A Rogue AP Detection Method Based on DHCP Snooping

DHCP 스누핑 기반의 비인가 AP 탐지 기법

  • Park, Seungchul (School of Computer Science and Engineering, Korea University of Technology and Education)
  • Received : 2016.01.12
  • Accepted : 2016.03.25
  • Published : 2016.06.30


Accessing unauthorized rogue APs in WiFi environments is a very dangerous behavior which may lead WiFi users to be exposed to the various cyber attacks such as sniffing, phishing, and pharming attacks. Therefore, prompt and precise detection of rogue APs and properly alarming to the corresponding users has become one of most essential requirements for the WiFi security. This paper proposes a new rogue AP detection method which is mainly using the installation information of authorized APs and the DHCP snooping information of the corresponding switches. The proposed method detects rogue APs promptly and precisely, and notify in realtime to the corresponding users. Since the proposed method is simple and does not require any special devices, it is very cost-effective comparing to the wireless intrusion prevention systems which are normally based on a number of detection sensors and servers. And it is highly precise and prompt in rogue AP detection and flexible in deployment comparing to the existing rogue AP detection methods based on the timing information, location information, and white list information.

와이파이 환경에서 비인가 AP(rogue AP)의 접속은 스니핑(sniffing), 피싱(phishing), 파밍(pharming) 공격 등 다양한 사이버 공격에 노출될 수 있는 매우 위험한 행위이다. 따라서 비인가 AP를 신속하고 정확하게 탐지하여 와이파이 사용자가 해당 AP에 대한 접속을 회피할 수 있도록 적절하게 경고하는 것은 와이파이 보안의 핵심 요구사항이 되고 있다. 본 논문은 인가된 AP에 대한 설치 정보와 스위치의 DHCP 스누핑 정보를 활용하여 비인가 AP를 정확하고 신속하게 탐지하여, 무선 단말에 실시간으로 통보하는 새로운 비인가 AP 탐지 기법을 제시한다. 제안된 비인가 AP 탐지 기법은 별도의 장비가 불필요하고 간단하여 많은 수의 탐지 센서와 탐지 서버로 구성되는 무선 침입 방지 시스템(wireless intrusion prevention system)에 비해 저가격에 구현가능하다. 그리고 타이밍 정보, 위치 정보, 화이트 리스트 기반 등의 기존 비인가 AP 탐지 기법에 비해 탐지의 정확성이 높고, 신속하며, 개방 환경을 포함하여 다양한 환경에 유연하게 적용가능한 장점이 있다.



  1. R. Beyah and A. Venkataraman, "Rogue-Access-Point Detection Challenges, Solutions, and Future Directions," IEEE Security and Privacy, Sept./Oct 2011, pp. 56-61.
  2. Motorola, "Solutions for Detecting and Eliminating Rogue Wireless Networks," White Paper, Oct. 2011.
  3. M. Kim, J. Mun, S. Jung, and Y. Kim, "A Mobile Device-based Mobile AP Detection Scheme using NAT Behavior," Proceedings of 2013 International Conference on IT Convergence and Security, 16-18 Dec. 2013, pp. 1-4.
  4. L. Watkins, R. Beyah, and C. Corbett, "A Passive Approach to Rogue Access point Detection," Proceedings of IEEE Globecom 2007, 26-30 Nov. 2007, pp. 355-360.
  7. H. Han, B. Sheng, C. C. Tan, Q. Li, and S. Lu, "A Timing-based Scheme for Rogue AP Detection," IEEE Transactions on Parallel and Distributed Systems, Vol. 22, No. 11, Nov. 2011, pp. 1012-1925
  8. J. Lee, S. Lee, and J. Moon, "Detecting Rogue AP using k-SVM method," Journal of The Korea Institue of Information Security and Cryptology, Vol. 24, No. 1, Feb 2014, pp. 87-95
  9. K. Kao, T. Yeo, W. Yong, and H. Chen, "A Location-aware Rogue Ap Detection System Based on Wireless Packet Sniffing of Sensor APs," Proceedings of The 2011 ACM Symposium on Applied Computing, Mar. 2011, pp. 32-36
  10. J. Park, M. Park, and S. Jung, "A Whitelist-based Scheme for Detecting and Preventing Unauthorized AP Access Using Mobile Device," Journal of KICS, Vol. 38B, No.8, Aug. 2013, pp. 632-640