SaaS Wireless Vulnerability Management Using Sniffer Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional wireless networking technologies, such as WiFi, face security vulnerabilities due to the inability to contain radio waves within physical boundaries, allowing unauthorized access to local area networks, leading to potential data breaches and compliance issues.

Innovation Solution

A Software-as-a-Service (SaaS) based system for wireless vulnerability management, which deploys sniffers to monitor and report wireless activity, processed by a security server to identify and mitigate vulnerabilities, providing customizable and cost-effective security measures for local area networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless communication technologies are deployed to provide wireless extension to LAN, then ease of operation and accessibility are improved, but security vulnerability increases due to inability to contain radio waves within physical boundaries

Engineering Contradiction:
Improvewireless connectivityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary system consisting of sniffers deployed at customer premises and a centralized server that mediates between the wireless network and security monitoring. The sniffers capture wireless traffic locally, and the server analyzes this captured data to identify unauthorized access attempts, thereby providing security without interfering with the wireless connectivity functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces physical security mechanisms (such as controlling access to physical connection ports) with electronic/software-based monitoring. Instead of relying on physical containment of network access, the system uses software sniffers to capture and analyze wireless traffic, substituting mechanical/physical security controls with electronic detection and analysis capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If conventional security measures such as authentication handshake and encryption are implemented, then security is improved, but device complexity and operational overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service security monitoring where the sniffers automatically capture wireless traffic and the centralized server automatically analyzes the captured data for security threats. This automated self-service approach eliminates the need for manual security configuration and monitoring, reducing operational overhead while maintaining security effectiveness.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent merges multiple security functions into a single centralized server that handles authentication, encryption verification, and unauthorized access detection. By combining these previously separate security mechanisms into one integrated system, the patent reduces overall device complexity and simplifies security configuration while maintaining comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of manufacture

If wireless vulnerability management is provided as hosted service, then cost is reduced through subscription model, but service reliability may be affected by dependency on external provider

Engineering Contradiction:
Improvedeployment costVSAvoidservice continuity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent segments the vulnerability management system into distributed sniffers deployed at each customer premises and a centralized hosted server. This segmentation allows the security monitoring function to be distributed across multiple locations while still leveraging centralized analysis capabilities, thereby maintaining service reliability even when using an external hosted provider through the SaaS model.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8032939B2Method and system for providing wireless vulnerability management for local area computer networks
Publication Date: 2011.10.04 ARISTA NETWORKS INC
  • US8032939B2 patent drawing
  • US8032939B2 patent drawing
  • US8032939B2 patent drawing

AI summary

A Software-as-a-Service (SaaS) based method for providing wireless vulnerability management for local area computer networks. The method includes providing a security server being hosted by a service provider entity to provide analysis of data associated with wireless vulnerability management for a plurality of local area computer networks of a plurality of customer entities, respectively. The method includes creating a workspace for wireless vulnerability management for a customer entity on the security server and receiving configuration information associated with the workspace. The method also includes supplying one or more sniffers to the customer entity. The method includes receiving at the security server information associated with wireless activity monitored by the one or more sniffers at premises of the customer entity and processing the received information within the workspace for the customer entity using the security server. The method includes metering usage of the workspace for wireless vulnerability management for the customer entity.