IP Library › Granted Patent US 7,426,383
Granted Patent B2
US 7,426,383 · App. 10/744,026 · Granted Sep 16, 2008

Wireless LAN intrusion detection based on location

Assignee: Symbol Technologies, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,426,383
App. No.
10/744,026
Granted
Sep 16, 2008
Kind
B2
Abstract

A intrusion detection method is disclosed for use in a wireless local area data communications system, wherein mobile units communicate with access points, and wherein the system is arranged to locate transmitters using signals transmitted by the transmitters. A database relating authorized transmitters to location is maintained. Selected signals are detected at the access points and location data corresponding to the selected signals for use in locating a source of the signals is recorded. The source location is determined using the location data, and the source location is compared to a corresponding location in the database. An alarm is signaled if the source location is inconsistent with the corresponding database location.

Claims (52)

1. In a wireless local area data communications system, wherein mobile units communicate with access points, and wherein said system is arranged to locate transmitters using signals transmitted by said transmitters, a method for detecting unauthorized signals, comprising:

maintaining a database relating authorized transmitters to location;

detecting selected signals at said access points and recording location data corresponding to said signals for use in locating a source of said signals;

locating said source using said location data;

comparing said source location to a corresponding location in said database; and

signaling an alarm if said source location is inconsistent with said corresponding database location.

2. A method as specified in claim 1 wherein said selected signal is a signal transmitted by a mobile unit and wherein said source location is compared to a location for said mobile unit in said database.

3. A method as specified in claim 2 wherein said selected signal is an association request signal.

4. A method as specified in claim 2 wherein said signal is an Extensible Authentication Protocol over LAN (“EAPoL”) signal.

5. A method as specified in claim 1 , wherein additional locating devices are used to detect said selected signals to improve the accuracy of the locating of said source.

6. A method as specified in claim 1 wherein said selected signal is a signal type transmitted by an access point, and wherein said source location is compared to a location for said access point.

7. A method as specified in claim 6 wherein said selected signal is a management/control signal.

8. A method as specified in claim 6 wherein said signal is a beacon signal.

9. A method as specified in claim 6 wherein said signal is a de-authorization or de-authentication signal.

10. A method as specified in claim 6 wherein said signal is a disassociation signal.

11. A method as specified in claim 6 wherein said signal is an Extensible Authentication Protocol over LAN (“EAPoL”) signal.

12. In a wireless local area data communications system, wherein mobile units communicate with access points, and wherein said system is arranged to locate transmitters using signals transmitted by said transmitters, a method for detecting unauthorized signals, comprising:

maintaining a database relating authorized transmitters to location, said database further comprising MAC information;

detecting selected signals at said access points and recording location data corresponding to said signals for use in locating a source of said signals;

locating said source using said location data;

comparing said source location to a corresponding location in said database;

extracting a MAC address from said source location;

comparing said MAC address with MAC information in said database; and

signaling an alarm if analysis of said source location and said MAC address suggest possible unauthorized network access.

13. A method as specified in claim 12 wherein said analysis indicates that said MAC address is inconsistent with MAC information relating to substantially the same location.

14. A method as specified in claim 12 wherein said analysis indicates that said MAC address is located at more than one location.

15. In a wireless local area data communications system, wherein mobile units communicate with access points, and wherein said system is arranged to locate transmitters using signals transmitted by said transmitters, a method for detecting unauthorized signals, comprising:

maintaining a database relating to allowed locations;

detecting selected signals at said access points and recording location data corresponding to said signals for use in locating a source of said signals;

locating said source using said location data;

comparing said source location to the allowed locations in said database; and

signaling an alarm if said source location is not within said allowed locations.

16. A method as specified in claim 15 , wherein said allowed locations correspond to locations which are authorized locations for mobile units.

17. A method as specified in claim 15 , wherein said allowed locations correspond to locations which are physically feasible locations for mobile units.

18. A method as specified in claim 15 , wherein said allowed locations correspond to locations which are unobstructed by structures.

19. A method as specified in claim 15 , wherein additional locating devices are used to detect said selected signals to improve the accuracy of the locating of said source.

20. In a wireless local area data communications system, wherein mobile units communicate with a first and second access points, and wherein said system is arranged to locate transmitters using signals transmitted by said transmitters, and further wherein said first and second access points are located substantially within proximity such that under normal conditions they detect signals transmitted by same said transmitters, a method for detecting unauthorized signals, comprising:

detecting selected signals at said first access point and recording location data corresponding to said signals for use in locating a source of said signals; and

signaling an alarm if said signals are not detected at said second access point.

21. In a wireless local area data communications system, wherein mobile units communicate with access points, and wherein said system is arranged to locate transmitters using signals transmitted by said transmitters, a method for detecting unauthorized signals, comprising:

maintaining a database comprising network data traffic information;

detecting selected signals at said access points and recording location data corresponding to said signals for use in locating a source of said signals;

locating said source using said location data;

monitoring said selected signals to determine network data traffic characteristics at said source location;

comparing said determined network data traffic characteristics to information in said database; and

signaling an alarm if said determined network data traffic characteristics at said source location is inconsistent with information in said database.

22. In a wireless local area data communications system, wherein mobile units communicate with access points, and wherein said system is arranged to locate transmitters using signals transmitted by said transmitters, a method for detecting unauthorized signals, comprising:

maintaining a database relating authorized transmitters to location;

detecting selected signals by one or more mobile units and recording location data corresponding to said signals for use in locating a source of said signals;

locating said source using. said location data;

comparing said source location to a corresponding location in said database; and

signaling an alarm if said source location is inconsistent with said corresponding database location.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 17, 2015
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 036371/0738 →
CHANGE OF NAME Recorded Jul 8, 2015
From: SYMBOL TECHNOLOGIES, INC.
To: SYMBOL TECHNOLOGIES, LLC
Reel/Frame 036083/0640 →
SECURITY AGREEMENT Recorded Oct 31, 2014
From: ZIH CORP.; LASER BAND, LLC; ZEBRA ENTERPRISE SOLUTIONS CORP.; SYMBOL TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC. AS THE COLLATERAL AGENT
Reel/Frame 034114/0270 →
REQUEST TO CORRECT DOC DATES ORIGINALLY RECORDED AT 015095/0656 ON DEC. 20, 2004 Recorded Oct 14, 2005
From: WANG, HUAYAN AMY; COREN, DAVE; SHARONY, JACOB; WILLINS, BRUCE
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 016882/0854 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2004
From: WANG, HUAYAN AMY; GOREN, DAVE; SHARONY, JACOB; WILLINS, BRUCE
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 016095/0656 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2004
From: WANG, HUAYAN AMY; COREN, DAVE; SHARONY, JACOB; WI, BRUCE
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 015327/0634 →
Continuity (1)
Related Publication 20050136891A1 · Jun 23, 2005