IP Library Granted Patent US 7,778,606
Granted Patent B2
US 7,778,606 · App. 10/147,308 · Granted Aug 17, 2010

Method and system for wireless intrusion detection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,778,606
App. No.
10/147,308
Granted
Aug 17, 2010
Kind
B2
Abstract

A wireless intrusion detection system (WIDS) is disclosed for monitoring both authorized and unauthorized access to a wireless portion of a network. The WIDS consists of a collector and one or more nodes that communicate via an out of band means that is separate from the network. Unauthorized access points and unauthorized clients in the network can be detected. The WIDS can be used to monitor, for example, a network implemented using the 802.11 protocol. In addition, the WIDS can be used by one company to provide a service that monitors the wireless network of another company.

Claims (87)

1. A method comprising:

monitoring, for at least one monitoring cycle, a wireless network of interest for a plurality of signals from one or more wireless access devices;

storing results from the monitoring cycle;

encrypting the results from the monitoring cycle prior to transmitting to a data collector;

transmitting the results of the monitoring cycle to the data collector;

processing the results of the monitoring cycle to determine whether any access of the wireless network of interest has occurred; and

notifying a user of the results of the processing of the monitoring cycle.

2. The method of claim 1 , further comprising:

detecting access points in the wireless network; and

detecting clients in the wireless network.

3. The method of claim 1 , further comprising:

using a separate communications channel for the transmission of the results of the monitoring cycle to the data collector.

4. The method of claim 1 , further comprising:

performing a monitoring cycle utilizing one or more nodes.

5. The method of claim 4 , further comprising:

monitoring the status of the one or more nodes.

6. A method comprising:

monitoring, for at least one monitoring cycle, a wireless network of interest for a plurality of signals from one or more wireless access devices;

storing results from the monitoring cycle;

transmitting the results of the monitoring cycle to a data collector;

processing the results of the monitoring cycle to determine whether any access of the wireless network of interest has occurred;

notifying a user of the results of the processing of the monitoring cycle; and

tracking of authorized and unauthorized access points and clients.

7. The method of claim 6 , further comprising:

locating any unauthorized devices.

8. The method of claim 6 , wherein the transmitting of results further comprises transmitting over a wireless communications medium.

9. The method of claim 8 , wherein the transmitting of results over a wireless communications medium further comprises transmitting a 900 MHz radio transmission.

10. A method comprising:

monitoring, for at least one monitoring cycle, a wireless network of interest for a plurality of signals from one or more wireless access devices;

storing results from the monitoring cycle;

transmitting the results of the monitoring cycle to a data collector;

processing the results of the monitoring cycle to determine whether any access of the wireless network of interest has occurred;

notifying a user of the results of the processing of the monitoring cycle; and

determining the status of any authorized access points.

11. The method of claim 10 , further comprising:

determining whether any authorized access points have changed.

12. The method of claim 10 , further comprising:

determining whether any authorized access points are not operating.

13. The method of claim 10 , wherein the monitoring of signals from one or more wireless access devices further comprises monitoring for clients.

14. A method comprising:

monitoring, for at least one monitoring cycle, a wireless network of interest for a plurality of signals from one or more wireless access devices;

storing results from the monitoring cycle;

transmitting the results of the monitoring cycle to a data collector;

processing the results of the monitoring cycle to determine whether any access of the wireless network of interest has occurred;

notifying a user of the results of the processing of the monitoring cycle; and

identifying any denial of service attempts.

15. The method of claim 14 , further comprising:

tracking of multiple connection attempts to the wireless network by any unauthorized devices.

16. The method of claim 14 , further comprising:

notifying the user of any unauthorized attempts to access the wireless network.

17. The method of claim 14 , wherein the transmitting of results further comprises transmitting to a remotely located data collector.

18. The method of claim 14 , wherein the monitoring of signals from one or more wireless access devices further comprises monitoring for access points.

19. A method comprising:

monitoring, for at least one monitoring cycle, a wireless network of interest for a plurality of signals from one or more wireless access devices;

storing results from the monitoring cycle;

transmitting the results of the monitoring cycle to a data collector;

processing the results of the monitoring cycle to determine whether any access of the wireless network of interest has occurred;

notifying a user of the results of the processing of the monitoring cycle; and

tracking how long any unauthorized device has attempted to access the wireless network.

20. The method of claim 19 , further comprising:

identifying attempts to spoof an authorized access point.

21. The method of claim 19 , further comprising:

notifying the user of any authorized attempts to access the wireless network.

22. A method for controlling a wireless intrusion detection system comprising:

transmitting a plurality of beacon packets from a collector;

receiving one or more of the beacon packets at a node; and

establishing a communications link between the collector and the node for detecting unauthorized access of a wireless network of interest;

wherein the collector controls a wireless intrusion detection system by a communications link that utilizes a different means of communication than the wireless network.

23. A method as in claim 22 , the communications link being a 900 MHz radio channel.

24. A method comprising:

receiving, from a node, results, of a monitoring cycle, of a plurality of signals from one or more wireless access devices in a wireless network of interest;

processing the results of the monitoring cycle to generate at least one indicator indicative of unauthorized access to the wireless network of interest,

where the processing comprises applying adaptive learning techniques to evolve recognition of unauthorized access to the wireless network of interest;

recognizing patterns in the results of the monitoring cycle; and

refining responses to the results of the monitoring cycle based on recognized patterns.

25. A method as in claim 24 , wherein the applying adaptive learning techniques further comprises:

utilizing genetic algorithms.

26. A system for controlling a wireless intrusion detection system comprising:

means for transmitting a plurality of beacon packets from a collector;

means for receiving one or more of the beacon packets at a node; and

means for establishing a communications link between the collector and the node for detecting unauthorized access of a wireless network of interest;

wherein the collector controls a wireless intrusion detection system by a communications link that utilizes a different means of communication than the wireless network.

27. One or more devices that store instructions executable by one or more processors, the instructions comprising:

one or more instructions to transmit a plurality of beacon packets from a collector;

one or more instructions to receive one or more of the beacon packets at a node; and

one or more instructions to establish a communications link between the collector and the node for detecting unauthorized access of a wireless network of interest;

where the collector controls a wireless intrusion detection system by a communications link that utilizes a different means of communication than the wireless network.

Assignments (9)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 8, 2020
From: INTELLECTUAL VENTURES ASSETS 132 LLC
To: OZMO LICENSING LLC
Reel/Frame 051448/0907 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2019
From: OL SECURITY LIMITED LIABILITY COMPANY
To: INTELLECTUAL VENTURES ASSETS 132 LLC
Reel/Frame 050898/0090 →
MERGER Recorded Oct 27, 2015
From: TEKLA PEHR LLC
To: OL SECURITY LIMITED LIABILITY COMPANY
Reel/Frame 036979/0106 →
MERGER Recorded Dec 3, 2012
From: NETWORK SECURITY TECHNOLOGIES, INC.
To: MCI COMMUNICATIONS SERVICES, INC.
Reel/Frame 029390/0955 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2012
From: VERIZON PATENT AND LICENSING INC.
To: TEKLA PEHR LLC
Reel/Frame 029368/0460 →
RELEASE OF SECURITY INTEREST Recorded Oct 24, 2012
From: SILICON VALLEY BANK
To: NETWORK SECURITY TECHNOLOGIES, INC.
Reel/Frame 029181/0475 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2012
From: MCI COMMUNICATIONS SERVICES, INC.
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 028968/0437 →
SECURITY AGREEMENT Recorded Aug 4, 2004
From: NETWORK SECURITY TECHNOLOGIES, INC.
To: SILICON VALLEY BANK
Reel/Frame 015649/0249 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2002
From: AMMON, KEN; O'FERRELL, CHRIS; MITZEN, WAYNE; FRASNELLI, DAN; WIMBLE, LAWRENCE; YANG, YIN; MCHALE, TOM; DOTEN, RICK
To: NETWORK SECURITY TECHNOLOGIES, INC.
Reel/Frame 013206/0146 →