Anomalous Access Point Detection via Client Reports

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in detecting and mitigating 'evil twin' access points, which impersonate legitimate access points to steal data or deliver malicious payloads, especially in large corporate environments with numerous access points.

Innovation Solution

A fraud detection service that utilizes client devices to report visible access points and their locations, comparing these reports to expected access point positions to identify anomalies, such as evil twin access points, and trigger corrective actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional signal monitoring methods are used to detect evil twin access points, then detection capability is improved, but cost and system complexity increase significantly

Engineering Contradiction:
Improveevil twin detection capabilityVSAvoidsignal monitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes client devices (smartphones, laptops) perform the detection work themselves by having them scan for access points and report their observations to the fraud detection service, eliminating the need for expensive dedicated signal monitoring hardware while leveraging the computational resources already present in user devices

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses multi-functional client devices that serve both as end-user computing devices and as distributed detection sensors, allowing these devices to perform their primary computing functions while simultaneously contributing to network security by detecting evil twin access points

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If comprehensive access point monitoring is implemented across large corporate environments, then detection accuracy is improved, but the number of access points to monitor and system resource requirements increase

Engineering Contradiction:
Improveaccess point location verification accuracyVSAvoidnumber of access points to monitor
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system divides the monitoring task into segments performed by multiple client devices distributed throughout the corporate environment, with each device independently scanning and reporting access points in its local area, collectively providing comprehensive coverage without requiring centralized monitoring of all access points simultaneously

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds the dimension of client device location data to the detection process, using geographic positioning information from multiple devices to triangulate and verify access point locations, thereby improving detection accuracy through spatial distribution rather than increasing the number of monitored access points

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP4325384B1Anomalous access point detection
Publication Date: 2025.03.05 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP4325384B1 patent drawingFigure 1
  • EP4325384B1 patent drawingFigure 2
  • EP4325384B1 patent drawingFigure 3

AI summary

Disclosed in some examples are methods, systems, devices, and machine-readable mediums that detect evil twin and other anomalous access points in an IT infrastructure by detecting access points that are not in their expected locations based upon an analysis of access point reports from one or more computing devices.