Wireless Access Point Tracing via IP Packet Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unauthorized access points in wireless networks can pose security risks by allowing unauthorized access to private wired networks, as they can be connected without detection, leading to potential data breaches and network intrusion.

Innovation Solution

A detector sends an IP packet through the wireless network with specific IP address settings to trace the access point, determining if it is connected to the same private wired network by routing the packet back through a switch, allowing identification of unauthorized access points and their connection ports, enabling disconnection or disabling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the wireless network uses an open architecture to allow stations to associate with access points, then network interoperability and ease of access are improved, but security risks increase due to potential unauthorized access points

Engineering Contradiction:
Improveease of accessVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary detection by sending IP packets from a detector through the wireless network to access points before unauthorized access can occur. The detector proactively traces access points by routing packets through the wireless network and analyzing return paths, identifying unauthorized access points before they can compromise network security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes a feedback mechanism where the detector monitors IP packet return paths from access points. By analyzing which packets return through the private wired network and tracing their paths through switches, the system continuously feedbacks information about access point authorization status, enabling real-time security monitoring and response.

Inventive Principle:
Principle #23Feedback

2Duration of action of stationary object

If unauthorized access points are not detected, then the wireless network maintains operational continuity, but confidential information may be compromised through undetected data breaches

Engineering Contradiction:
Improveoperational continuityVSAvoidinformation security
Core Design Contradiction:
Duration of action of stationary objectVSReliability

Solution Approach 1:

The detector serves as an intermediary between the private wired network and wireless access points. It intercepts and analyzes IP packet traffic, acting as a security gateway that can identify unauthorized access points without disrupting the normal operation of authorized access points, thus maintaining operational continuity while ensuring information security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces physical security inspection methods with electronic IP packet tracing. Instead of manual security checks or physical access control, the system uses network-layer IP packet routing and analysis to automatically detect unauthorized access points, providing continuous security monitoring without mechanical intervention.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If the detector traces all access points by sending IP packets through the wireless network, then unauthorized access points can be identified, but network traffic increases and detection complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The detection process is segmented into distinct phases: IP packet transmission from detector to access point through wireless network, packet routing through private wired network switches, and analysis of return packet paths. This segmentation allows the system to trace access points systematically by breaking down the complex tracing operation into manageable stages, improving detection accuracy while organizing complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access points themselves participate in the detection process by responding to IP packets with their own traffic. Instead of requiring active probing or complex scanning mechanisms, the system leverages the access points' normal network operations and traffic patterns to enable self-identification and tracing, reducing detection complexity while maintaining accuracy.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8437263B2Tracing an access point in a wireless network
Publication Date: 2013.05.07 NETSCOUT SYSTEMS INC
  • US8437263B2 patent drawing
  • US8437263B2 patent drawing
  • US8437263B2 patent drawing

AI summary

An access point in a wireless network is traced by sending an internet protocol (IP) packet from a detector to the access point through the wireless network. The detector and the access point are connected through a private wired network. The IP packet is sent with the source IP address field and the destination IP address of the IP packet set to the wireless IP address and wired IP address, respectively, of the detector. The IP packet is routed back to the detector through a switch in the private wired network. When the IP packet is received at the detector, a source IP address, which corresponds to the port on the switch used to send the IP packet, is determined from the received IP packet.