Rogue Device Detection via Dummy Network Identifiers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing and maintaining effective network security in dynamic and rapidly changing wireless computer network environments is challenging due to the proliferation of devices and varied threats.

Innovation Solution

A system and method for rogue device detection that involves generating dummy network identifiers, advertising them, and monitoring devices that attempt to connect to these identifiers. If the monitored traffic meets an abnormality threshold, the device is identified as a rogue device, and appropriate actions are taken to protect the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security methods are used, then network security is maintained, but the system cannot detect rogue devices in dynamic wireless environments

Engineering Contradiction:
Improvenetwork securityVSAvoiddetection capability in dynamic environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by generating and advertising dummy network identifiers before actual threats materialize. These dummy identifiers act as traps that rogue devices will attempt to connect to, allowing detection before the rogue devices can compromise the real network. This proactive approach enables the system to adapt to dynamic environments by anticipating potential threats.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary mechanism - dummy network identifiers - that mediates between the legitimate network and potential rogue devices. Instead of directly monitoring all network traffic for signs of compromise, the system uses these intermediary dummy identifiers as a detection layer, allowing rogue devices to reveal themselves through their connection attempts without directly exposing the real network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If dummy network identifiers are generated and advertised, then rogue device detection capability is improved, but network complexity increases

Engineering Contradiction:
Improverogue device detectionVSAvoidnetwork structure
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system creates simplified copies of network identifiers (dummy SSIDs) that mirror the structure and appearance of legitimate network identifiers. These copies are easier to generate and manage than comprehensive monitoring systems, as they leverage existing network advertising mechanisms. The dummy identifiers replicate enough characteristics to attract rogue devices while maintaining simplicity in implementation.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The dummy network identifiers serve multiple functions simultaneously: they act as detection traps for rogue devices, do not require separate infrastructure from existing wireless networks, and can be implemented using standard network advertising protocols. This multi-functionality reduces the need for additional complex components while maintaining effective detection capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If connection attempts to dummy identifiers are monitored, then detection accuracy is improved, but false positives may increase

Engineering Contradiction:
Improverogue device identification accuracyVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system applies partial monitoring by focusing detection efforts specifically on connection attempts to dummy identifiers rather than monitoring all network traffic. This selective approach reduces the overall volume of data requiring analysis and minimizes false positives from legitimate network activity. The system performs excessive action in the specific area of dummy identifier connections to ensure thorough detection of rogue devices.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system applies different monitoring intensities to different parts of network traffic. Dummy identifier connections receive intensive monitoring and analysis since these are high-value indicators of rogue devices, while other network traffic receives standard monitoring. This localized quality approach improves detection accuracy for rogue devices while reducing false positives from normal network operations in other areas.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12207092B2System and method for rogue device detection
Publication Date: 2025.01.21 SOPHOS LTD
  • US12207092B2 patent drawing
  • US12207092B2 patent drawing
  • US12207092B2 patent drawing

AI summary

Methods, systems and computer readable media for rogue device detection are described. The method may include automatically generating one or more dummy network identifiers associated with a wireless network, advertising the one or more dummy network identifiers, and identifying a device as a suspect device based on receiving a connection attempt to at least one of the one or more dummy network identifiers by the device. The method can also include allocating a virtual local area network within the wireless network to process traffic associated with the at least one of the one or more dummy network identifiers, and monitoring network traffic of the suspect device on the virtual local area network. The method can further include, if the monitored network traffic meets an abnormality threshold, determining that the suspect device is a rogue device, and performing an action to protect the wireless network from the rogue device.