-
公开(公告)号:US07558960B2
公开(公告)日:2009-07-07
申请号:US11029987
申请日:2005-01-05
申请人: Nancy Cam Winget , Mark Krishcer , Timothy Olson , Pauline Shuen , Ajit Sanzgiri , Sheausong Yang
发明人: Nancy Cam Winget , Mark Krishcer , Timothy Olson , Pauline Shuen , Ajit Sanzgiri , Sheausong Yang
IPC分类号: H04L9/00
CPC分类号: H04W12/04 , H04L41/00 , H04L63/062 , H04L63/08 , H04L63/083 , H04L63/123 , H04L63/126 , H04L63/1408 , H04W12/10 , H04W12/12 , H04W84/12 , H04W88/08
摘要: A detection-based defense to a wireless network. Elements of the infrastructure, e.g., access points or scanning-only access points, detect intruders by detecting spoofed frames, such as from rogue access points. Access points include a signature, such as a message integrity check, with their management frames in a manner that enables neighboring access points to be able to validate the management frames, and to detect spoofed frames. When a neighboring access point receives a management frame, obtains a key for the access point sending the frame, and validates the management frame using the key.
摘要翻译: 基于检测的无线网络防御。 基础设施的元件,例如接入点或仅扫描接入点,通过检测欺骗性帧(例如从流氓接入点)来检测入侵者。 接入点包括诸如消息完整性检查之类的签名,以及其管理帧的方式使得相邻接入点能够验证管理帧,并且检测被欺骗的帧。 当相邻接入点接收到管理帧时,获取发送帧的接入点的密钥,并使用密钥验证管理帧。
-
公开(公告)号:US08191144B2
公开(公告)日:2012-05-29
申请号:US12430375
申请日:2009-04-27
申请人: Nancy Cam Winget , Mark Krishcer , Sheausong Yang , Ajit Sanzgiri , Timothy Olson , Pauline Shuen
发明人: Nancy Cam Winget , Mark Krishcer , Sheausong Yang , Ajit Sanzgiri , Timothy Olson , Pauline Shuen
IPC分类号: H04L29/06
CPC分类号: H04W12/04 , H04L41/00 , H04L63/062 , H04L63/08 , H04L63/083 , H04L63/123 , H04L63/126 , H04L63/1408 , H04W12/10 , H04W12/12 , H04W84/12 , H04W88/08
摘要: A detection-based defense to a wireless network. Elements of the infrastructure, e.g., access points or scanning-only access points, detect intruders by detecting spoofed frames, such as from rogue access points. Access points include a signature, such as a message integrity check, with their management frames in a manner that enables neighboring access points to be able to validate the management frames, and to detect spoofed frames. When a neighboring access point receives a management frame, obtains a key for the access point sending the frame, and validates the management frame using the key.
摘要翻译: 基于检测的无线网络防御。 基础设施的元件,例如接入点或仅扫描接入点,通过检测欺骗性帧(例如从流氓接入点)来检测入侵者。 接入点包括诸如消息完整性检查之类的签名,以及其管理帧的方式使得相邻接入点能够验证管理帧,并且检测被欺骗的帧。 当相邻接入点接收到管理帧时,获取发送帧的接入点的密钥,并使用密钥验证管理帧。
-