Network Characterization System for Rogue Access Point Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of modern computing environments with numerous broadband networks poses security risks and management difficulties, as users often face challenges in seamlessly connecting to networks due to the presence of rogue access points and multiple connection clients, leading to resource consumption and user frustration.

Innovation Solution

A network characterization system that includes a detection unit to identify network indicators, a classification unit to categorize networks as trusted, untrusted, or semi-trusted based on provided attributes, and a characterization unit to verify the accuracy of these classifications, ensuring secure and seamless connections by leveraging additional information beyond network provider identifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users use multiple connection clients to connect to multiple networks, then network connectivity is improved, but system resource consumption increases and user confusion increases

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsystem resource consumption
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal connection client that can handle multiple network types (WiFi, Bluetooth, cellular, wired Ethernet) through a single unified interface. The system automatically detects available networks, classifies them by trust level, and manages connections across different network technologies without requiring separate clients for each network type, thereby reducing system resource consumption while maintaining versatile connectivity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If users manually manage multiple connection clients, then network access flexibility is improved, but ease of operation deteriorates due to user confusion and frustration

Engineering Contradiction:
Improvenetwork access flexibilityVSAvoiduser confusion
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system implements automatic network discovery, classification, and connection management without requiring manual user intervention. The connection client automatically detects available networks, classifies them by trust level based on various indicators, prioritizes trusted networks, and establishes connections autonomously. The system also automatically re-evaluates network trust levels and switches connections when needed, eliminating user confusion while preserving access flexibility.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary network classification and trust assessment before users need to connect. By proactively evaluating networks and establishing a hierarchy of trusted versus untrusted networks in advance, the system prepares connection options ready for user selection or automatic connection, reducing the cognitive load and decision-making complexity for users at the moment of connection need.

Inventive Principle:
Principle #10Preliminary action

3Speed

If the system classifies networks based on provider identifiers, then connection speed is improved, but reliability deteriorates due to rogue access points

Engineering Contradiction:
Improveconnection speedVSAvoidnetwork trustworthiness
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system implements continuous feedback loops for network evaluation. After initially classifying networks based on provider identifiers for fast connection, the system continuously monitors network behavior, checks for expected attributes and services, and re-evaluates trust levels based on actual network performance and characteristics. This feedback mechanism allows the system to quickly connect to suspected rogue networks while automatically detecting and disconnecting from malicious networks, maintaining both speed and reliability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary classification based on provider identifiers to enable fast initial connection assessment, but immediately follows up with verification steps including checking for expected network attributes, services, and behaviors. This preliminary action followed by verification allows the system to quickly identify potential networks while maintaining security through subsequent validation, preventing connection to rogue access points that mimic legitimate networks.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9088627B2System and method for actively characterizing a network
Publication Date: 2015.07.21 CHANNEL IP BV
  • US9088627B2 patent drawing
  • US9088627B2 patent drawing
  • US9088627B2 patent drawing

AI summary

In one embodiment the method includes detecting a network indicator associated with a network, the network provided by a network provider. In one embodiment, after the detecting of the network indicator, the method includes obtaining from the network provider an actual attribute associated with the network. The method may also include determining, based on stored network information, whether the actual attribute matches an expected attribute for the network. If the actual attribute matches the expected attribute, the method may classify the network into one of a plurality of network classes.