Rogue AP BSSID Normalization for Physical Access Point Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing number of rogue access points and events in network environments, particularly with the adoption of 5G mobile networks and Wi-Fi 6, makes rogue AP analysis unwieldy due to a large number of displayed threats, complicating the correlation and grouping of rogue broadcast service set identifiers (BSSIDs) from the same physical AP.
Innovation Solution
Implementing a normalization process using vendor-specific translation algorithms to determine a common normalized BSSID for a plurality of BSSIDs, allowing for a more user-friendly and efficient analysis by displaying rogue events associated with a single physical AP, reducing the number of displayed threats and enhancing threat correlation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If vendor-specific translation algorithms are applied to normalize BSSIDs, then the number of displayed rogue APs is reduced and analysis becomes more manageable, but the complexity of the system increases due to the need to implement and maintain multiple vendor-specific algorithms
Solution Approach 1:
The patent introduces a normalization process as an intermediary layer between raw BSSID data and the rogue AP analysis interface. This intermediary translates multiple vendor-specific BSSID formats into a unified representation, reducing the number of displayed threats while managing complexity through standardized processing logic.
Solution Approach 2:
The system changes the parameter representation of BSSIDs by applying vendor-specific translation algorithms that convert raw BSSID identifiers into normalized forms. This parameter transformation reduces redundancy and groups related rogue events under single normalized identifiers, making analysis more manageable.
2Loss of information
If all individual BSSIDs are displayed without normalization, then complete threat information is provided, but the large number of rogue events makes analysis unwieldy and time-consuming
Solution Approach 1:
The patent merges multiple individual BSSID threats that originate from the same physical rogue AP into a single normalized threat entry. This combining process preserves complete threat information by maintaining associations between normalized identifiers and their underlying BSSIDs, while significantly reducing the time required to analyze rogue events.
Solution Approach 2:
The system creates normalized copies of rogue AP identifiers that represent multiple BSSIDs from the same physical device. These normalized copies serve as consolidated viewpoints that reduce analysis time while maintaining links to the original detailed threat data for complete information retrieval when needed.
3Productivity
If vendor-specific translation algorithms are implemented to correlate BSSIDs to physical APs, then threat correlation speed increases, but the difficulty of implementing and maintaining the system increases
Solution Approach 1:
The patent implements preliminary normalization of BSSID data before the threat correlation process begins. By pre-processing BSSIDs through vendor-specific translation algorithms and creating normalized identifiers in advance, the system accelerates subsequent threat correlation operations while managing implementation complexity through standardized preprocessing routines.
Data Source
AI summary
A device receives data indicative of a plurality of broadcast service set identifiers. The device applies a schema to the data indicative of the plurality of broadcast service set identifiers to determine data indicative of a physical access point that broadcasts each of the plurality of broadcast service set identifiers. The device provides the data indicative of the physical access point to a user interface.


