IP Library Granted Patent US 8,493,977
Granted Patent B2
US 8,493,977 · App. 12/957,260 · Granted Jul 23, 2013

Detection of an unauthorized access point in a wireless communication network

Inventors: Ramprasad Vempati (Karnataka, IN); Pasupula Sridhar (Karnataka, IN); Ananda Krishnan Vishwanathan (Karnataka, IN)
Assignee: Symbol Technologies, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,493,977
App. No.
12/957,260
Granted
Jul 23, 2013
Kind
B2
Abstract

A method and controller for detecting an unauthorized access point in a wireless communication network includes a first step of generating ( 200 ) a probe identity that is unused in the wireless communication network. A next step includes informing ( 202 ) adopted access points in the communication network of this generated probe identity, and that packets from this generated probe identity should be ignored. A next step includes broadcasting ( 204 ) at least one probe request using the generated probe identity. A next step includes detecting ( 206 ) if there are any probe responses to the at least one probe request, indicating an unauthorized access point. A next step includes providing an alert ( 214, 216, 218 ) if an unauthorized access point is detected.

Claims (33)

1. A method for detecting an unauthorized access point in a wireless communication network, the method comprising:

generating, by a processor, a probe identity that is unused in the wireless communication network;

informing, by the processor, adopted access points in the communication network of this generated probe identity, and that packets from this generated probe identity should be ignored;

broadcasting, by the adopted access points, at least one probe request using the generated probe identity;

detecting, by the processor, if there are any probe responses to the at least one probe request, indicating an unauthorized access point; and

providing an alert, by the processor, if an unauthorized access point is detected.

2. The method of claim 1 , wherein informing includes a time duration for which the generated probe identity will be valid.

3. The method of claim 1 , wherein broadcasting is performed by all adopted access points on their own respective operating channel in the communication network.

4. The method of claim 3 , wherein broadcasting includes a separate intrusion detector also broadcasting the at least one probe request on all communication network channels.

5. The method of claim 1 , wherein informing includes informing the adopted access points in the communication network that packets from a probe request with a Service Set Identifier (SSID) set as NULL should be ignored, and wherein broadcasting includes broadcasting a probe request with the SSID set as NULL, whereupon the adopted access points in the communication network ignore the probe request.

6. The method of claim 1 , wherein informing includes informing the adopted access points in the communication network that packets from a probe request with specific Service Set Identifiers (SSIDs) configured on the adopted access ports should be ignored, and wherein broadcasting includes broadcasting a probe request with one of the specific SSIDs that are configured on adopted access ports, whereupon the adopted access points in the communication network ignore the probe request.

7. The method of claim 1 , wherein informing includes informing the adopted access points in the communication network that packets from a probe request with a Service Set Identifier (SSID) set as NULL and specific Service Set Identifiers (SSIDs) configured on the adopted access ports should be ignored, and wherein broadcasting includes broadcasting a first probe request with the SSID set as NULL and a second probe request with one of the specific SSIDs that are configured on adopted access ports, whereupon the adopted access points in the communication network ignore the probe requests.

8. The method of claim 1 , further comprising:

checking whether the probe response has a known MAC address, and

providing an alert of unauthorized spoofing of an access point.

9. The method of claim 1 , further comprising:

checking whether the probe response has a known SSID, and

providing an alert of an unauthorized access point if the probe response has an unknown SSID, and

providing an alert of a rogue access point if the probe response has a known SSID.

10. A controller for detecting an unauthorized access point in a wireless communication network, the controller comprising:

a processor operable to generate a probe identity that is unused in the wireless communication network, inform adopted access points in the communication network of this generated probe identity, and that packets from this generated probe identity should be ignored, direct the adopted access points to broadcast at least one probe request using the generated probe identity, detect if there are any probe responses to the at least one probe request, indicating an unauthorized access point, and provide an alert if an unauthorized access point is detected.

11. The controller of claim 10 , wherein the processor will inform the adopted access points of a time duration for which the generated probe identity will be valid.

12. The controller of claim 10 , wherein the generated probe identity is an interface MAC address known by the controller as not being authorized for use by access points.

13. The controller of claim 12 , further comprising a separate intrusion detector also directed by the processor to broadcast the at least one probe request on all communication network channels.

14. The controller of claim 10 , wherein adopted access points in the communication network are informed that packets from a probe request with a Service Set Identifier (SSID) set as NULL should be ignored, and wherein a first probe request includes the SSID set as NULL, whereupon the adopted access points in the communication network ignore the probe request.

15. The controller of claim 10 , wherein the adopted access points in the communication network are informed that packets from a probe request with specific Service Set Identifiers (SSIDs) configured on the adopted access ports should be ignored, and wherein a second probe request includes one of the specific SSIDs that are configured on the adopted access ports, whereupon the adopted access points in the communication network ignore the probe request.

16. The controller of claim 10 , wherein the adopted access points in the communication network are informed that packets from a probe request with a Service Set Identifier (SSID) set as NULL and specific Service Set Identifiers (SSIDs) configured on the adopted access ports should be ignored, and wherein the at least one probe request includes a first probe request with a the SSID set as NULL and a second probe request with one of the specific SSIDs that are configured on adopted access ports,

whereupon the adopted access points in the communication network ignore the probe requests.

17. The controller of claim 10 , wherein the processor is further operable to check whether the probe response has a known MAC address, and provide an alert of unauthorized spoofing of an access point.

18. The controller of claim 10 , wherein the processor is further operable to check whether the probe response has a known SSID, and provide an alert of an unauthorized access point if the probe response has an unknown SSID, and provide an alert of a rogue access point if the probe response has a known SSID.

19. A controller for detecting an unauthorized access point in a wireless communication network, the controller comprising:

a processor operable to generate a probe identity that is unused in the wireless communication network, inform adopted access points in the communication network of this generated probe identity and that packets from a probe request with a Service Set Identifier (SSID) set as NULL and specific Service Set Identifiers (SSIDs) configured on the adopted access ports should be ignored, and that packets from this generated probe identity, probe requests with the SSID set as NULL, and probe requests with one of the specific SSIDs that are configured on adopted access ports should be ignored, direct the adopted access points to broadcast a first probe request using the generated probe identity and that includes the SSID set as NULL and a second probe request using the generated probe identity and that includes one of the specific SSIDs that are configured on the adopted access ports, whereupon the adopted access points in the communication network ignore the probe requests, detect if there are any probe responses to the at least one probe request, indicating an unauthorized access point, and provide an alert if an unauthorized access point is detected.

20. The controller of claim 10 , wherein the processor is further operable to check whether the probe response has a known MAC address, and provide an alert of unauthorized spoofing of an access point, check whether the probe response has a known SSID, and provide an alert of an unauthorized access point if the probe response has an unknown SSID, and provide an alert of a rogue access point if the probe response has a known SSID.

Assignments (14)
RELEASE OF PATENT AND TRADEMARK SECURITY INTEREST AT REEL/FRAME NO. 46050/0546 Recorded Jul 30, 2026
From: BANK OF MONTREAL, AS AGENT
To: EXTREME NETWORKS, INC.
Reel/Frame 076081/0088 →
SECURITY INTEREST Recorded Jul 29, 2026
From: EXTREME NETWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 076078/0590 →
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2016
From: SYMBOL TECHNOLOGIES, LLC
To: EXTREME NETWORKS, INC.
Reel/Frame 040579/0410 →
AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2016
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 040521/0762 →
RELEASE OF SECURITY INTEREST Recorded Aug 17, 2015
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 036371/0738 →
CHANGE OF NAME Recorded Jul 8, 2015
From: SYMBOL TECHNOLOGIES, INC.
To: SYMBOL TECHNOLOGIES, LLC
Reel/Frame 036083/0640 →
SECURITY AGREEMENT Recorded Oct 31, 2014
From: ZIH CORP.; LASER BAND, LLC; ZEBRA ENTERPRISE SOLUTIONS CORP.; SYMBOL TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC. AS THE COLLATERAL AGENT
Reel/Frame 034114/0270 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDRESS OF SYMBOL TECHNOLOGIES, INC. TO READ ONE MOTOROLA PLAZA, HOLTSVILLE, NY 11742. PREVIOUSLY RECORDED ON REEL 025403 FRAME 0908. ASSIGNOR(S) HEREBY CONFIRMS THE ADDRESS CORRECTION.. Recorded Jun 21, 2013
From: VEMPATI, RAMPRASAD; SRIDHAR, PASAPULA; VISHWANATHAN, ANANDA KRISHNAN
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 030666/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2010
From: VEMPATI, RAMPRASAD; SRIDHAR, PASUPULA; VISHWANATHAN, ANANDA KRISHNAN
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 025403/0908 →
Continuity (1)
Related Publication 20120134272A1 · May 31, 2012