IP Library Granted Patent US 9,763,099
Granted Patent B2
US 9,763,099 · App. 14/574,240 · Granted Sep 12, 2017

System and method for security and quality assessment of wireless access points

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,763,099
App. No.
14/574,240
Granted
Sep 12, 2017
Kind
B2
Abstract

A computer-implemented method for security risk assessment of wireless access point devices, the computer-implemented method comprising: receiving signals from one or more wireless access points by two or more mobile wireless devices visiting said access points, obtaining Basic Service Set Identifiers (BSSID) of visited access points and reporting values derived from BSSID and from an identifier of corresponding mobile device to a first database, receiving a request for a security risk assessment of evaluated wireless access point, said request containing value derived from BSSID of the evaluated access point, searching the first database for one or more entries corresponding to the evaluated access point, and processing search results to assess security risk of the evaluated access point, said processing comprises computing a component of said risk dependent on the count of unique identifiers of mobile devices reported for the evaluated access point.

Claims (70)

1. A method for security risk assessment of wireless access point devices, the method comprising performing, by a computer system:

receiving, from a plurality of devices, a plurality of reports, each report being transmitted by a device of the plurality of devices in response to accessing an access point having a unique access point identifier and including a unique user identifier;

determining a number of unique user identifiers represented in the plurality of reports;

determining that both of (a) the number of unique user identifiers exceeds a first threshold and (b) the number of unique user identifiers is below a second threshold that is higher than the first threshold; and

in response to determining that both (a) and (b) are true, transmitting a message to one or more devices of the plurality of devices, the message indicating that the access point is not secure.

2. The method of claim 1 , further comprising:

determining that the number of unique user identifiers of the access point is growing; and

wherein transmitting the message is performed in response to both of growth in the number of unique user identifiers and determining that (a) and (b) are true.

3. The method of claim 1 , wherein the plurality of reports are a first plurality of reports and the access point is a first access point, the method further comprising:

receiving, from a plurality of devices, a second plurality of reports, each report being transmitted by a device of the plurality of devices in response to accessing a second access point having a unique access point identifier and including a unique user identifier;

determining that at least one of (a) the number of unique user identifiers is below a first threshold and (b) the number of unique user identifiers is above a second threshold that is higher than the first threshold; and

in response to determining that at least one of (a) and (b) are true, refraining from notifying one or more devices of the plurality of devices that the access point is not secure.

4. The method of claim 1 , further comprising determining a security score for the access point by:

determining the security score according to a function of a numbers of reconnects per session included in the plurality of reports;

determining that the security score indicates that the access point is not secure; and

in response to determining that the security score indicates that the access point is not secure, transmitting the message to the one or more devices of the plurality of devices.

5. The method of claim 1 , further comprising determining a security score for the access point by:

determining the security score according to a function of a number of local internet protocol (IP) addresses detected during one or more accesses;

determining that the security score indicates that the access point is not secure; and

in response to determining that the security score indicates that the access point is not secure, transmitting the message to the one or more devices of the plurality of devices.

6. The method of claim 1 , further comprising determining a security score for the access point by:

additionally determining the security score according to a second function of an elapsed time between a first time of access reported in a first-received report of the plurality of reports and a second time of access reported in a last-received report of the plurality of reports;

determining that the security score indicates that the access point is not secure; and

in response to determining that the security score indicates that the access point is not secure, transmitting the message to the one or more devices of the plurality of devices.

7. The method of claim 1 , further comprising determining a security score for the access point by:

determining the security score according to a function of a number of reconnects per session detected during one or more accesses;

additionally determining the security score according to a second function of the a number of local internet protocol (IP) addresses detected during one or more accesses;

additionally determining the security score according to a third function of an elapsed time between two or more accesses;

determining that the security score indicates that the access point is not secure; and

in response to determining that the security score indicates that the access point is not secure, transmitting the message to the one or more devices of the plurality of devices.

8. The method of claim 1 , wherein transmitting the message to one or more devices of the plurality of devices comprises transmitting an instruction to the one or more devices to not use the access point.

9. The method of claim 1 , wherein transmitting the message to one or more devices of the plurality of devices comprises transmitting an instruction to the one or more devices to perform data access using the access point using a virtual private network (VPN).

10. The method of claim 1 , wherein transmitting the message to one or more devices of the plurality of devices comprises transmitting an interface to one or more devices, the interface indicating that the access point is not secure and providing an interface element configured to invoke performing of data access using the access point by means of a virtual private network (VPN).

11. A method for security risk assessment of wireless access point devices, the method comprising performing, by a computer system:

receiving, from a plurality of devices, a plurality of reports, each report being transmitted by a device of the plurality of devices in response to accessing an access point having a unique access point identifier and including a unique user identifier;

determining a number of unique user identifiers represented in the plurality of reports;

determining a security score for the access point according to a function that indicates higher risk with increasing number of unique user identifiers; and

determining that the score indicates that the access point is not secure;

in response to determining that the score indicates that the access point is not secure, transmitting a message to one or more devices of the plurality of devices, the message indicating that the access point is not secure,

wherein determining the security score for the access point according to the function that indicates higher risk with increasing number of unique user identifiers comprises, computing the security score according to a nonlinear function of risk with respect to number of unique user identifiers such that:

for a first portion of a range of possible numbers of unique user identifiers, the security score indicates decreasing risk with increasing number of unique user identifiers;

for a second portion of the range of possible numbers of unique user identifiers, the security score indicates increasing risk with increasing number of unique user identifiers;

for a third portion of the range of possible numbers of unique user identifiers, the security score indicates decreasing risk with increasing number of unique user identifiers;

wherein the third portion includes higher values for the number of unique user identifiers than the second portion and the second portion includes higher values for the number of unique user identifiers than the first portion.

12. A system for security risk assessment of wireless access point devices, the system comprising one or more processors and one or more memory devices operably coupled to the one or more processors, the one or more memory devices storing executable code effective to cause the one or more processors to:

receive, from a plurality of devices, a plurality of reports, each report being transmitted by a device of the plurality of devices in response to accessing an access point having a unique access point identifier and including a unique user identifier;

determine a number of unique user identifiers represented in the plurality of reports;

and

if the number of unique user identifiers is greater than a first threshold and less than a second threshold, transmit a message to one or more devices of the plurality of devices, the message indicating that the access point is not secure, the second threshold being greater than the second threshold.

13. The system of claim 12 , wherein the executable data is further effective to cause the one or more processors to determine a growth in the number of unique user identifiers; and

determining that the access point indicates higher risk if the number of unique users is increasing and the number of unique user identifiers is below the second threshold.

14. The system of claim 12 , wherein the executable data is further effective to cause the one or more processors to:

if the number of unique user identifiers is at least one of less than the first threshold and greater than the second threshold, refrain from notifying one or more devices of the plurality of devices that the access point is not secure.

15. The system of claim 12 , wherein the executable data is further effective to cause the one or more processors to:

determine a security risk according to a first function of the number of reconnects per session for one or more accesses;

additionally determine a security risk according to a second function of a number of local internet protocol (IP) addresses detected during one or more accesses; and

additionally determine the security risk according to a third function of an elapsed time between two or more accesses;

notify one or more of the plurality of devices that the access point is not secure if the security risk is above a threshold value.

16. The system of claim 12 , wherein the executable data is further effective to cause the one or more processors to transmit the message to one or more devices of the plurality of devices by transmitting an instruction to the one or more devices to not use the access point.

17. The system of claim 12 , wherein transmitting the message to one or more devices of the plurality of devices by transmitting an interface to one or more devices, the interface indicating that the access point is not secure and providing an interface element configured to invoke performing of data access using the access point by means of a virtual private network (VPN).

18. A system for security risk assessment of wireless access point devices, the system comprising one or more processors and one or more memory devices operably coupled to the one or more processors, the one or more memory devices storing executable code effective to cause the one or more processors to:

receive, from a plurality of devices, a plurality of reports, each report being transmitted by a device of the plurality of devices in response to accessing an access point having a unique access point identifier and including a unique user identifier;

determine a number of unique user identifiers represented in the plurality of reports;

determine a security score for the access point according to a function that indicates higher risk with increasing number of unique user identifiers; and

if the score indicates that the access point is not secure, transmit a message to one or more devices of the plurality of devices, the message indicating that the access point is not secure

wherein the executable data is further effective to cause the one or more processors to determine the security score by computing the security score according to a nonlinear function of risk with respect to number of unique user identifiers such that:

for a first portion of a range of possible numbers of unique user identifiers, the security score indicates decreasing risk with increasing number of unique user identifiers;

for a second portion of the range of possible numbers of unique user identifiers, the security score indicates increasing risk with increasing number of unique user identifiers;

for a third portion of the range of possible numbers of unique user identifiers, the security score indicates decreasing risk with increasing number of unique user identifiers;

wherein the third portion includes higher values for the number of unique user identifiers than the second portion and the second portion includes higher values for the number of unique user identifiers than the first portion.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Dec 17, 2024
From: JPMORGAN CHASE BANK, N.A.
To: AURA SUB, LLC; INTERSECTIONS, LLC; TWINGATE INC.
Reel/Frame 069616/0097 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 14, 2023
From: INTERSECTIONS, LLC
To: AURA SUB, LLC
Reel/Frame 065875/0853 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2023
From: CF NEWCO, INC.
To: INTERSECTIONS, LLC
Reel/Frame 065717/0131 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2023
From: AURA SUB, LLC
To: AURA HOLDCO, LLC
Reel/Frame 065716/0906 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2023
From: AURA HOLDCO, LLC
To: CF INTERMEDIATE HOLDINGS, LLC
Reel/Frame 065717/0021 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2023
From: CF INTERMEDIATE HOLDINGS, LLC
To: CF NEWCO, INC.
Reel/Frame 065717/0095 →
CORRECTIVE ASSIGNMENT TO REMOVE THE ERRONEOUS SERIAL NUMBER 16/000,700 AND 16/149,928 PREVIOUSLY RECORDED AT REEL: 059251 FRAME: 0342. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME Recorded Jun 6, 2023
From: PANGO INC.
To: PANGO LLC
Reel/Frame 064065/0406 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION NUMBERS 16000700 AND 16149928 PREVIOUSLY RECORDED AT REEL: 059462 FRAME: 0043. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 14, 2023
From: AURA HOLDCO, LLC
To: AURA SUB, LLC
Reel/Frame 063859/0966 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE SERIAL NUMBERS 16000700 AND 16149928 PREVIOUSLY RECORDED AT REEL: 059285 FRAME: 0023. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 14, 2023
From: PANGO LLC
To: PORTUNUS PARENT, LLC
Reel/Frame 063873/0502 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION NUMBER 16000700 AND 16149928 PREVIOUSLY RECORDED AT REEL: 059392 FRAME: 0479. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 14, 2023
From: PORTUNUS PARENT, LLC
To: AURA HOLDCO, LLC
Reel/Frame 063873/0551 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2022
From: AURA HOLDCO, LLC
To: AURA SUB, LLC
Reel/Frame 059462/0043 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2022
From: PORTUNUS PARENT, LLC
To: AURA HOLDCO, LLC
Reel/Frame 059392/0479 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2022
From: PANGO LLC
To: PORTUNUS PARENT, LLC
Reel/Frame 059285/0023 →
CHANGE OF NAME Recorded Feb 25, 2022
From: PANGO INC.
To: PANGO LLC
Reel/Frame 059251/0342 →
RELEASE OF SECURITY INTEREST Recorded Dec 8, 2021
From: JPMORGAN CHASE BANK, N.A.
To: PANGO, INC.; INTERSECTIONS INC.
Reel/Frame 058330/0983 →
SECURITY INTEREST Recorded Dec 7, 2021
From: INTERSECTIONS INC.; PANGO INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 058328/0941 →
SECURITY INTEREST Recorded Jul 2, 2020
From: PANGO, INC.; INTERSECTIONS INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 053105/0591 →
RELEASE OF SECURITY INTEREST Recorded Jul 1, 2020
From: PACIFIC WESTERN BANK
To: PANGO INC. (FORMERLY KNOWN AS ANCHORFREE INC.)
Reel/Frame 053116/0489 →
SECURITY INTEREST Recorded Jun 25, 2020
From: PANGO INC.
To: PACIFIC WESTERN BANK
Reel/Frame 053039/0417 →
CHANGE OF NAME Recorded Jan 10, 2020
From: ANCHORFREE INC.
To: PANGO INC.
Reel/Frame 051566/0680 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2014
From: LAPIDOUS, EUGENE
To: ANCHORFREE INC.
Reel/Frame 034534/0149 →