Rogue AP BSSID Normalization for Physical Access Point Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of rogue access points and events in network environments, particularly with the adoption of 5G mobile networks and Wi-Fi 6, makes rogue AP analysis unwieldy due to a large number of displayed threats, complicating the correlation and grouping of rogue broadcast service set identifiers (BSSIDs) from the same physical AP.

Innovation Solution

Implementing a normalization process using vendor-specific translation algorithms to determine a common normalized BSSID for a plurality of BSSIDs, allowing for a more user-friendly and efficient analysis by displaying rogue events associated with a single physical AP, reducing the number of displayed threats and enhancing threat correlation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If vendor-specific translation algorithms are applied to normalize BSSIDs, then the number of displayed rogue APs is reduced and analysis becomes more manageable, but the complexity of the system increases due to the need to implement and maintain multiple vendor-specific algorithms

Engineering Contradiction:
Improverogue AP analysis manageabilityVSAvoidnormalization process complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a normalization process as an intermediary layer between raw BSSID data and the rogue AP analysis interface. This intermediary translates multiple vendor-specific BSSID formats into a unified representation, reducing the number of displayed threats while managing complexity through standardized processing logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameter representation of BSSIDs by applying vendor-specific translation algorithms that convert raw BSSID identifiers into normalized forms. This parameter transformation reduces redundancy and groups related rogue events under single normalized identifiers, making analysis more manageable.

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If all individual BSSIDs are displayed without normalization, then complete threat information is provided, but the large number of rogue events makes analysis unwieldy and time-consuming

Engineering Contradiction:
Improvethreat information completenessVSAvoidrogue AP analysis time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent merges multiple individual BSSID threats that originate from the same physical rogue AP into a single normalized threat entry. This combining process preserves complete threat information by maintaining associations between normalized identifiers and their underlying BSSIDs, while significantly reducing the time required to analyze rogue events.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system creates normalized copies of rogue AP identifiers that represent multiple BSSIDs from the same physical device. These normalized copies serve as consolidated viewpoints that reduce analysis time while maintaining links to the original detailed threat data for complete information retrieval when needed.

Inventive Principle:
Principle #26Copying

3Productivity

If vendor-specific translation algorithms are implemented to correlate BSSIDs to physical APs, then threat correlation speed increases, but the difficulty of implementing and maintaining the system increases

Engineering Contradiction:
Improvethreat correlation speedVSAvoidsystem implementation complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements preliminary normalization of BSSID data before the threat correlation process begins. By pre-processing BSSIDs through vendor-specific translation algorithms and creating normalized identifiers in advance, the system accelerates subsequent threat correlation operations while managing implementation complexity through standardized preprocessing routines.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11765589B2Aggregation and correlation of rogue broadcast service set identifiers to a physical access point
Publication Date: 2023.09.19 CISCO TECHNOLOGY INC
  • US11765589B2 patent drawing
  • US11765589B2 patent drawing
  • US11765589B2 patent drawing

AI summary

A device receives data indicative of a plurality of broadcast service set identifiers. The device applies a schema to the data indicative of the plurality of broadcast service set identifiers to determine data indicative of a physical access point that broadcasts each of the plurality of broadcast service set identifiers. The device provides the data indicative of the physical access point to a user interface.