Method and system for detecting characteristics of a wireless network
First Claim
Patent Images
1. A network device comprising:
- a processing device in communication with a memory, the processing device configured to execute instructions received from the memory to;
create a state transition table for one or more detected wireless access devices in a wireless network, the state transition table including;
a first entry that includes information identifying a first state of a communication session, via the wireless network, between the one or more detected wireless access devices and at least one device,the first state being associated with one or more respective identifiers of the one or more detected wireless access devices and a type of at least one packet identifying the one or more detected wireless access devices,observe a plurality of packets transmitted by the one or more detected wireless access devices,identify, based on observing the plurality of packets, a state change from the first state for at least one of the one or more detected wireless access devices in response to determining that types of the plurality of packets differ from the type of the at least one packet or in response to determining that the plurality of packets are associated with a source or a destination other than the at least one device, andreport the identified state change to another network device.
7 Assignments
0 Petitions
Accused Products
Abstract
Characteristics about one or more wireless access devices in a wireless network, whether known or unknown entities, can be determined using a system and method according to the present invention. An observation is made of the activity over a Wireless Area Network (WLAN). Based on this activity, changes in state of wireless access devices within the WLAN can be observed and monitored. These changes in state could be indicative of normal operation of the WLAN, or they may indicate the presence of an unauthorized user. In the latter case, an alert can be sent so that appropriate action may be taken. Additionally, ad hoc networks can be detected that may be connected to a wireless access point.
-
Citations
16 Claims
-
1. A network device comprising:
a processing device in communication with a memory, the processing device configured to execute instructions received from the memory to; create a state transition table for one or more detected wireless access devices in a wireless network, the state transition table including; a first entry that includes information identifying a first state of a communication session, via the wireless network, between the one or more detected wireless access devices and at least one device, the first state being associated with one or more respective identifiers of the one or more detected wireless access devices and a type of at least one packet identifying the one or more detected wireless access devices, observe a plurality of packets transmitted by the one or more detected wireless access devices, identify, based on observing the plurality of packets, a state change from the first state for at least one of the one or more detected wireless access devices in response to determining that types of the plurality of packets differ from the type of the at least one packet or in response to determining that the plurality of packets are associated with a source or a destination other than the at least one device, and report the identified state change to another network device. - View Dependent Claims (2, 3, 4, 5, 6)
-
7. A method comprising:
-
creating a state transition table for one or more detected wireless access devices in a wireless network, the state transition table including; a first entry that includes information identifying a first state of a communication session, via the wireless network, between the one or more detected wireless access devices and at least one device, the first state being associated with one or more respective identifiers of the one or more detected wireless access devices and a type of at least one packet identifying the one or more detected wireless access devices, observing a plurality of packets transmitted by the one or more detected wireless access devices, identifying, based on observing the plurality of packets, a state change from the first state for at least one of the one or more detected wireless access devices in response to determining that types of the plurality of packets differ from the type of the at least one packet or in response to determining that the plurality of packets are associated with a source or a destination other than the at least one device, and reporting the identified state change to another network device. - View Dependent Claims (8, 9, 10, 11, 12, 13, 14, 15, 16)
-
Specification