Wireless Blacklisting via Traffic Rule Violation Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current techniques for identifying and preventing unauthorized wireless clients from misusing network resources are not effective in detecting and disrupting communications in response to traffic rule violations.
Innovation Solution
A system and method that includes a traffic violation detection module to identify rule violations in packets and blacklist clients, disassociating them from access points, and sharing blacklisted information to prevent reassociation, using circuitry and logic to manage wireless communications and enforce traffic rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current blacklisting techniques are used to block clients by MAC address, then network access control is implemented, but the effectiveness in identifying and preventing unauthorized clients is insufficient
Solution Approach 1:
The patent changes the blacklisting parameter from static MAC address blocking to dynamic traffic rule violation-based blacklisting. The system monitors packet traffic attributes (source/destination addresses, ports, protocols) and dynamically identifies clients violating traffic rules, making the blacklisting more effective and adaptable to actual network misuse patterns rather than relying on predetermined MAC addresses.
Solution Approach 2:
The system implements feedback by continuously monitoring packet traffic and comparing it against defined traffic rules. When violations are detected, the system provides feedback by blacklisting the offending client and can share this information with other access points, creating a closed-loop security mechanism that adapts to real-time network conditions and misuse patterns.
2Reliability
If traffic rule violations are monitored and clients are blacklisted, then network security is improved, but communication disruption increases
Solution Approach 1:
The patent converts the harmful effect of communication disruption into a beneficial security measure. By disrupting communications with clients that violate traffic rules, the system protects the network from unauthorized access and misuse. The disruption is not arbitrary but is precisely targeted at clients exhibiting malicious traffic patterns, thereby converting what appears to be harmful disruption into effective security enforcement.
Solution Approach 2:
The system applies local quality by tailoring the blacklisting action to specific clients based on their individual traffic violation patterns. Rather than disrupting all communications uniformly, the system identifies and disrupts only those communications from clients that have violated traffic rules, while maintaining normal operations for compliant clients. This localized approach minimizes unnecessary disruption while maximizing security effectiveness.
Data Source
AI summary
In some embodiments, a network system includes an access point to wirelessly associate with a client that provides signals with traffic specification attributes to the access point. The system also includes circuitry detect if at least one of the signals violates a traffic rule through considering at least one of the traffic specification attributes and to instruct the access point to disassociate the client in response to a particular number of violations. Other embodiments are described.


