IP Library Granted Patent US 8,707,432
Granted Patent B1
US 8,707,432 · App. 11/961,677 · Granted Apr 22, 2014

Method and system for detecting and preventing access intrusion in a network

Inventors: Manish M. Rathi (San Jose, CA); Vipin K. Jain (Santa Clara, CA); Shehzad T. Merchant (Mountain View, CA); Victor C. Lin (Fremont, CA)
Assignee: Extreme Networks, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,707,432
App. No.
11/961,677
Granted
Apr 22, 2014
Kind
B1
Abstract

A wireless computer network includes components cooperating together to prevent access intrusions by detecting unauthorized devices connected to the network, disabling the network connections to the devices, and then physically locating the devices. The network can detect both unauthorized client stations and unauthorized edge devices such as wireless access points (APs). The network can detect intruders by monitoring information transferred over wireless channels, identifying protocol state machine violations, tracking roaming behavior of clients, and detecting network addresses being improperly used in multiple locations. Upon detecting an intruder, the network can automatically locate and shut off the physical/logical port to which the intruder is connected.

Claims (14)

1. A method of detecting a denial of service attack in a wireless computer network, the method comprising:

recording, at a plurality of intervals, a number of association or probe requests made by a wireless client device to a plurality of wireless edge devices coupled to a respective plurality of ports of a network switch;

comparing the number of association or probe requests recorded at each interval to a threshold value;

detecting the denial of service attack if the number of association or probe requests exceeds the threshold value; and

monitoring a protocol state machine associated with the wireless client device by a network analysis application running on a server computer, the protocol state machine having one or more wireless attributes of the wireless client device, the network analysis application detecting the denial of service attack by detecting anomalies in the one or more wireless attributes, wherein the one or more wireless attributes comprise the number of association and probe requests.

2. The method of claim 1 performed on non-dedicated, distributed network infrastructure.

3. The method of claim 1 wherein the threshold value is based on a normal rate of association or probe requests.

4. The method of claim 1 further comprising, in response to detecting the denial of service attack, automatically instructing the network switch to shut down a port of the plurality of ports under attack.

5. The method of claim 1 further comprising, in response to detecting the denial of service attack, automatically instructing the network switch to discard packets from a port of the plurality of ports under attack.

6. The method of claim 1 further comprising, in response to detecting the denial of service attack, alerting a network administrator of the attack.

7. The method of claim 1 wherein monitoring further comprises determining a geographic proximity between two or more wireless client devices.

8. The method of claim 7 , wherein the geographic proximity of the two or more wireless clients is determined by signal strength of the two or more wireless clients as identified by the network analysis application.

9. The method of claim 1 , wherein monitoring further comprises monitoring two or more wireless client devices operating at two or more frequencies in a wireless channel by switching to the two or more frequencies.

10. The method of claim 1 , wherein monitoring further comprises determining and comparing MAC addresses of two or more wireless client devices.

Assignments (10)
RELEASE OF PATENT AND TRADEMARK SECURITY INTEREST AT REEL/FRAME NO. 46050/0546 Recorded Jul 30, 2026
From: BANK OF MONTREAL, AS AGENT
To: EXTREME NETWORKS, INC.
Reel/Frame 076081/0088 →
SECURITY INTEREST Recorded Jul 29, 2026
From: EXTREME NETWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 076078/0590 →
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2016
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 040521/0762 →
SECURITY AGREEMENT Recorded Jul 27, 2015
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 036189/0284 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2014
From: RATHL, MANISH M.; JAIN, VIPIN K.; MERCHANT, SHEHZAD T.; LIN, VICTOR C.
To: EXTREME NETWORKS, INC.
Reel/Frame 032328/0441 →
Continuity (4)
Division 10794203 · Mar 5, 2004
Continuation In Part 10774079 · Feb 6, 2004
Continuation In Part 10773394 · Feb 6, 2004
Continuation In Part 10773487 · Feb 6, 2004