Invention Grant
- Patent Title: Method and apparatus for detecting and handling evil twin access points
-
Application No.: US17861073Application Date: 2022-07-08
-
Publication No.: US11863984B2Publication Date: 2024-01-02
- Inventor: Scott Elliott , Jay Lindenauer
- Applicant: WatchGuard Technologies, Inc.
- Applicant Address: US WA Seattle
- Assignee: WatchGuard Technologies, Inc.
- Current Assignee: WatchGuard Technologies, Inc.
- Current Assignee Address: US WA Seattle
- Agency: Compass IP Law PC
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04W12/08 ; H04L9/06 ; H04W12/12

Abstract:
Methods and apparatus for detecting and handling evil twin access points (APs). The method and apparatus employ trusted beacons including security tokens that are broadcast by trusted APs. An Evil twin AP masquerades as a trusted AP by broadcasting beacons having the same SSID as the trusted AP, as well as other header field and information elements IE in the beacon frame body containing identical information. A sniffer on the trusted AP or in another AP that is part of a Trusted Wireless Environment (TWE) receives the beacons broadcasts by other APs in the TWE including potential evil twin APs. The content in the header and one or more IEs in received beacons are examined to determine whether a beacon is being broadcast by an evil twin. Detection of the evil twin are made by one of more of differences in MAC addresses of trusted and untrusted beacons, time jitter measurements and replay detection using timestamps in the beacons, detection of missing security tokens in untrusted beacons and detection that a security token that is mimicked by an evil twin is invalid. In one aspect, the security token is stored in a vendor-specific IE in trusted beacons that is generated by employing a secret key using a cryptographic operation operating on data in the beacon prior to the vendor-specific IE.
Public/Granted literature
- US20220353685A1 METHOD AND APPARATUS FOR DETECTING AND HANDLING EVIL TWIN ACCESS POINTS Public/Granted day:2022-11-03
Information query