Remote Sensor Emulating Client Workstation for Wireless Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional wireless intrusion detection and prevention systems are ineffective in unknown wireless networks, as they rely on reactive signature matching and are unable to assess security risks before a device joins the network, leaving users vulnerable to various threats.

Innovation Solution

A remote sensor system with a virtual client subsystem mimics a client workstation to connect to the network, monitor security threats, and report them back to a user via a secure tunnel, providing proactive threat detection and analysis before access is granted, using techniques applicable to both wireless and wired networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional WIPS technologies use reactive signature matching to detect malicious traffic, then detection capability for known attacks is improved, but the system cannot assess security risks before a device joins the network

Engineering Contradiction:
Improvedetection capabilityVSAvoidsecurity assessment timing
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs security assessment actions before the user's device joins the network. A remote sensor with virtual client subsystem connects to the network first, actively probes for threats, and reports findings before the user initiates access, enabling proactive rather than reactive security evaluation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A remote sensor acts as an intermediary between the user's vulnerable workstation and the foreign wireless network. The sensor mimics a client workstation, connects to the network first, and performs threat detection on behalf of the user's device, isolating the vulnerable device from direct exposure to potential attacks

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If traditional WIPS systems monitor network traffic passively, then system complexity is reduced, but the system cannot detect active attacks or lure attackers into revealing themselves

Engineering Contradiction:
Improvesystem complexityVSAvoidattack detection accuracy
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system dynamically switches between passive monitoring and active probing modes. The remote sensor can passively listen for attacks, actively transmit typical internet traffic to lure attackers, or perform specific threat hunts depending on network conditions and detection needs, making the detection approach adaptive rather than static

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system uses the attacker's own actions against them by transmitting typical internet traffic that lures attackers into initiating attacks. The virtual client subsystem automatically responds to detected threats and reports findings, enabling the system to detect attacks through the attackers' self-revealing behavior

Inventive Principle:
Principle #25Self-service

3Ease of operation

If a user connects directly to a foreign wireless network with a vulnerable workstation, then network access is achieved, but the device becomes vulnerable to security threats

Engineering Contradiction:
Improvenetwork accessVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The remote sensor serves as a protective intermediary between the user's vulnerable workstation and the foreign wireless network. The sensor connects to the network first, performs threat detection, and only after verification does it allow the user's device to connect, effectively filtering out security risks before they can affect the vulnerable device

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security verification by having the remote sensor connect to and assess the network before the user's device joins. This advance checking ensures that security threats are identified and mitigated before the vulnerable workstation becomes exposed to potential attacks

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9628502B2Active attack detection system
Publication Date: 2017.04.18 MEADOW HILLS
  • US9628502B2 patent drawing
  • US9628502B2 patent drawing
  • US9628502B2 patent drawing

AI summary

A method and system of detecting security attacks on a wireless networked computer system includes a remote sensor having a wireless adapter, processor, storage and memory, the remote sensor configured and arranged to emulate a client workstation that is activated and instructed to connect to a wireless computer network having an unknown security status. A secure communications tunnel is established via wired or wireless means between the remote sensor and a server. The server is configured to issue commands to the remote sensor and receive alert information from the remote sensor which detects security events on the wireless computer network. The server determines the threat level the security event poses to a user of the wireless computer network and issues a threat assessment to the user.