Wireless network de-authentication method & apparatus

The directional network communications device addresses the challenge of managing rogue devices by using a directional antenna and processor to disconnect specific devices from the network, ensuring only authorized devices remain connected, with a user-friendly interface for operation.

GB2643042APending Publication Date: 2026-02-04LUPERCAL SYST LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
GB2024011160
Authority / Receiving Office
GB · GB
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-30
Publication Date
2026-02-04

AI Technical Summary

Technical Problem

Existing network management tools lack a straightforward and integrated solution to identify, distinguish, and manage rogue or unwanted devices connected to a wireless data network, particularly those that mimic approved devices, and often require highly trained administrators for effective operation.

Method used

A directional network communications device equipped with a directional antenna and processor that can extract metadata to generate de-authentication requests, optionally with a user interface, to target and disconnect specific devices from the network, using a whitelist to ensure only authorized devices remain connected.

Benefits of technology

Enables effective management of rogue devices without disrupting authorized ones, providing a user-friendly interface for operation and enhancing the ability to identify and target specific devices, including those difficult to visually discover or reach.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Rogue or unwanted devices connected to a wireless network (e.g. Wi-Fi) may be de-authenticated by a directional communications device. The directional communications device comprises a directional ant
Need to check novelty before this filing date? Find Prior Art

Description

There are a variety of network management tools and software available commercially, but none of these provide a straightforward and integrated solution to identify and distinguish devices connected to a wireless data network, target specific devices connected to the wireless data network, and manage the connection of rogue or potentially unwanted devices connected to the wireless data network. For example, in patent publication CN 103067916 B, there is described a system operable to block devices from connecting to a wireless data network where these devices do not have their device properties or characteristics detailed on a “white list” of approved devices for connection to that wireless data network. This allows network administrators to limit those devices permitted to connected to wireless data networks that they manage, but this approach does not prevent devices mimicking other devices on the “white list” by spoofing the device properties or characteristics of a device on the “white list”. In another example, in patent publication CN 106572464 B, there is described a method to monitor for rogue access points that are attached to a wireless local area network. The method maintains a list of allowed access points and their respective MAC addresses, and monitors the MAC addresses encoded within data exchange messages being communicated over the wireless local area network to detect rogue access points that are not on the list of allowed access points. Again this approach does not prevent access points that mimic other access points on the list of allowed access points from being able to operate undetected on the wireless local area network. Further, these examples of existing approaches are not typically provided with a user-friendly interface, instead relying on highly trained network administrators being aware of the details of the approach and applying them to situations on an ad hoc basis. These highly trained or skilled network administrators will typically monitor networks under their management for known threats for which alerts have been set up using network monitoring software, and they will do this from a standard computer terminal in an office environment that is not always co-located with the network being administered as these activities can be performed from remote locations unless physical interaction with network equipment is required. Summary of Invention Aspects and / or embodiments seek to provide a directional network communications device able to perform a range of network functions within the communications network solely within the zone of coverage provided by the directional nature of the device. Some aspects provide a device and method for de-authentication of wireless network connections. According to a first aspect, there is provided a directional communications device comprising: a directional antenna operable to transmit and receive communications within a field of view provided by the directional antenna, wherein the directional antenna receives communication data between one or more target devices and at least one access point; a processor in communication with the directional antenna, wherein the processor extracts metadata from the communication data and generates using the metadata a de-authentication request appearing to originate from at least one of the one or more target devices; wherein the device is operable to transmit the de-authentication request via the directional antenna to one of the at least one access points. The use of directional antenna can enable the controlled detection of devices and identification and targeting of rogue or potentially rogue devices. By targeting specific devices amongst all devices operating nearby, appropriate action can be taken to manage the threats posed by rogue devices without substantial disruption or damage to nearby devices that pose no threat. Optionally, there is further provided a user interface, wherein the user interface is operable to present a user of the directional communication device with a list of the one or more target devices and is operable to receive a selection of one or more or the one or more target devices. Optionally, the user interface comprising any or any combination of: one or more buttons; a display; a D-Pad controller. By providing a user interface, substantially more straightforward control of the device can be achieved by the user of the device. Optionally, at least one of the one or more target devices comprises any or any combination of: a drone; an internet-of-things device; a mobile device; a tablet computer; a smartphone; a personal computer. By providing the device with a directional antenna, it is possible to provide a device with substantial range and specificity to target a variety of devices from stationary but difficult to visually discover internet-of-things devices to mobile and difficult to physically reach devices such as drones. Optionally, at least one of the one or more target devices can be identified using manual input of the metadata of the at least one of the one or more target devices. By allowing user to enter metadata manually, known target devices can be targeted by the device. Optionally, the metadata comprises any or any combination of: a MAC address; an intended access point address. By using standard network metadata, the device can identify and target specific devices and specific connections between devices on a wireless data network. Optionally, the directional antenna comprises a plurality of antennas. By using multiple antennas, an substantially larger field-of-view or a combination of antenna properties can be exploited by the device. Optionally, one of the plurality of antennas is an omnidirectional antenna, optionally wherein the omnidirectional antenna is a transmit-only antenna. By providing an omnidirectional antenna as well as the directional antenna, multiple devices can be communicated with without needing to locate the desired target within the field of view of the directional antenna. Optionally, if the omnidirectional antenna is transmit-only, then the directional antenna can be used to target devices of interest while the omnidirectional antenna can transmit signals such as de-authentication packets to a plurality of access points or an access point not within line-of-sight of the directional antenna. In some embodiments, an omnidirectional antenna will be used for transmitting as well as receiving. In some embodiments, multiple omnidirectional antennas are used in conjunction. In some embodiments, some modules, such as the GPS module, will use the omnidirectional antenna. Optionally, the received communication data is stored. Optionally, there is further provided a satellite positioning module wherein the associated positioning data from the satellite positioning module is stored linked to each packet of the stored received communication data. Optionally, the received communication data comprises the device identification data for devices detected to be transmitting by the directional communications device. Storing the data received by the device can allow for later analysis either on-device or off-device using specialist software or higher-computationally-powerful equipment. Optionally, there is further provided a data storage device, the data storage device comprising a whitelist wherein the whitelist comprises a list of permitted devices; wherein the processor determines whether each of the one or more target devices are listed in the whitelist and does not send de-authentication requests pertaining to any target devices listed in the whitelist. By checking that a target device is on a whitelist of permitted devices, the device can target only those devices not permitted to access a wireless data network without disrupting authorised devices. Optionally, the directional antenna is physically remote from the processor and / or user interface and / or data storage device. By providing the antenna or antennas remotely from the processor and / or user interface and / or data storage, a variety of configurations can be used that allows the operator to control one or more antenna(s) remotely and / or allows the location of the antenna(s) in otherwise difficult to reach locations or in locations in need of permanent capabilities. Optionally, the directional antenna comprises an access point in a wireless network. By providing the antenna(s) in an access point, the wireless network can have a built-in defence system. According to a second aspect, there is provided a method of de-authenticating a target device comprising: receiving communications using by a directional antenna, wherein the directional antenna receives communication data between one or more target devices and at least one access point within a field of view of the directional antenna; extracting metadata from the communication data and generating, using the metadata, a de-authentication request appearing to originate from at least one of the one or more target devices; transmitting the deauthentication request via the directional antenna to one of the at least one access points. Brief Description of Drawings Embodiments will now be described, by way of example only and with reference to the accompanying drawings having I ike-reference numerals, in which: Figure 1 shows a simplified side-view of a device according to an embodiment; Figure 2 shows a simplified view of the user interface of the device of Figure 1 according to an embodiment; Figure 3 shows an example directional antenna arrangement of the device of Figure 1 according to an embodiment; Figure 4 shows the use of the directional antenna device of Figure 1 alongside other devices within a wireless communications network according to an embodiment; Figure 5 shows an example menu structure of the user interface controlled via the user interface, showing the nested menu selection screens for one route through the menu structure, of the device of Figure 2, according to an embodiment; Figure 6 shows a system diagram of the device of Figure 1 according to an embodiment; Figure 7 shows a simplified diagram illustrating the functionality of the passive listening module of the device of Figure 1 according to an embodiment; Figure 8 shows a simplified diagram illustrating the functionality of the geo-tagging and storage module of the device of Figure 1 according to an embodiment; Figure 9 shows a simplified diagram illustrating the functionality of the module for blocking non-white listed devices, from a wireless network, of the device of Figure 1 according to an embodiment; Figure 10 shows a simplified diagram illustrating the functionality of the deauthentication process of the device of Figure 1 according to an embodiment; Figure 11 shows a simplified diagram illustrating the functionality of the noise module of the device of Figure 1 according to an embodiment; Figure 12 shows a simplified diagram illustrating the functionality of the vulnerability analysis module of the device of Figure 1 according to an embodiment; Figure 13 shows a simplified diagram illustrating the functionality of the man-in-the-middle module of the device of Figure 1 according to an embodiment; Figure 14 shows a simplified diagram illustrating the functionality of the password sniffing module of the device of Figure 1 according to an embodiment, showing a first step performed by the module; and Figure 15 shows a simplified diagram illustrating the functionality of the password sniffing module of the device of Figure 1 according to an embodiment, showing a second step performed by the module. Specific Description Referring now to Figures 1 to 15, a specific description of an embodiment will now be described in further detail along with alternative embodiments and optional functionality. Referring to Figure 1, a directional network communications device 100 according to an embodiment will now be described. There is shown a device 110 having a grip 150, three primary buttons 130, a switch protector 140 and a transmitter and receiver 120. Not shown is a user interface including a display and a controller. The grip 150 enables a user to hold the device substantially securely and with the primary buttons 130 able to be used. The three primary buttons 130 are operable to be depressed by the user’s fingers, to activate their respective functions. In this embodiment, the first button locks on to a target, the second button switches an attack on or off, and the third button functions as a “panic” button which switches all actions off. The switch protector is a plastic cover on a hinge, that can be moved away from covering the primary buttons 130 to allow a user to operate the device and which can be replaced covering the primary buttons 130 to prevent accidental use of the device 100. The transmitter and receiver 120 is the output area of the device allowing it to transmit wireless signals to a wireless network or device and / or receive these same signals. This end 120 of the device 100 is pointed at the intended target or devices on which to use the functionality of the device 100. In this embodiment, the form factor can be described as a “rifle” style form factor. In other embodiments, a different form factor can be used for the device 100. In other embodiments, a different number of primary buttons 130 can be used. In other embodiments, different functions can be allocated to the buttons. In other embodiments, no switch protector may be present or alternatively another mechanism for providing a removable screen to prevent accidental depression of the primary buttons 130 may be provided. In other embodiments, the controls for the device can be provided on another device remote from the physical device, allowing the physical device to be mounted remotely or on a platform or fixed / movable mounting. For example, the device might be mounted on buildings, or tripods, or on a gimbal which can be mounted on the same or platforms such as vehicles. As a further example, the device when suitable mounted in any of the possible options, can be remotely controlled using a tablet computer or laptop computer (or any device presenting the user interface and offering user input capabilities). Referring to Figure 2, a device user interface 200 according to an embodiment will now be described. There is provided a device user interface 210 having a display 220 and a user interface button 230. The display 220 provides the user with a selection of options to choose, typically of which functions to perform using the device 100. The display in this embodiment is a grayscale LCD screen. The user interface button 230 is a “D-pad” or directional pad, which is a flat, thumb-operated directional control found on nearly all modern gamepads, handheld game consoles, and audiovisual device remote controls. The directional pad operates using four internal pushbuttons arranged at 90° angles, providing discrete directional options typically linked to up, down, left, and right functions on a connected user interface, with possible diagonal combinations through two-button presses. By pressing up or down, or right or left, the user can navigate the menus of the user interface presented on the display 220. Alternative display technologies can be used, including multiple screens and / or indicators such as LED lights. Alternative user interface button or buttons can be used, for example joysticks, trackpads, or discrete function buttons or numbered buttons. Alternatively, a touchscreen user interface may be provided, removing the need for a separate control 230 and allowing the user to interact directly with the display 220. In some embodiments, display 220 is a colour LCD screen. Referring to Figure 3, a directional antenna 300 according to an embodiment will now be described. The directional antenna 300 comprises a central boom rod made from stainless steel 360, having drilled discs 340 fitted around the central boom rod 360, where the drilled discs 340 are positioned at measured distance intervals from each other along the central boom rod 360 using spacers 310 to hold the drilled discs 340 in place. Two fixing nuts are provided at each end of the central boom rod 360 to hold the spacers 310 and drilled discs 340 in place. The central boom rod 360 extends out at one end beyond the drilled discs 340 to form a boom end 350, and there is a co-axial connector fitted in parallel to the boom end 350 to one of the drilled discs 340, spaced apart from the boom end 350. This arrangement provides a directional antenna, which has a narrow field of view and can communicate by transmitting and receiving signals only within this narrow field of view. This arrangement is sometimes referred to as a “cigar” style antenna, which can be used to pinpoint a target directionally, i.e. isolate one device to target among other devices not intended to be targeted. Use of a directional antenna substantially increases the range of the device. Use of a directional antenna also substantially decreases the number of devices detected on a wireless network when using a “monitor mode”, which would otherwise present the user via the user interface with an unmanageable large number of devices to choose from / assess as targets if using an omni-directional antenna in “monitor mode”. In alternative embodiments, alternative directional antenna arrangements can be used. In other embodiments, the directional antenna can be used alongside a non-directional antenna where the directional antenna is used to target rogue or potentially rogue devices while the non-directional antenna can be used to broadcast certain transmissions such as deauthentication requests, where these transmissions need to be sent to non-directional recipients (e.g. multiple access points, or access points not within line of sight of the directional antenna). In alternative embodiments, an electronically steerable antenna can be used. In other embodiments, the central boom rod 360 is a rod made out of another conductive metal such as copper, bronze, etc. In other embodiments, the central boom rod 360 is a rod-like shape. Referring to Figure 4, the line of sight limited field of view of the directional antenna of the device 400 according to an embodiment will now be described. The user 430 is using the device 100, which has a limited field of view or line of sight 440 such that the device can “see”, i.e. can communicate with by receiving signals from and / or transmitting signals to, an access point 410, but cannot “see” other devices 420 that are connected to the same wireless data network as that provided by the access point 410. Referring to Figure 5, an example menu structure of the user interface 500 of the device 100 according to an embodiment will now be described. In this example menu structure, three menu levels are shown: a top-level menu 510; a second level menu 520; and a third level menu 530. The top level menu 510 is the first menu presented to the user of the device 100. Using the user interface controls, the user can select one of the options presented in the menu 510. Assuming the user selects the first option in the top level menu 510, the second level menu for that selection will be displayed 520. Similarly, assuming the user selects the first option in the second level menu 520, the third level menu 530 for that selection will be displayed. Selecting one of the options in this third level menu will activate the device 100 to perform a specific function based on the menu choices of the user and an associated functionality of the device 100. Alternative menu structures might require different numbers of levels of choices to be presented to a user, or a combination of levels of choices - for example a common function might be able to be selected from the top level menu 510 directly while less-used functions might be selectable from a deeper level menu. Referring to Figure 6, a system diagram 600 illustrating some of the functions of the device 100 according to an embodiment will now be described. The system 600 comprises a receiving antenna 610, a switch or touchscreen user interface 615 and a transmitting antenna 620. The receiving antenna 610 is coupled to a receiver 625 while the transmitting antenna is coupled to a transmitter 635. The system 600 comprises a variety of modules 640, 645, 650, 655 that are coupled to the receiver 625 and transmitter 635. Some modules 640 are in communication with external systems 665. Some modules 655 are in communication with databases 660 to store data. Some modules 640 are in communication with GPS modules to receive positioning data. For example, in this embodiment, the system 600 is provided with a geotagging and storage module 640, a de-authentication module 645, a noise module 650 and a vulnerability module 655. Based on the user input 630 provided by the user interface 615, the receiver or transmitted can be triggered to perform a function enabled by one or more of the modules 640, 645, 650, 655. These modules 640, 645, 650, 655 will be described in further detail below. In other embodiments, the system 600 may contain different combinations of modules to those shown in this Figure. Referring to Figure 7, a passive listening module 700 according to an embodiment will now be described. The module 700 is in communication with a station or access point 710, is provided on the device 720 and comprises storage 730. The station or access point 710 is the device of interest on the data network, which is being targeted by a user. The device 720 is the device of this embodiment, having the receiving antenna described hereinbefore and able to receive signals within the field of view of the directional antenna. The storage 730 is a memory device on-board the device 720 that is operable to store the data received by the receiving antenna from the station or access point 710. This module 700 provides for the intercept of packets from the station or access point 710 received via the receiving antenna on the device 720. These packets are stored internally on the storage 730 for analysis on an external machine. In alternative embodiments, the device 720 might be directed at an end-user device on the network rather than an access point 710. The storage 730 can be any form of storage including on-board or remote storage and / or permanent or temporary storage. Referring to Figure 8, a geo-tagging and storage module 800 according to an embodiment will now be described. The module 800 is in communication with a station or access point 810 on a data network that is transmitting data in the form of packets 820. The packets 820 are received by the receiving antenna of the device according to the embodiment 830. The device 830 then queries a global positioning system module to receive position data 860 to associate with each packet 820 received by the device 830. The packet 820 and position data 860 are combined into a data and GPS packet 870 and this is stored in storage medium 880. The data stored in the storage medium 880 can then be analysed and / or decrypted and / or processed, typically using an external device with more computation power or that uses specific software to perform these tasks. In alternative embodiments, the device 830 might be directed at an end-user device on the network rather than an access point 810. The storage 880 can be any form of storage including on-board or remote storage and / or permanent or temporary storage. Other positioning systems other than GPS can be used, including satellite position but also inertial, cell-tower or image-based positioning can be used in these alternative embodiments. In other embodiments, no geo-tagging process or GPS data is used and transmissions on the data network are simply stored for future analysis. Referring to Figure 9, a method of blocking non-while listed devices 900 according to an embodiment will now be described. The method uses the receiving antenna 910 and the transmitting antenna 920 of the device 100 to perform a series of steps 930, 940, 950, 960, 970. First, the device 100 receives signals via the receiving antenna 910. From these signals, the MAC addresses of one or more target devices are extracted along with the intended access point address(es) with which the target device is, or target devices are, communicating. A MAC address (Media Access Control address) is a unique identifier assigned to a network interface controller (NIC) for use as a network address in communications within a network segment. It is a 12-digit hexadecimal number, typically represented as six groups of two hexadecimal digits separated by hyphens, colons, or without separators (e.g., 00:1A:2B:3C:4D:5E). Each MAC address is unique to the device's NIC, ensuring that no two devices on the same network segment have the same MAC address. MAC addresses are usually assigned by the device manufacturer and are often referred to as burned-in addresses (BIAs). Second, the device compares the extracted MAC address(es) with a whitelist of MAC addresses 940 to determine whether the extracted MAC address(es) is / are present on the whitelist of approved devices. This white list can be maintained to include all devices known to be permitted to join a specific wireless network. Third, if one or more of the extracted MAC addresses are found on the whitelist of MAC addresses, no action is taken 950 for those MAC addresses, as each of these devices are deemed to be permitted to join and remain connected to the specific wireless network of interest. Fourth, if any of the extracted MAC addresses are not found on the whitelist of MAC addresses, then the device 100 starts forging packets 960, mimicking packets send by the non-approved devices but using the MAC addresses of the non-whitelisted devices. In this embodiment, these mimicked packets aim to de-authenticate the non-whitelisted devices, thus disconnecting each of them from the wireless network. Each de-authentication packets 960 include the MAC address of the non-whitelisted device as the originating address along with the destination address as that of the access point with which the non-whitelisted device is communicating as the intended destination for the de-authentication packet 960. Fifth, these de-authentication packets are then transmitted 970 on to the wireless network using the transmitting antenna 920. The access points and devices on the wireless network cannot verify that the spoofed messages including the MAC address of the non-whitelisted device(s) came from their advertised (i.e. via the MAC address used in the messages) source, so accept these as legitimate. The spoofed messages will then cause the non-whitelisted device(s) to be disconnected from the wireless network due to the spoofed messages and will thus prevent valid responses being sent and data being transmitted via the wireless data network between the target device and the access point as the access point no longer considers the target device to be connected to the wireless data network. In other embodiments, rather than a device on the wireless network, a rogue access point can be disconnected or disrupted from remaining on the wireless network - rogue access points can be used to join an existing wireless network and store or modify data transferred over the wireless network passing via the rogue access point, and network administrators will know the MAC addresses of all authorised network equipment thus will be able to use this information to enable targeting and disconnection of rogue access points. Referring to Figure 10, a de-authentication process 1000 according to an embodiment will now be described, for example that can be used with the method shown in Figure 9 and described above. The de-authentication process 1000 involves a client device 1010, which is intended to be disconnected from the wireless data network, the device 1020, which will arrange this disconnection, and the access point 1030 from which the client device 1010 will be disconnected in order to disconnect the client device 1010 from the wireless data network. In a normal connection process 1040, where the client device 1010 connects to a wireless data network via an access point 1030, the client device 1010 sends an authentication request 1041 to the access point 1030. Then the access point 1030 responds with an authentication response 1042 to the client device 1010, after which the client device 1010 sends an association request 1043 to the access point 1030. The access point 1030 then response with an association response 1044. This process authenticates and connects the client device 1010 to the access point 1030. Once the client device 1010 is connected via the access point 1030, it can start transmitting data 1045 on the wireless data network via the access point 1030. However, when the user of device 1020 determines that the client device 1010 needs to be disconnected from the access point 1030, perhaps because it is a rogue device that is not on a white list of approved devices permitted to access the wireless network provided by access point 1030, the following process is used. The device 1020 sends a de-authentication request using a spoofed de-authentication packet (i.e. mimicking the metadata used by the client device 1010, to make the packet appear to have originated from client device 1010) to the access point 1030. In the meantime, the client device 1010 is still sending data 1047 to the access point 1030. However, in response to the de-authentication request send to the access point 1030 by the device 1020 but appearing to be send on behalf of the client 1010, the access point 1030 de-authenticates the client device 1010 and sends a de-authentication confirmation message 1048 to the client device 1010 which then updates its status to being disconnected. This may trigger the client device 1010 to attempt to re-connected to access point 1030 but the same process can be repeated until the client device 1010 stops attempting to reconnect. In other embodiments, the de-authentication process can be triggered manually by a user of device 1020 rather than in response to determining that the client device 1010 is not on a white list of approved devices. In other embodiments, the client device 1010 may be a rogue access point attempting to attach itself to access point 1030 to extend the wireless data network in order to perform rogue activities such as recording data transmitted on the wireless data network. In other embodiments, the de-authentication process can receive a manual input of a MAC address to de-authenticate. In other embodiments, the de-authentication process can receive a list of MAC addresses to de-authenticate and optionally can broadcast de-authentication requests for any or all of these MAC addresses periodically. Referring to Figure 11, a noise module and its operation 1100 according to an embodiment will now be described. When the device 1120 is interacting with a station or access point 1110, the two exchange data packets 1111, 1112. Where the device 1120 detects a device that needs to be interrupted from communicating on a wireless network, it can be triggered to engage a noise module 1130 to generate random data to flood the network in order to disrupt the entire network or specific devices on the network provided by the station or access point 1110. The noise module receives the channel data 1121 from the device 1120, which is the packets of data received 1111 from the station or access point 1110 by the device 1120. Using the metadata from the channel data 1121 and the operation parameters from the device 1120, provided by a user of the device 1120 (i.e. whether a single device is to be disrupted or the entire access point), spoofed packets containing noise can be generated 1122 and the device 1120 transmits these 1112 to the station or access point 1110 causing disruption in the communications of the targeted device or network. By providing a randomised, amplified signal into the network traffic, this signal makes it substantially hard or impossible for the routers / access points to operate correctly. Referring to Figure 12, a vulnerability analysis module 1200 and its operation according to an embodiment will now be described. Where the device 1220 is connected to a station or access point 1210 and exchanging data 1211, 1212, the operator of the device 1220 may wish to assess whether any devices on the network are able to be exploited using known vulnerabilities (i.e. known weaknesses in their code that allow software attacks to be used to disrupt or monitor these devices). To do this, the device 1220 receives packets 1211 transmitted by the access point 1210 and sends the metadata 1221 from these packets 1211 to a vulnerability analysis module 1230. The vulnerability analysis module 1230 performs a lookup in a database of known vulnerabilities using the metadata 1221 to filter the database for the correct combination of reported software versions and device version. Where one or more known vulnerabilities are identified in the database, these are reported 1222 back to the device along with details of how to exploit these vulnerabilities. The operator of the device 1220 can then select one or more of the vulnerabilities to exploit and send the payload packets 1212 to the access point and / or device in order to exploit the device and / or access point vulnerabilities. In other embodiments, the module can automatically test each detected vulnerability in sequence to determine whether the exploit will work. Referring to Figure 13, a man in the middle module 1300 and its operation according to an embodiment will now be described. Where there is a station or access point 1310 communicating 1360 with a client device 1330, the device 1320 can disrupt the original communication channel 1360 using a deauthentication approach. Once the station or access point 1310 has been disconnected from the client device 1330, the client device 1330 will typically automatically reconnect to the station or access point 1310. By increasing the power of the signals emitted by the device 1320, or locating the device 1320 physically in between the station or access point 1310 and the client 1330, the device 1320 can receive the reconnection request from the client device 1330 by spoofing the properties of the station or access point 1310. The device 1320 can also, either before connecting with the client device 1330 of afterward, spoof being the client device 1330 and connect itself to the station or access point 1310. Once this has been achieved, the device sits in between the connection from the station or access point 1310 to the client device 1330 while both the station or access point 1310 and the client device 1330 consider themselves connected directly to each other. Referring to Figure 14, a password sniffing module 1400 and the first part of its operation according to an embodiment will now be described. In the situation where there is a station or access point 1410 communicating data traffic 1440 with a client device 1430, and the user of the device 1420 wants to obtain one or more passwords or credentials from the client device 1430, a password sniffing process is used. First, the device 1420 sends a de-authentication request, spoofed to appear to originate from client device 1430, to station or access point 1410. Referring to Figure 15, a password sniffing module 1500 and the second part of its operation according to an embodiment will now be described. When the client device 1530 has been disconnected by the station or access point 1510 as a result of the de-authentication message from the device 1520, the client device 1530 typically automatically sends a re-authentication handshake 1540 which can also be received 1550 by the device 1520. This can be analysed to determine the password or credentials provided by the client device 1530 to the station or access point in order for the device 1520 to learn these. Other modules can be provided with the device in other embodiments, to provide additional functionality to the device. The device in other embodiments can be implemented using a combination of antenna and electronics or computer equipment, with either integrated display and control for the user or remotely operated software display and controls for the user. Target devices can include a variety of internet-connected devices, including drones and loT devices that connect via Wi-Fi or other wireless data networks. Any system feature as described herein may also be provided as a method feature, and vice versa. As used herein, means plus function features may be expressed alternatively in terms of their corresponding structure. Any feature in one aspect may be applied to other aspects, in any appropriate combination. In particular, method aspects may be applied to system aspects, and vice versa. Furthermore, any, some and / or all features in one aspect can be applied to any, some and / or all features in any other aspect, in any appropriate combination. It should also be appreciated that particular combinations of the various features described and defined in any aspects can be implemented and / or supplied and / or used independently.

Claims

1. A directional communications device comprising:a directional antenna operable to transmit and receive communications within a field of view provided by the directional antenna, wherein the directional antenna receives communication data between one or more target devices and at least one access point;a processor in communication with the directional antenna, wherein the processor extracts metadata from the communication data and generates using the metadata a de-authentication request appearing to originate from at least one of the one or more target devices;wherein the device is operable to transmit the de-authentication request via the directional antenna to one of the at least one access points.

2. The directional communications device of claim 1, further comprising:a user interface, wherein the user interface is operable to present a user of the directional communication device with a list of the one or more target devices and is operable to receive a selection of one or more or the one or more target devices.

3. The directional communications device of claim 2, wherein the user interface comprising any or any combination of: one or more buttons; a display; a D-Pad controller.

4. The directional communications device of any preceding claim, wherein at least one of the one or more target devices comprises any or any combination of: a drone; an internet-of-things device; a mobile device; a tablet computer; a smartphone; a personal computer.

5. The directional communications device of any preceding claim, wherein at least one of the one or more target devices can be identified using manual input of the metadata of the at least one of the one or more target devices.

6. The directional communications device of any preceding claim, wherein the metadata comprises any or any combination of: a MAC address; an intended access point address.

7. The directional communications device of any preceding claim, wherein the directional antenna comprises a plurality of antennas.

8. The directional communications device of claim 7, wherein one of the plurality of antennas is an omnidirectional antenna, optionally wherein the omnidirectional antenna is a transmit-only antenna.

9. The directional communications device of any preceding claim, wherein the received communication data is stored.

10. The directional communications device of claim 9, further comprising a satellite positioning module wherein the associated positioning data from the satellite positioning module is stored linked to each packet of the stored received communication data.

11. The directional communications device of claim 9, wherein the received communication data comprises the device identification data for devices detected to be transmitting by the directional communications device.

12. The directional communications device of any preceding claim, further comprising a data storage device, the data storage device comprising a whitelist wherein the whitelist comprises a list of permitted devices; wherein the processor determines whether each of the one or more target devices are listed in the whitelist and does not send de-authentication requests pertaining to any target devices listed in the whitelist.

13. The directional communications device of any preceding claim, wherein the directional antenna is physically remote from the processor and / or user interface and / or data storage device.

14. The directional communications device of any preceding claim, wherein the directional antenna comprises an access point in a wireless network.

15. A method of de-authenticating a target device comprising:receiving communications using by a directional antenna, wherein the directional antenna receives communication data between one or more target devices and at least one access point within a field of view of the directional antenna;extracting metadata from the communication data and generating, using the metadata, a de-authentication request appearing to originate from at least one of the one or more target devices;transmitting the de-authentication request via the directional antenna to one of 5 the at least one access points.18

Citation Information

Patent Citations

  • Method for adaptively disconnecting target wifi connection

    CN115243403A

  • System and method for detecting and locating interferers in a wireless communication system

    US20030123420A1

  • Intrusion detection in a wireless network using location information of wireless devices

    US20210409953A1