IP Library Granted Patent US 8,756,690
Granted Patent B2
US 8,756,690 · App. 12/570,671 · Granted Jun 17, 2014

Extensible authentication protocol attack detection systems and methods

Inventor: Jason Orgill (Boston, MA)
Assignee: Symbol Technologies, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,756,690
App. No.
12/570,671
Granted
Jun 17, 2014
Kind
B2
Abstract

The present disclosure provides systems and methods for detecting attacks against authentication mechanisms that generate Transport Layer Security (TLS) tunnels using a server public key. Such attacks can include misconfigured wireless local area network (WLAN) clients that fail to authenticate the server public key prior to creating the TLS tunnels and exchanging credentials. In an exemplary embodiment, an intrusion detection system (IDS) or intrusion prevention system (IPS) is aware of the server public key and monitors for authentication handshakes to detect invalid keys.

Claims (44)

1. A protocol attack detection system, comprising:

a monitoring device configured to monitor frames transmitted on a network between a client device and an access device;

a data store loaded with a server public key;

wherein the access device is configured to create a Transport Layer Security (TLS) tunnel with the client device through the exchange of a public key associated with the authentication, and

wherein the client cannot authenticate the public key prior to the creation of the TLS tunnel and exchanging credentials with the access device; and

a detection module, at a server, configured to receive said monitored frames from the monitoring device and to detect authentication based on the monitored frames and to determine whether a public key associated with the authentication is valid by checking the public key associated with the authentication against the server public key.

2. The detection system of claim 1 , wherein the detection module is further configured to provide one of an alarm and an alert responsive to detecting an invalid authentication thereby allowing reconfiguring of the client device such that the client device can perform authentication.

3. The detection system of claim 1 , wherein the detection module is configured to detect an attack whereby the access device comprises a spoofed access device of a legitimate access device.

4. The detection system of claim 1 , wherein the credentials are exchanged based upon one of Password Authentication Protocol, Challenge Handshake Authentication Protocol, Microsoft Challenge Handshake Authentication Protocol version 1, and Microsoft Challenge Handshake Authentication Protocol version 2.

5. The detection system of claim 1 , wherein the authentication is based on Extensible Authentication Protocol, and wherein the public key comprises an Access Point/Authenticator public key.

6. The detection system of claim 1 , wherein the detection module is configured to detect the attack based on monitoring a single frame of the frames; and

wherein the single frame comprises a Server Hello message with the public key.

7. The detection system of claim 1 , wherein the network comprises a wireless network utilizing IEEE 802.11 protocols;

wherein the client comprises a wireless device;

wherein the access device comprises a wireless access point with a Remote Authentication Dial In User Service server; and

wherein the authentication is complaint to IEEE 802.1X.

8. The detection system of claim 7 , wherein the authentication is compliant to any of Extensible Authentication Protocol—Transport Layer Security, Extensible Authentication Protocol—Tunneled Transport Layer Security, Extensible Authentication Protocol—Protected Extensible Authentication Protocol, and Lightweight Extensible Authentication Protocol.

9. The detection system of claim 1 , wherein the server public key is one of preloaded and learned.

10. A method for detecting extensible authentication protocol attacks, comprising:

at a detection system, accessing an authentication server public key, wherein the detection system is configured to receive monitored frames from a monitoring device;

monitoring frames, by the monitored device, transmitted on a network between a client device and an access device;

detecting an extensible authentication protocol authentication in the frames;

creating a Transport layer Security (TLS) tunnel by the access device with the client device through the exchange of the public key in the extensible authentication protocol authentication, wherein the client cannot authenticate the public key prior to creating the TLS tunnel and exchanging credentials with the access device; and

determining, by the detection system, if the extensible authentication protocol authentication is valid by checking the public key associated with the extensible authentication protocol authentication against the authentication server public key.

11. The method of claim 10 , further comprising:

validating a public key in the extensible authentication protocol authentication in response to the authentication server public key.

12. The method of claim 10 , further comprising:

providing an alert responsive to an invalid extensible authentication protocol authentication; and

performing reconfiguring of the client device responsive to the alert such that the client device can perform authentication.

13. The method of claim 10 , wherein the determining step is configured to detect validity of the extensible authentication protocol authentication based on monitoring a single frame of the frames; and

wherein the single frame comprises a Server Hello message with the public key.

14. The method of claim 10 , wherein the network comprises a wireless network utilizing IEEE 802.11 protocols;

wherein the client device comprises a wireless device;

wherein the access device comprises a wireless access point with a Remote Authentication Dial In User Service server;

wherein the authentication is complaint to IEEE 802.1X; and

wherein the extensible authentication protocol authentication is compliant to any of Extensible Authentication Protocol—Transport Layer Security, Extensible Authentication Protocol—Tunneled Transport Layer Security, Extensible Authentication Protocol—Protected Extensible Authentication Protocol, and Lightweight Extensible Authentication Protocol.

15. A wireless intrusion detection system, comprising:

a wireless monitoring device configured to monitor data transmitted on a wireless network between a client device and an access device;

wherein the access device is configured to create a Transport layer Security (TLS) tunnel with the client device through the exchange of a public key associated with the authentication, and

wherein the client cannot authenticate the public key prior to the creation of the TLS tunnel and exchanging credentials with the access device; and

a detection module, at a server, configured to receive the monitored data from the monitoring device and to detect valid and invalid extensible authentication protocol requests between a client and an access point responsive to monitored data on the network, wherein the detection module is able to detect valid and invalid extensible authentication protocol requests by checking the public key associated with the extensible authentication protocol authentication against an authentication server public key;

wherein the detection module is further configured to provide one of an alarm and an alert responsive to detecting an invalid request thereby allowing one of a password reset, active termination, and reconfiguring of the client.

16. The wireless intrusion detection system of claim 15 , wherein the detection module is configured to detect spoofed access points whereby the access point utilizes an extended service set identifier of a legitimate access point to exchange credentials with the client device;

wherein the public key comprises an Access Point/Authenticator public key.

Assignments (14)
RELEASE OF PATENT AND TRADEMARK SECURITY INTEREST AT REEL/FRAME NO. 46050/0546 Recorded Jul 30, 2026
From: BANK OF MONTREAL, AS AGENT
To: EXTREME NETWORKS, INC.
Reel/Frame 076081/0088 →
SECURITY INTEREST Recorded Jul 29, 2026
From: EXTREME NETWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 076078/0590 →
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2016
From: SYMBOL TECHNOLOGIES, LLC
To: EXTREME NETWORKS, INC.
Reel/Frame 040579/0410 →
AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2016
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 040521/0762 →
RELEASE OF SECURITY INTEREST Recorded Aug 17, 2015
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 036371/0738 →
CHANGE OF NAME Recorded Jul 8, 2015
From: SYMBOL TECHNOLOGIES, INC.
To: SYMBOL TECHNOLOGIES, LLC
Reel/Frame 036083/0640 →
SECURITY AGREEMENT Recorded Oct 31, 2014
From: ZIH CORP.; LASER BAND, LLC; ZEBRA ENTERPRISE SOLUTIONS CORP.; SYMBOL TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC. AS THE COLLATERAL AGENT
Reel/Frame 034114/0270 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE ADDRESS PREVIOUSLY RECORDED ON REEL 023347 FRAME 0681. ASSIGNOR(S) HEREBY CONFIRMS THE CORRECT ASSIGNEE ADDRESS IS: ONE SYMBOL PLAZA, HOLTSVILLE, NY 11742. Recorded Jul 14, 2014
From: ORGILL, JASON
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 033318/0778 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2009
From: ORGILL, JASON
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 023347/0681 →
Continuity (1)
Related Publication 20110078793A1 · Mar 31, 2011