Wireless Blacklisting via Traffic Rule Violation Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for identifying and preventing unauthorized wireless clients from misusing network resources are not effective in detecting and disrupting communications in response to traffic rule violations.

Innovation Solution

A system and method that includes a traffic violation detection module to identify rule violations in packets and blacklist clients, disassociating them from access points, and sharing blacklisted information to prevent reassociation, using circuitry and logic to manage wireless communications and enforce traffic rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current blacklisting techniques are used to block clients by MAC address, then network access control is implemented, but the effectiveness in identifying and preventing unauthorized clients is insufficient

Engineering Contradiction:
Improveeffectiveness of blacklistingVSAvoidblacklisting mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the blacklisting parameter from static MAC address blocking to dynamic traffic rule violation-based blacklisting. The system monitors packet traffic attributes (source/destination addresses, ports, protocols) and dynamically identifies clients violating traffic rules, making the blacklisting more effective and adaptable to actual network misuse patterns rather than relying on predetermined MAC addresses.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements feedback by continuously monitoring packet traffic and comparing it against defined traffic rules. When violations are detected, the system provides feedback by blacklisting the offending client and can share this information with other access points, creating a closed-loop security mechanism that adapts to real-time network conditions and misuse patterns.

Inventive Principle:
Principle #23Feedback

2Reliability

If traffic rule violations are monitored and clients are blacklisted, then network security is improved, but communication disruption increases

Engineering Contradiction:
Improvenetwork securityVSAvoidcommunication disruption
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent converts the harmful effect of communication disruption into a beneficial security measure. By disrupting communications with clients that violate traffic rules, the system protects the network from unauthorized access and misuse. The disruption is not arbitrary but is precisely targeted at clients exhibiting malicious traffic patterns, thereby converting what appears to be harmful disruption into effective security enforcement.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The system applies local quality by tailoring the blacklisting action to specific clients based on their individual traffic violation patterns. Rather than disrupting all communications uniformly, the system identifies and disrupts only those communications from clients that have violated traffic rules, while maintaining normal operations for compliant clients. This localized approach minimizes unnecessary disruption while maximizing security effectiveness.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9125130B2Blacklisting based on a traffic rule violation
Publication Date: 2015.09.01 ARUBA WIRELESS NETWORKS INC
  • US9125130B2 patent drawing
  • US9125130B2 patent drawing
  • US9125130B2 patent drawing

AI summary

In some embodiments, a network system includes an access point to wirelessly associate with a client that provides signals with traffic specification attributes to the access point. The system also includes circuitry detect if at least one of the signals violates a traffic rule through considering at least one of the traffic specification attributes and to instruct the access point to disassociate the client in response to a particular number of violations. Other embodiments are described.