Wireless Link Layer Traffic Analysis for Vulnerable Device Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity solutions are inadequate in detecting vulnerable wireless devices and networks within an organization's environment, particularly in unmonitored wireless networks, and struggle with profiling devices due to the lack of industry standards and frequent software updates, leading to potential malware transmission and data leaks.

Innovation Solution

A system and method that involves deploying sensors to monitor and analyze wireless traffic across various protocols, computing risk scores based on vulnerability analysis, and generating alerts for vulnerable devices, with the capability to mitigate threats by terminating connections and profiling devices to distinguish between legitimate and unknown devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security solutions operate at network layer or application layer to detect anomalies, then they can detect known vulnerabilities and threats, but they are completely agnostic to interconnectivity through wireless communications and cannot detect vulnerable devices in unmonitored wireless networks

Engineering Contradiction:
Improvedetection capabilityVSAvoidcoverage of wireless networks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a new detection dimension by operating at the wireless link layer (layer 2) in addition to traditional network layer (layer 4) and application layer (layer 7) monitoring. This dimensional expansion enables the system to detect vulnerable devices in unmonitored wireless networks by capturing wireless traffic at the link layer, thereby resolving the contradiction between detection reliability and network coverage adaptability

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If security solutions monitor all wireless activity in the protected organization, then they can detect threats, but they cannot detect sniffers that trap documents sent to wireless printers or legitimate devices transmitting sensitive information to vulnerable devices

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by implementing device-specific profiling that creates customized security profiles for different device types (printers, smartphones, laptops, etc.). Each profile contains device-specific attributes and expected behavior patterns, enabling the system to detect anomalies locally at each device level rather than applying uniform monitoring rules, thus improving detection accuracy while managing system complexity

Inventive Principle:
Principle #3Local quality

3Reliability

If the system profiles wireless devices to distinguish legitimate from unknown devices, then it can improve security, but it faces challenges due to lack of industry standards and frequent software updates making profiling inefficient

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidprofiling efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-defining profiles for known device types with expected attributes and behavior patterns before devices connect to the network. When a device is detected, the system matches it against pre-existing profiles rather than creating profiles from scratch, significantly improving profiling efficiency despite frequent software updates and lack of industry standards

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11102233B2Detection of vulnerable devices in wireless networks
Publication Date: 2021.08.24 ARMIS SECURITY LTD
  • US11102233B2 patent drawing
  • US11102233B2 patent drawing
  • US11102233B2 patent drawing

AI summary

A method and system for detecting vulnerable wireless devices operating in a wireless environment of an organization are provided. The method includes identifying a plurality of wireless devices operable in the wireless environment; for each identified wireless device: receiving intercepted traffic transmitted by the wireless device, wherein the intercepted traffic is transported using at least one type of wireless protocol; analyzing the intercepted traffic to determine if the wireless device is vulnerable, wherein the analysis is performed using an at least one investigation action; computing a risk score based on results of each of the least one investigation action; determining, based on the computed risk scores, if the wireless device is as vulnerable; and generating an alert, when it is determined that the wireless device is vulnerable.