Wireless AP Intrusion Detection Broadcast

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intrusion detection systems in wireless communication networks face challenges in efficiently disseminating information about illegal devices and incorrectly detecting legitimate access points, leading to unnecessary disconnection of clients and increased reconnection time.

Innovation Solution

Access points proactively broadcast intrusion detection information, including identifiers of illegal devices and the AP performing containment, using beacon frames and encryption to ensure secure communication, allowing other APs to determine and respond to malicious activity while minimizing false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an AP performs containment on a detected illegal device, then network security is improved, but false positives may cause legitimate devices to be disconnected

Engineering Contradiction:
Improvenetwork securityVSAvoidfalse positive disconnections
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where APs broadcast containment information and receive responses from other APs to verify the illegal status of detected devices. This allows legitimate devices to be identified and excluded from containment actions, reducing false positives while maintaining security.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary verification by broadcasting containment information before executing containment actions. Other APs can respond to verify the device status, ensuring that containment is only applied to genuinely illegal devices and not legitimate ones.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If an AP disconnects clients from a detected illegal device, then security is enhanced, but reconnection time increases when the detection is incorrect

Engineering Contradiction:
ImprovesecurityVSAvoidreconnection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The feedback mechanism allows APs to verify the legality of devices before disconnection. By receiving responses from other APs confirming the illegal status, the system avoids unnecessary disconnections of legitimate devices, thereby preventing extended reconnection times.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system takes preliminary anti-action by verifying device status through broadcasting and receiving responses before executing disconnection. This prevents the harmful action of disconnecting legitimate devices, avoiding the need for time-consuming reconnection processes.

Inventive Principle:
Principle #9Preliminary anti-action

3Speed

If intrusion detection information is broadcast to all APs, then response time to malicious activity is reduced, but network traffic increases

Engineering Contradiction:
Improveresponse timeVSAvoidnetwork traffic
Core Design Contradiction:
SpeedVSLoss of energy

Solution Approach 1:

The patent extracts only the necessary containment information (device identifiers and detecting AP identifier) and broadcasts it selectively to other APs. This minimizes the amount of network traffic while still enabling rapid response to malicious activity across the network.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12081985B2Broadcast of intrusion detection information
Publication Date: 2024.09.03 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12081985B2 patent drawing
  • US12081985B2 patent drawing
  • US12081985B2 patent drawing

AI summary

Implementations of the present disclosure relate to intrusion detection information. A method comprises detecting, by an access point (AP), at least one device in a wireless communication network to be an illegal device. The method also comprises obtaining, by the AP, intrusion detection information related to the at least one device, the intrusion detection information comprising at least one identifier of the at least one device.