Method and system for detecting characteristics of a wireless network
First Claim
1. A method, performed by one or more components of a node, the method comprising:
- observing, by the one or more components, a channel in a wireless network for a predetermined amount of time;
parsing, by the one or more components, a plurality of packets transmitted on the channel;
identifying, by the one or more components, protocol information in each of the plurality of parsed packets;
comparing, by the one or more components, the identified protocol information to known patterns associated with an ad hoc network; and
determining, by the one or more components and based on a result of the comparing, that the ad hoc wireless network exists.
7 Assignments
0 Petitions
Accused Products
Abstract
Characteristics about one or more wireless access devices in a wireless network, whether known or unknown entities, can be determined using a system and method according to the present invention. An observation is made of the activity over a Wireless Area Network (WLAN). Based on this activity, changes in state of wireless access devices within the WLAN can be observed and monitored. These changes in state could be indicative of normal operation of the WLAN, or they may indicate the presence of an unauthorized user. In the latter case, an alert can be sent so that appropriate action may be taken. Additionally, ad hoc networks can be detected that may be connected to a wireless access point.
66 Citations
17 Claims
-
1. A method, performed by one or more components of a node, the method comprising:
-
observing, by the one or more components, a channel in a wireless network for a predetermined amount of time; parsing, by the one or more components, a plurality of packets transmitted on the channel; identifying, by the one or more components, protocol information in each of the plurality of parsed packets; comparing, by the one or more components, the identified protocol information to known patterns associated with an ad hoc network; and determining, by the one or more components and based on a result of the comparing, that the ad hoc wireless network exists. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A system, comprising:
a network device configured to; observe a channel in a wireless network for a predetermined amount of time, parse a plurality of packets transmitted on the channel, identify protocol information in each of the plurality of parsed packets, compare the identified protocol information, for a particular one of the plurality of parsed packets, to a plurality of known patterns, where the identified protocol information comprises a Basic Service Set Identifier (BSSID) of a second network device, associated with the particular parsed packet, and determine, based on a result of the comparing, whether the plurality of packets were transmitted over the wireless network or an ad hoc network, where the network device is further configured to determine the particular parsed packet was transmitted over the wireless network, when the BSSID corresponds to a media access control (MAC) address of the second network device, and where the network device is further configured to determine the particular parsed packet was transmitted over the ad hoc network, when the BSSID comprises a number of random bits. - View Dependent Claims (9, 10, 11, 12, 13)
-
14. A method comprising:
-
observing, by each of a plurality of network devices, a channel in a wireless network for a predetermined amount of time; parsing, by each of the plurality of network devices, a plurality of observed packets transmitted on the channel; identifying, by each of the plurality of network devices, protocol information associated with each of the plurality of parsed packets; comparing, by each of the plurality of network devices, the identified protocol information, for a particular one of the plurality of parsed packets, to a plurality of known patterns, where the identified protocol information comprises a Basic Service Set Identifier (BSSID) of a first network device, where the first network device does not comprise one of the plurality of network devices, and the first network device is associated with the particular one of the plurality of parsed packets; and determining, by each of the plurality of network devices and based on a result of the comparing, whether the particular one of the plurality of parsed packets was transmitted over a wireless network or an ad hoc network, where the particular one of the plurality of parsed packets was transmitted over the wireless network, when the BSSID corresponds to a media access control (MAC) address of the first network device, and where the particular one of the plurality of parsed packets was transmitted over the ad hoc network, when the BSSID comprises a number of random bits. - View Dependent Claims (15, 16, 17)
-
Specification