Method and system for detecting characteristics of a wireless network
First Claim
1. A method comprising:
- detecting a wireless access device in an area;
creating a state transition table for said detected wireless access device;
observing a plurality of packets transmitted by said detected wireless access device;
determining, based on said plurality of packets, whether a state change has occurred for said detected wireless access device;
identifying said state change in said state transition table; and
checking for security violations as a result of said state change.
9 Assignments
0 Petitions
Accused Products
Abstract
Characteristics about one or more wireless access devices in a wireless network, whether known or unknown entities, can be determined using a system and method according to the present invention. An observation is made of the activity over a Wireless Area Network (WLAN). Based on this activity, changes in state of wireless access devices within the WLAN can be observed and monitored. These changes in state could be indicative of normal operation of the WLAN, or they may indicate the presence of an unauthorized user. In the latter case, an alert can be sent so that appropriate action may be taken. Additionally, ad hoc networks can be detected that may be connected to a wireless access point.
166 Citations
22 Claims
-
1. A method comprising:
-
detecting a wireless access device in an area;
creating a state transition table for said detected wireless access device;
observing a plurality of packets transmitted by said detected wireless access device;
determining, based on said plurality of packets, whether a state change has occurred for said detected wireless access device;
identifying said state change in said state transition table; and
checking for security violations as a result of said state change. - View Dependent Claims (2, 3, 4, 5, 6)
-
-
7. A method of determining whether an ad hoc wireless network exists comprising:
-
observing a channel in a wireless network for a predetermined amount of time;
parsing all packets transmitted on said channel;
examining protocol information in each of said packets; and
comparing said protocol information in each of said packets with known patterns associated with an ad hoc network. - View Dependent Claims (8, 9, 10, 11, 12)
-
-
13. A system for detecting state changes in a wireless network, comprising:
-
means for creating a state transition table for a detected wireless access device in a wireless network;
means for observing a plurality of packets transmitted by said detected wireless access device;
means for determining, based on said plurality of packets, whether a state change has occurred for said detected wireless access device;
means for identifying said state change in said state transition table; and
means for checking for security violations as a result of said state change.
-
-
14. A system for detecting an ad hoc network, comprising:
-
means for observing a channel in a wireless network for a predetermined amount of time;
means for parsing all packets transmitted on said channel;
means for examining protocol information in each of said packets; and
means for comparing said protocol information in each of said packets with known patterns;
wherein a determination can be made, based on the protocol information from said packets, whether said packets were transmitted over said wireless network or an ad hoc network.
-
-
15. A computer readable medium containing computer program instructions for:
-
creating a state transition table for a detected wireless access device in a wireless network;
observing a plurality of packets transmitted by said detected wireless access device;
determining, based on said plurality of packets, whether a state change has occurred for said detected wireless access device;
identifying said state change in said state transition table; and
checking for security violations as a result of said state change.
-
-
16. A computer readable medium containing computer program instructions for:
-
observing a channel in a wireless network for a predetermined amount of time;
parsing all packets transmitted on said channel;
examining protocol information in each of said packets; and
comparing said protocol information in each of said packets with known patterns associated with an ad hoc network.
-
-
17. A wireless intrusion detection system node, comprising:
-
means for creating a state transition table for one or more detected wireless access devices in a wireless network;
means for observing a plurality of packets sent by each of said one or more detected wireless access devices;
means for determining, based on said plurality of packets, whether a state change has occurred for any of said one or more detected wireless access devices; and
means for reporting any of said state changes to a wireless intrusion detection system collector.
-
-
18. A wireless intrusion detection system collector, comprising:
-
means for receiving state changes from one or more wireless intrusion detection system nodes; and
means for determining activity within a wireless network based on said state changes. - View Dependent Claims (19, 20, 21, 22)
-
Specification