top of page

[Tech Guide] WithNetworks’ ‘HawkAI’ Turns Wi-Fi APs into AI Security Sensors, Enabling Real-Time Response to Wireless Threats

11 hours ago
3 min read

Detects 36 types of wireless and network-layer threats on Wi-Fi 7 APs, with AI determining whether an attack is actually taking place From detection and analysis to reporting and device blocking, all handled on-premises without relying on external cloud services

 

As corporate work environments rapidly shift toward wireless connectivity, Wi-Fi access points (APs) are evolving beyond simple internet connectivity devices to serve as security sensors as well.


Withnetworks (CEO Ahn Jong-up) announced on the 13th that it is targeting the post-access security market for enterprise wireless networks with HawkAI, the AI-powered security feature of its integrated wireless management and security solution, AiriX.


HawkAI uses Wi-Fi 7 APs themselves as intrusion detection system (IDS) sensors to detect threats occurring on wireless networks in real time, while AI determines whether an actual attack is taking place. When a threat is identified, the system can also block or isolate the device according to predefined security policies.


Enterprise security has traditionally been built around wired networks, focusing on gateways where the internet connects to internal networks and critical servers. In contrast, wireless networks, where large numbers of laptops, smartphones, tablets, IP cameras, and IoT devices connect, have relied relatively heavily on access authentication such as IDs and passwords.


According to Withnetworks, if an attacker obtains legitimate authentication credentials and gains access to an enterprise Wi-Fi network, the connection itself may appear normal. This makes it necessary to continuously monitor abnormal activity occurring after the initial connection.


HawkAI focuses on addressing this gap in wireless security directly at the AP level. APs receive wireless signals over the air while also serving as gateways through which device traffic passes before entering the company’s wired internal network. Rather than adding separate security sensors, the solution uses already-installed APs as security monitoring points.


HawkAI detects 36 types of threats across the wireless and network layers in real time on Wi-Fi 7 APs. Rather than simply issuing alerts about suspicious activity, its AI analyzes the context surrounding individual events and correlations between activities to determine whether they represent an actual attack.


To reduce the burden on security administrators who would otherwise have to manually analyze numerous alerts, HawkAI also automatically generates reports containing the rationale behind the AI’s security decisions. Devices identified as threats and subject to security policies can then be blocked or isolated. This creates an integrated wireless management and security framework covering detection, analysis, determination, reporting, and response.


In particular, the entire process, including AI analysis, is performed on-premises without relying on external cloud services. This enables deployment in segmented or closed networks used by public-sector, defense, and financial institutions, where transmitting internal data outside the organization may not be permitted.


As cyberattacks that exploit wireless networks as alternative access routes have emerged in practice, the need to monitor device activity after network access has also grown. In the so-called “Neighbor Attack” reported in 2024, a Russian hacking group reportedly avoided directly attacking the internet gateway of a target organization protected by multi-factor authentication (MFA). Instead, the group first compromised a nearby organization and then used the wireless capabilities of a PC at that organization to gain access to the target’s internal Wi-Fi network.


Sung Young-sam, Executive Director at Withnetworks, said, “Going forward, network competitiveness will depend not only on how fast a network is, but also on whether it can monitor devices after they connect and determine which threats are genuine among the numerous alerts. In particular, in environments such as the public sector, defense, and finance, where data cannot be sent outside the organization, it is equally important for this analysis and decision-making to be completed internally. As business operations increasingly move onto wireless networks, security will become a key factor in how networks are selected.”



전자신문


 
 
 

Comments


bottom of page