IP Library Granted Patent US 10,243,974
Granted Patent B2
US 10,243,974 · App. 15/235,737 · Granted Mar 26, 2019

Detecting deauthentication and disassociation attack in wireless local area networks

Inventors: Naveen Manjunath (Bangalore Karnataka, IN); Santashil PalChaudhuri (Bangalore Karnataka, IN); Deepakparasar Avalur (Bangalore Karnataka, IN)
Assignee: Hewlett Packard Enterprise Development LP
H04L63/1416H04L61/6022H04W12/12H04W8/26H04W84/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,243,974
App. No.
15/235,737
Granted
Mar 26, 2019
Kind
B2
Abstract

The present disclosure relates to a network device that detects a deauthentication and/or disassociation attack in a wireless local area network (WLAN). In example implementations, the network device selects a random Media Access Control (MAC) address that is unused in the WLAN. The network device then transmits a request using the selected MAC address over a shared wireless communication channel. Next, the network device transmits a response using a MAC address corresponding to the network device over the shared wireless communication channel. Subsequently, the network device receives a disconnection request using the selected MAC address over the shared wireless communication channel. In response to receiving the disconnection request, the network device can detect an attacker device in the WLAN.

Claims (14)

1. A first network device comprising:

a memory;

one or more processors to:

select a random Media Access Control (MAC) address that is unused in a wireless local area network;

transmit a request using the selected MAC address over a shared wireless communication channel;

receive a response over the shared wireless communication channel from a second network device in the wireless local area network;

receive a disconnection request over the shared wireless communication channel, wherein the disconnection request comprises the MAC address corresponding to the second network device and the selected MAC address;

transmit a message over a wired connection to determine whether the disconnection request is transmitted by the second network device; and

detect an attacker in the wireless local area network in response to determining that the disconnection request is not transmitted by the second network device.

2. The network device of claim 1 , wherein the message over the wired connection is transmitted to at least one of the second network device and a network controller that manages client devices and access points in the wireless local area network.

3. The network device of claim 1 , wherein the first request comprises one or more of a probe request, an authentication request, and an association request.

4. The network device of claim 1 , wherein the first response comprises one or more of a probe response, an authentication response, and an association response.

5. The network device of claim 1 , wherein the disconnection request comprises one or more of a de-authentication request and a disassociation request.

6. The network device of claim 1 , wherein the selected MAC address is used to emulate a client device in the wireless local area network.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2018
From: ARUBA NETWORKS, INC.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 045921/0055 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2016
From: MANJUNATH, NAVEEN; PALCHAUDHURI, SANTASHIL; AVALUR, DEEPAKPARASAR
To: ARUBA NETWORKS, INC.
Reel/Frame 039421/0139 →
Priority Claims (1)
IN 201641005781 · Feb 19, 2016 · national
Continuity (1)
Related Publication 20170244732A1 · Aug 24, 2017
Cited By (1)
US 12,593,265