IP Library Granted Patent US 8,549,634
Granted Patent B2
US 8,549,634 · App. 13/293,867 · Granted Oct 1, 2013

Method and apparatus for detecting a rogue access point in a communication network

Inventors: Pradip K. Dubey (Karnataka, IN); Jitesh Narayan Verma (Karnataka, IN)
Assignee: Symbol Technologies, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,549,634
App. No.
13/293,867
Granted
Oct 1, 2013
Kind
B2
Abstract

A method and apparatus for detecting a rogue access point in a communication network is described herein. The method includes a probing unit sending a pre-detection message to an associated access point in the communication network. The pre-detection message indicates a start of rogue access point detection mode and informs the associated access point not to respond to probe requests following the pre-detection message. The method further includes the probing unit broadcasting probe requests in the communication network. The probing unit detect that one or more of the plurality of access points is the rogue access point based on receiving a probe response in reply to the broadcasted probe request from the rogue access point. A method for detecting a rogue access point includes broadcasting a probe request with a proprietary information bit and detecting the rogue access point based on receiving a probe response for the broadcasted probe request.

Claims (30)

1. A method for detecting a rogue access point in a communication network comprising a probing unit authorized in the network, a plurality of client devices, and a plurality of access points, the method comprising:

operating the probing unit to:

associate with at least one of the plurality of access points, wherein the associated access point is an authorized access point in the communication network;

send a pre-detection message to the associated access point, wherein the pre-detection message indicates a start of rogue access point detection mode and informs the associated access point not to respond to at least one of a plurality of probe requests following the pre-detection message;

broadcast at least one probe request in the communication network after sending the pre-detection message and during the detection mode, wherein authorized access points in the plurality of access points being previously instructed to not to respond to the at least one probe request; and

detect that one or more of the plurality of access points is the rogue access point based on receiving a probe response in reply to the broadcasted probe request from the rogue access point during the detection mode.

2. The method of claim 1 further comprising:

sending, by the associated access point, the pre-detection message to the other plurality of access points authorized to the communication network and informing the other plurality of authorized access points not to respond to at least one probe request following the pre-detection message.

3. The method of claim 2 further comprising:

operating the probing unit to:

send a post-detection message to the associated access point indicating end of rogue access point detection mode.

4. The method of claim 3 further comprising:

sending, by the associated access point, the post-detection message to the other plurality of authorized access points indicating the end of rogue access point detection mode.

5. The method of claim 4 , wherein the pre-detection message and the post-detection message are proprietary messages specific to the communication network.

6. The method of claim 1 further comprising:

operating the probing unit to:

determine whether a predetermined time period expires when no probe response is received; and

send a post-detection message when the predetermined time period expires and when no probe response is detected.

7. The method of claim 3 , wherein the plurality of access points operate in a normal mode outside of the detection mode.

8. The method of claim 1 , wherein the probing unit includes at least one of the plurality of client devices in the communication network.

9. The method of claim 1 , wherein the probing unit includes at least one of the plurality of access points operating in a probe mode.

10. A method for detecting a rogue access point in a communication network comprising a probing unit authorized in the network, a plurality of client devices, and a plurality of access points, the method comprising:

operating an authorized plurality of access points to:

receive a pre-detection message from the probing unit associated with the at least one access point, wherein the pre-detection message indicates a start of rogue access point detection mode and informs the authorized access points not to respond to at least one of a plurality of probe requests following the pre-detection message;

receive at least one of a plurality of probe requests broadcast by the probing unit after receiving the pre-detection message and during the detection mode;

refrain from responding to probe requests during the detection mode.

11. The method of claim 10 further comprising:

operating the at least one access point to:

respond to probe requests after a post-detection message is received.

12. The method of claim 10 , wherein the plurality of access points operate in a normal mode outside of the detection mode.

Assignments (11)
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2016
From: SYMBOL TECHNOLOGIES, LLC
To: EXTREME NETWORKS, INC.
Reel/Frame 040579/0410 →
AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2016
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 040521/0762 →
RELEASE OF SECURITY INTEREST Recorded Aug 17, 2015
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 036371/0738 →
CHANGE OF NAME Recorded Jul 8, 2015
From: SYMBOL TECHNOLOGIES, INC.
To: SYMBOL TECHNOLOGIES, LLC
Reel/Frame 036083/0640 →
SECURITY AGREEMENT Recorded Oct 31, 2014
From: ZIH CORP.; LASER BAND, LLC; ZEBRA ENTERPRISE SOLUTIONS CORP.; SYMBOL TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC. AS THE COLLATERAL AGENT
Reel/Frame 034114/0270 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2011
From: DUBEY, PRADIP K.; VERMA, JITESH NARAYAN
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 027209/0989 →
Continuity (1)
Related Publication 20120124665A1 · May 17, 2012