IP Library Granted Patent US 7,676,218
Granted Patent B2
US 7,676,218 · App. 11/416,761 · Granted Mar 9, 2010

System and method for detection of a rouge wireless access point in a wireless communication network

Assignee: Symbol Technologies, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,676,218
App. No.
11/416,761
Granted
Mar 9, 2010
Kind
B2
Abstract

Described are a system and method for detecting an unauthorized access point accessing a communication network. An authorized access point and/or an authorized mobile unit detects a beacon generated by a transmitting access point. The beacon includes identification information of the transmitting access point. A computing arrangement verifies the identification information of the transmitting access point with a preexisting database of the communication network. The preexisting database includes data corresponding to identification information of a plurality of authorized access points. The computing arrangement initiates a tracking procedure to determine a location of the unauthorized access point where the verification of the transmitting access point identification information with the preexisting database fails.

Claims (33)

1. A device, comprising:

a communications arrangement providing at least one mobile unit with access to a communication network, wherein the communication arrangement scans a plurality of radio frequency channels to detect a beacon transmitted by an unverified access point in the communications network, the beacon including identification information of the unverified access point; and

a processor verifying the identification information with a preexisting database, the verifying comprising comparing a portion of a MAC (medium access controller) address representing a manufacturer identification included in the beacon to manufacturer identification information stored in the preexisting database and comparing a SSID (service set identification) included in the beacon to SSID information stored in the preexisting database, the preexisting database including identification information of a plurality of access points authorized to access the communications network, wherein when the verification of the identification information fails, the processor identifies the unverified access point as an unauthorized access point and sets conditions for which the unauthorized access point is allowed to access the communication network.

2. The device according to claim 1 , wherein, when the verification fails, the processor initiates a tracking procedure to determine a location of the unauthorized access point.

3. The device according to claim 1 , wherein the device is an authorized access point.

4. The device according to claim 1 , wherein the identification information includes at least one of (i) a serial number of the corresponding unverified access point and (ii) a virtual private network identifier.

5. The device according to claim 1 , wherein the processor notifies a network administrator when the verification fails.

6. The device according to claim 1 , wherein the processor generates an activity record of activities of the unauthorized access point.

7. The device according to claim 6 , wherein the activity record includes at least one of a manufacturer serial number, a virtual private network number, a time and date of the unauthorized access, a signal strength of the beacon, a time and date of subsequent communications with the unauthorized access point, a source and a destination of each of the subsequent communications and a signal strength of each of the subsequent communications.

8. The device according to claim 7 , wherein the processor determines the location of the unauthorized access point as a function of the activity record and geographic locations of the device and at least two access points of the plurality of access points.

9. A system, comprising:

a communications arrangement providing at least one mobile unit with access to a communication network, wherein the communication arrangement communicates with a plurality of access points authorized to communicate on the communications network, wherein the communications arrangement scans a plurality of radio frequency channels to detect a beacon transmitted by an unverified access point in the communications network;

a memory storing identification information of the unverified access point that was received in the beacon from the unverified access point, the memory further storing a preexisting database including identification information of the plurality of authorized access points, the preexisting database storing at least one of a manufacturer identification information and a SSID (service set identification) information; and

a processor performing a verification procedure by comparing a portion of a MAC (medium access controller) address representing a manufacturer identification included in the detected beacon to the stored manufacturer information in the preexisting database and a SSID included in the detected beacon to the stored SSID information in the database, wherein when the verification fails, the processor identifies the unverified access point as an unauthorized access point and sets conditions for which the unauthorized access point is allowed to access the communications network.

10. The system according to claim 9 , wherein, when the verification fails, the processor determines a location of the unauthorized access point.

11. The system according to claim 9 , wherein the identification information includes at least one of a manufacturer serial number of the corresponding unverified access point and a virtual private network identifier.

12. The system according to claim 9 , wherein the processor notifies a network administrator of the detection of the unauthorized access point.

13. The system according to claim 9 , wherein the system receives an activity record of activities of the unauthorized access point from the at least one of the plurality of authorized access points.

14. The system according to claim 13 , wherein the activity record includes at least one of a manufacturer serial number, a virtual private network number, a time and date of the unauthorized access, a signal strength of the beacon, a time and date of subsequent transmissions by with the unauthorized access point, a source and a destination of each of the subsequent transmissions and a signal strength of each of the subsequent transmissions.

15. The system according to claim 14 , wherein a location of the unauthorized access point is determined as a function of the activity record and a geographic location of the at least one of the plurality of access points.

16. A method, comprising:

scanning, by a computing arrangement, a plurality of radio frequency channels in a wireless communications network to detect a beacon from an unverified access point, the beacon including identification information of the access point, the computing arrangement providing at least one mobile unit with access to the communication network;

transmitting the identification information to the computing arrangement for performing a verification procedure, the verification procedure including comparing a portion of a MAC (medium access controller) address representing a manufacturer identification included in the detected beacon to stored manufacturer information in a preexisting database and comparing a SSID (service set identification) included in the detected beacon to stored SSID information in the preexisting database, the preexisting database comprising identification information of a plurality of access points authorized to communicate on the communications network; and

when the unverified access point fails the verification procedure, identifying the unverified access point as an unauthorized access point and generating an activity record of activities of the unauthorized access point.

17. The method according to claim 16 , further comprising:

transmitting the activity record to the computing arrangement.

18. The method according to claim 16 , wherein the activity record includes at least one of a manufacturer serial number, a virtual private network number, a time and date of the unauthorized access, a signal strength of the beacon, a time and date of subsequent transmissions by the unauthorized access point, a source and a destination of each of the subsequent transmissions and a signal strength of each of the subsequent transmissions.

19. The method according to claim 16 , further comprising:

determining a location of the unauthorized access point; and transmitting the location to the computing arrangement.

20. An arrangement, comprising:

a communications means for providing at least one mobile unit with access to a communication network, wherein the communication arrangement detects a beacon transmitted by an unverified access point in the communications network, the beacon including corresponding identification information of the unverified access point; and

a processing means for verifying the identification information with a preexisting database, the preexisting database including identification information for a plurality of access points authorized to access the communications network, wherein when the verification of the identification information fails, the unverified access point is an unauthorized access point, the processing means sets conditions for allowing the unauthorized access point to access the communications network,

wherein the verifying comprises comparing a portion of a MAC (medium access controller) address representing a manufacturer identification included in the detected beacon to authorized manufacturer information in the preexisting database and comparing a SSID (service set identification) included in the detected beacon to authorized SSID information in the preexisting database.

Assignments (11)
RELEASE OF PATENT AND TRADEMARK SECURITY INTEREST AT REEL/FRAME NO. 46050/0546 Recorded Jul 30, 2026
From: BANK OF MONTREAL, AS AGENT
To: EXTREME NETWORKS, INC.
Reel/Frame 076081/0088 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2016
From: SYMBOL TECHNOLOGIES, LLC
To: EXTREME NETWORKS, INC.
Reel/Frame 040579/0410 →
AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2016
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 040521/0762 →
RELEASE OF SECURITY INTEREST Recorded Aug 17, 2015
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 036371/0738 →
CHANGE OF NAME Recorded Jul 8, 2015
From: SYMBOL TECHNOLOGIES, INC.
To: SYMBOL TECHNOLOGIES, LLC
Reel/Frame 036083/0640 →
SECURITY AGREEMENT Recorded Oct 31, 2014
From: ZIH CORP.; LASER BAND, LLC; ZEBRA ENTERPRISE SOLUTIONS CORP.; SYMBOL TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC. AS THE COLLATERAL AGENT
Reel/Frame 034114/0270 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2006
From: BALLAI, PHILIP N.
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 017862/0243 →
Continuity (2)
Continuation 1021229100 · Aug 2, 2002
Related Publication 20060193258A1 · Aug 31, 2006