Wireless Network Intrusion Detection and Rogue Device Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless computer networks face challenges in securing access due to the difficulty in controlling unauthorized access points and client stations, which can lead to denial-of-service attacks and data breaches, as traditional access control methods are insufficient in preventing over-the-air intrusions.
Innovation Solution
A system comprising network switches and a network manager that detects and prevents unauthorized devices by monitoring wireless channels, using techniques such as beacon frame monitoring, probe requests, and MAC address verification, and physically locating rogue devices to disconnect and isolate them from the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional access control methods are used in wireless networks, then physical access to connection points can be limited, but unauthorized access points and client stations can still be deployed over-the-air
Solution Approach 1:
The patent introduces a network manager as an intermediary component that coordinates between multiple network switches to detect and respond to rogue devices. The network manager receives information from switches about unauthorized access points and client stations, processes this information centrally, and coordinates the disconnection process across the network, thereby resolving the limitation of individual switches unable to detect over-the-air intrusions alone.
Solution Approach 2:
The patent makes network switches multi-functional by enabling them to perform both traditional data forwarding and rogue device detection functions. The switches monitor wireless channels for beacon frames from unauthorized access points and probe requests from unauthorized client stations, in addition to their standard networking functions, thereby addressing the security issue without adding separate dedicated detection hardware.
2Difficulty of detecting and measuring
If network switches monitor wireless channels for rogue devices, then detection capability is improved, but system complexity increases
Solution Approach 1:
The patent segments the detection and response functions between network switches and a central network manager. The switches are responsible for monitoring wireless channels and detecting rogue devices locally, while the network manager handles the coordination of disconnection actions. This segmentation allows switches to maintain relatively simple functionality while achieving comprehensive network-wide detection through their coordinated operation.
Solution Approach 2:
The patent implements preliminary action by having network switches continuously monitor wireless channels for rogue devices before these devices can cause significant harm. The switches proactively detect unauthorized access points through beacon frame monitoring and unauthorized client stations through probe request monitoring, enabling early intervention and prevention of potential security incidents.
3Reliability
If unauthorized devices are automatically disconnected from the network, then security is improved, but loss of time occurs during detection and disconnection
Solution Approach 1:
The patent applies preliminary action by continuously monitoring wireless channels for rogue devices before they can establish harmful connections or cause denial-of-service attacks. The network switches are already in position to detect unauthorized access points and client stations, enabling rapid response that minimizes the time window for potential damage.
Solution Approach 2:
The patent implements feedback mechanisms where network switches continuously report detected rogue devices to the network manager, which then coordinates immediate disconnection actions. This feedback loop enables the system to rapidly respond to security threats by automatically disconnecting unauthorized devices once detected, minimizing the time they can operate on the network.
Data Source
AI summary
A wireless computer network includes components cooperating together to prevent access intrusions by detecting unauthorized devices connected to the network, disabling the network connections to the devices, and then physically locating the devices. The network can detect both unauthorized client stations and unauthorized edge devices such as wireless access points (APs). The network can detect intruders by monitoring information transferred over wireless channels, identifying protocol state machine violations, tracking roaming behavior of clients, and detecting network addresses being improperly used in multiple locations. Upon detecting an intruder, the network can automatically locate and shut off the physical/logical port to which the intruder is connected.


