Unauthorized Wireless Device Detection via Log Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless network security systems face challenges in accurately detecting unauthorized wireless devices, often resulting in false positives due to interference from authorized access points and other networks, which can compromise network security and efficiency.

Innovation Solution

An unauthorized wireless device detection platform that analyzes network connection logs using MAC addresses and predetermined criteria to identify and authorize devices, eliminating the need for physical signal detection and reducing false positives, thereby enhancing security and operational efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If physical signal detection is used to identify unauthorized wireless devices, then detection capability is improved, but false positives increase due to interference from authorized access points and other networks

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces network connection logs as an intermediary data source. Instead of directly detecting wireless signals (which causes false positives), the system uses log data that records device connections to the network. This intermediary approach allows identification of unauthorized devices through their connection patterns and MAC addresses without the interference problems of direct signal detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the physical/mechanical signal detection system with an information processing system. Instead of using wireless monitors to detect radio signals, the system uses software to analyze network connection logs, MAC addresses, and device identifiers. This substitution eliminates the false positives associated with physical signal detection while maintaining detection capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Area of stationary object

If extensive monitoring infrastructure is deployed to detect unauthorized devices, then detection coverage is improved, but system complexity and cost increase

Engineering Contradiction:
Improvemonitoring coverageVSAvoidmonitoring infrastructure
Core Design Contradiction:
Area of stationary objectVSDevice complexity

Solution Approach 1:

The patent enables the network infrastructure to monitor itself. Existing network components (access points, switches, servers) that are already present in the network generate connection logs as part of normal operation. The detection system utilizes these self-generated logs without requiring additional monitoring hardware, making the system self-sufficient and reducing complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent makes existing network infrastructure serve multiple functions. Network access points and switches continue their primary function of providing network access while simultaneously generating connection logs that are used for security monitoring. This multi-functionality eliminates the need for dedicated monitoring infrastructure, reducing system complexity and cost.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If log analysis is used instead of signal detection, then false positives are reduced, but detection speed may be affected

Engineering Contradiction:
Improvefalse positive rateVSAvoiddetection speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent implements preliminary action by continuously collecting and storing network connection logs as devices connect to the network. This log data is prepared in advance and organized for quick retrieval. When security analysis is needed, the pre-collected log data is already available, eliminating the need for real-time signal processing and enabling fast detection without sacrificing accuracy.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9119070B2Method and system for detecting unauthorized wireless devices
Publication Date: 2015.08.25 VERIZON PATENT & LICENSING INC
  • US9119070B2 patent drawing
  • US9119070B2 patent drawing
  • US9119070B2 patent drawing

AI summary

An approach is provided for detecting unauthorized wireless devices in a network. A platform retrieves an identifier of a device from a log of devices connected to a network, determines whether the device is a wireless device by applying a plurality of criteria to the identifier, retrieving a list of wireless devices authorized to connect to the network if the device is determined to be a wireless device, and compares the identifier with the list to determine whether the device is authorized to connect to the network.