Wireless Network Sensor Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity solutions are inadequate in detecting and mitigating vulnerabilities in wireless networks, particularly those that are unmonitored or connected to internal networks, due to their limited ability to scan wireless activity within protected environments.

Innovation Solution

A method and system utilizing network sensors deployed in wireless environments to collect and analyze traffic data, detect potential vulnerabilities, and enforce security policies by identifying and mitigating threats, including disconnecting vulnerable connections, blocking devices, and alerting security systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security solutions scan wireless activity in protected networks, then known vulnerabilities can be detected, but unmonitored wireless networks and coexisting wireless environments cannot be detected

Engineering Contradiction:
Improvedetection capabilityVSAvoidcoverage scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments wireless detection into two distinct components: an internal scanner for protected networks and a wireless sensor for coexisting wireless environments. This segmentation allows each component to specialize in its domain while collectively providing comprehensive coverage, resolving the contradiction between reliable detection of known vulnerabilities and versatile coverage of unmonitored networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The wireless sensor acts as an intermediary device deployed in the coexisting wireless environment that bridges the gap between protected internal networks and external wireless spaces. It collects data from unmonitored networks and relays information to the security system, enabling detection capabilities to extend into previously inaccessible wireless domains without compromising internal network security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security systems monitor all wireless connections, then threats can be detected, but legitimate device activity may be restricted

Engineering Contradiction:
Improvethreat detectionVSAvoiddevice connectivity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies different monitoring qualities to different wireless entities: suspicious entities detected by the wireless sensor undergo rigorous analysis and potential blocking, while legitimate internal network traffic monitored by the scanner receives standard security processing. This localized differentiation of monitoring intensity allows comprehensive threat detection while preserving normal device operations and connectivity.

Inventive Principle:
Principle #3Local quality

3Reliability

If multiple security products are deployed, then various threats can be addressed, but the system complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the internal wireless scanner with the external wireless sensor into a unified security system architecture. Rather than deploying separate complex systems for internal and external wireless monitoring, the combined system shares common infrastructure, data processing capabilities, and response mechanisms, thereby achieving comprehensive security coverage while reducing overall system complexity and resource requirements.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3422665B1Sensor-based wireless network vulnerability detection
Publication Date: 2021.11.10 ARMIS SECURITY LTD
  • EP3422665B1 patent drawingFigure 1
  • EP3422665B1 patent drawingFigure 2
  • EP3422665B1 patent drawingFigure 3

AI summary

Certain embodiments disclosed herein include a method for detecting potential vulnerabilities in a wireless environment. The method comprises collecting, by a network sensor deployed in the wireless environment, at least wireless traffic data; analyzing the collected wireless traffic data to detect at least activity initiated by a wireless entity in the wireless environment; sending, to a control system, data indicating the detected wireless entity; and enforcing a security policy on the detected wireless entity based on instructions received from the control system.