A kind of method that prevents that wireless network is detectedTechnical field
The present invention relates to the wireless network secure field, particularly a kind ofly strengthen the method that wireless network secure prevents that wireless network is detected.
Background technology
Along with the development that continues burning hot and technology of wireless network, the coverage of wireless network is more and more wider, and the hidden danger of the wireless network secure that thereupon brings is also increasing.At present, wireless network is in certain scope, use a wireless aps (Access point WAP (wireless access point), it mainly provides wireless stations to cable LAN with from the access of cable LAN to wireless stations) realize communicating by letter between terminal and the cable LAN, in the scope that wireless aps covers, terminal (comprising portable terminal and fixed terminal) is by detecting the wireless signal of reception, and obtain SSID (the Service Set Identifier of wireless aps, user ID wireless network identification code), just can be linked in the network by wireless aps.
At present, have a variety of for the strick precaution of wireless network secure or the method for assurance, mainly be some wireless encryption methods, such as WPA/WPA2, WAPI (WAPI (WLAN Authentication and Privacy Infrastructure), it is WAPI, it is for WEP protocol security problem among the IEEE802.11, through in many ways participating in, repeatedly prove, take into full account various application models, the wlan security solution that in Chinese WLAN (wireless local area network) standard GB/T 15629.11, proposes.Simultaneously, the IEEE Registration Authority(IEEE of the mechanism enrolment authority that this programme has been authorized by ISO/IEC) examination and acquisition approval, distributed the EtherType field that is used for the WAPI agreement, this also is the at present only agreement that gets the Green Light in this field of China.) etc.These methods all are encrypted for wireless data and realize by Password Management, but terminal all still can scan wireless network.May cause like this having unsafe factor.
Summary of the invention
For solving in the present network security method, mechanism manages by accessing to your password etc., and in use terminal still can scan the deficiency of the unsafe factor that wireless network brings, the invention provides a kind of method that prevents that wireless network is detected, further improve the security performance of wireless network.
The present invention for the technical scheme of finishing its technical purpose and adopting is: a kind of method that prevents that wireless network is detected, in the method, in the wireless communication process, WAP (wireless access point) is by hiding user ID wireless network identification code, so that the scanning software of the terminal in this coverage range of wireless access point can't scan this user ID wireless network identification code, so can't detect this wireless network by user ID wireless network identification code.
Further, above-mentioned preventing in the method that wireless network is detected: comprise the steps:
Steps A, need to send the place of beacon frame in the wireless driving of WAP (wireless access point), hide virtual radio access point corresponding to user ID wireless network identification code for needs, just withdraw from not beacon on frame;
If step B WAP (wireless access point) is received the request message of detecting of terminal transmission, when request message is detected in wireless driving answer, for virtual radio access point corresponding to user ID wireless network identification code that will hide, if when finding not carry the information of this user ID wireless network identification code in the probe requests thereby message, do not send out with regard to withdrawing from and to detect the answer message.
Further, above-mentioned preventing in the method that wireless network is detected: in described wireless contact coverage, terminal is by after the user ID wireless network identification code of having filled in this access point, WAP (wireless access point) receives that terminal sends when detecting request message, when request message is detected in wireless driving answer, will reply normally probe messages, could pass through like this this WAP (wireless access point) and connect.
The method of the reinforcement wireless network secure that proposes among the present invention is exactly to hide wireless network, and the people who only is apprised of just knows to have which wireless network, connects by the wireless network that manually arranges hiding again; Other people greatly reduces the hidden danger of wireless network secure because scanning less than the existence of wireless network, just can't be carried out any operation to these wireless networks.On the basis of this method, add these wireless encryption methods above-mentioned, will further strengthen wireless network secure.
Below by with specific embodiments and the drawings the present invention is further detailed.
Description of drawings
Accompanying drawing 1 is the embodiment of the invention 1 flow chart.
Embodiment
As shown in Figure 1, in strengthening the method that wireless network secure prevents that wireless network is detected, by hiding SSID, so that scanning software can't scan this SSID, reach and strengthen wireless network secure and prevent the purpose that wireless network is detected.Its key is how to realize hiding SSID, is mainly reflected in the following aspects:
A, beacon on frame (beacon frame) not, namely, send the place of beacon frame (beacon frame) in the wireless driving of wireless aps, the SSID that will hide for the current VAP (virtual radio access point) that will send out beacon, just withdraw from and do not send out the beacon frame, the existence that terminal just can't Cognitive radio networks like this.
Here, do not send out the beacon frame, except the existence of terminal perception less than wireless network, do not have other consequences; The beacon frame namely is beacon frame, and the transmission beacon frame that each VAP of wireless router can be regularly is with existing of the terminal wireless network around telling; Wireless driving refers to the wireless driving in the wireless router software, is similar to wired driving of wired network adapter; The place that sends the beacon frame refers to the place of sending out the beacon frame in the software; Hide the ssid of which wireless VAP, sheerly personal inclination or artificial appointment, each VAP is the same, which wants to specify just need to hide in wireless driving those VAP are not sent the beacon frame; Here terminal refers to any one wireless terminal, and the Wi-Fi terminal refers to certainly within the wireless network coverage, and outside scope, even send the beacon frame, terminal does not receive yet.
B, do not respond probe response frame (probe response frame), namely, be directed to the probe response frame (probe request message) of the Wi-Fi terminal that receives, when probe response is replied in wireless driving, for VAP corresponding to the ssid that will hide, if when not carrying the information of SSID of this AP in the probe request message of finding, do not send out probe response frame with regard to withdrawing from, namely do not return the probe request of terminal, terminal just can't be by seeking the information of obtaining wireless network like this.
Terminal can termly in the channel list of its support, send and detect claim frame (Probe Request) scanning wireless network.When AP receive detect claim frame after, can respond the radio network information that probe response frame (Probe Response) announcement can provide, originally be that all VAP on the wireless router can reply Probe Response, but, here for VAP corresponding to the ssid that will hide, if when finding not carry the information of this SSID in the probe requests thereby message, just do not reply, not replying does not have any other consequence.In wireless contact coverage, particular terminal is by after the user ID wireless network identification code of having filled in this access point, WAP (wireless access point) receives that terminal sends when detecting request message, when request message is detected in wireless driving answer, will reply normally probe messages, could pass through like this this WAP (wireless access point) and connect.
Do not send the beacon frame and do not return probe response frame by top, will hide well the title (SSID) of user ID wireless network, other terminal can't obtain SSID, therefore also survey less than the wireless network of having hidden SSID.But, know the terminal of SSID, under the terminal active scan mode such as this wireless network of granted access, work station (terminal) send include that this station wishes the SSID information that adds inquire after (Probe) frame, in this case, the driving of AP is just replied and is inquired after response frame (Probe Response Frame), like this, terminal will get access to the information of required network, carries out association and online.