (en) * | 2012-11-23 | 2014-08-12 | 유넷시스템주식회사 | System for detecting unauthorized AP and method for detecting thereof |
-
2014
- 2014-09-24 KR KR1020140127624A patent/KR101626567B1/en active IP Right Grant
- 2014-10-20 WO PCT/KR2014/009843 patent/WO2016047843A1/en active Application Filing
Patent Citations (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR101360348B1 (en) * | 2013-09-13 | 2014-02-10 | 지니네트웍스(주) | Method for detecting wireless access point |
Also Published As
Publication number | Publication date |
---|---|
KR20160035823A (en) | 2016-04-01 |
WO2016047843A1 (en) | 2016-03-31 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US10257832B2 (en) | Method and apparatus for directed adaptive control of dynamic channel selection in wireless networks | |
CN107683617B (en) | System and method for pseudo base station detection | |
ES2877176T3 (en) | Notification of WiFi channel measurements to a cellular radiocommunication network | |
US10104665B2 (en) | Method and apparatus for providing dynamic frequency selection spectrum access in peer-to-peer wireless networks | |
US20180035457A1 (en) | Method and apparatus for use of simultaneous multiple channels in the dynamic frequency selection band in wireless networks | |
US20130225165A1 (en) | Out-of-band scanning for femto access point detection | |
CN109068330A (en) | Pseudo-base station identifying processing method, equipment and storage medium | |
KR101626567B1 (en) | Wireless security apparatus and method | |
CN105992208A (en) | Wireless connection authentication method and wireless connection authentication device | |
US20060058053A1 (en) | Method for logging in a mobile terminal at an access point of a local communication network, and access point and terminal for carrying out the method | |
KR20150041407A (en) | Trust Access Point connection Apparatus and Method | |
EP2499854A1 (en) | Identity acquisition of mobile stations in a mobile telecommunications network | |
US10382967B2 (en) | Location information protection | |
KR101737893B1 (en) | WIPS Sensor and Terminal block Method Using The Same | |
US10638412B2 (en) | Implicit spatial replay protection | |
KR101557857B1 (en) | Detection apparatus for wireless intrusion prevention system | |
Sørseth | Location disclosure in lte networks by using imsi catcher | |
KR20150022743A (en) | Out-of-band scanning for femto access point detection | |
KR101477760B1 (en) | Detection Method for Infringement of Illegal Mobile device using wire and wireless scanning | |
US11665621B2 (en) | Restricting access to a mobile communications network | |
US20190028553A1 (en) | Explicit Spatial Replay Protection | |
KR101564001B1 (en) | Device for securely managemnet of wired and wireless communications | |
KR101564002B1 (en) | Detection Apparatus for Infringement of Illegal Mobile device |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
A201 | Request for examination | ||
E902 | Notification of reason for refusal | ||
E701 | Decision to grant or registration of patent right | ||
GRNT | Written decision to grant | ||
FPAY | Annual fee payment |
Payment date: 20190403 Year of fee payment: 4 |