IP Library Granted Patent US 10,505,967
Granted Patent B1
US 10,505,967 · App. 15/635,465 · Granted Dec 10, 2019

Sensor-based wireless network vulnerability detection

Inventors: Tomer Schwartz (Tel Aviv, IL); Nadir Izrael (Tel Aviv, IL)
Assignee: Armis Security Ltd.
H04L63/1433H04L63/0263H04L63/1408H04L63/1425H04W24/08G06F21/577H04L63/1416H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,505,967
App. No.
15/635,465
Granted
Dec 10, 2019
Kind
B1
Abstract

Certain embodiments disclosed herein include a method for detecting potential vulnerabilities in a wireless environment. The method comprises collecting, by a network sensor deployed in the wireless environment, at least wireless traffic data; analyzing the collected wireless traffic data to detect at least activity initiated by a wireless entity in the wireless environment; sending, to a control system, data indicating the detected wireless entity; and enforcing a security policy on the detected wireless entity based on instructions received from the control system.

Claims (100)

1. A method for detecting potential vulnerabilities in a wireless environment, comprising:

collecting, by an out-of-band network sensor that can process a complete protocol stack for each respective one of a plurality of communication protocols deployed in the wireless environment, at least wireless traffic data, wherein the wireless traffic data employs at least two of the plurality of communication protocols;

analyzing the collected wireless traffic data to detect at least activity of a wireless entity in the wireless environment, wherein the wireless entity is adapted to employ at least two of the plurality of communication protocols and wherein the wireless entity is a network element deployed in the wireless environment;

sending, to a control system, data indicating the detected wireless entity; and

enforcing a security policy on the wireless entity based on instructions received from the control system:

collecting, by the network sensor, data related to the network element;

determining, based at least on the collected network element data, whether the network element is an unmanaged element; and

sending, to the control system, the results of the determination.

2. The method of claim 1 , wherein the network sensor is a hardware sensor deployed in the wireless environment, wherein the hardware sensor includes at least one microprocessor and at least two transceivers, wherein each microprocessor is configured to process signals according to a wireless protocol for a respective transceiver of the at least two transceivers.

3. The method of claim 1 , wherein the network sensor is an agent sensor installed on a wireless device operable in the wireless environment, further comprising:

collecting, by the agent sensor, data related to the at least wireless device; and

sending, to the control system, the collected wireless device data.

4. The method of claim 1 , wherein the network sensor is a network infrastructure sensor connected to a network element deployed in the wireless environment, further comprising:

collecting, by the network infrastructure sensor, data related to the network element; and

sending, to the control system, the collected network element data.

5. The method of claim 1 , further comprising:

probing, by the network sensor, a wireless device in the wireless environment;

identifying, based at least on the probing, the wireless device; and

sending, to the control system, the identification of the wireless device.

6. The method of claim 1 , further comprising:

identifying, based on the collected wireless traffic data, sensitive data being transmitted in the wireless environment; and

sending, to the control system, the identification of the transmitted sensitive data.

7. The method of claim 1 , wherein enforcing the security policy includes performing, by the network sensor, at least one of: disconnecting an active connection in real-time, blocking a device from connecting to a network of the wireless environment, generating an alert, modifying configuration of a device, and containing a device outside of a network of the wireless environment.

8. The method of claim 1 , wherein the wireless environment further includes a wireless device, further comprising:

collecting data related to the wireless device;

determining, based on the collected wireless device data, a geographical location of the wireless device; and

sending, to the control system, the determined geographical location.

9. The method of claim 1 , further comprising:

checking if the wireless entity meets the security policy based on the collected at least wireless traffic data, wherein the security policy is enforced when the wireless entity meets the security policy, wherein enforcing the security policy includes at least one of: performing at least one mitigation action, logging a detected incident, and initiating a probe of the wireless entity.

10. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute the method of claim 1 .

11. A system for detecting potential vulnerabilities in a wireless environment, comprising:

a control system; and

at least one network sensor deployed in the wireless environment, wherein each network sensor is configured to;

collect at least wireless traffic data;

analyze the collected wireless traffic data to detect at least activity initiated by a wireless entity in the wireless environment;

send, to the control system, data indicating the detected wireless entity; and

enforce a security policy on the detected wireless entity based on instructions received from the control system;

wherein the at least one network sensor is an out-of-band network sensor that can process the complete protocol stack for each respective one of a plurality of communication protocols deployed in the wireless environment, wherein the wireless traffic data employs at least two of the plurality of communication protocols, and wherein the wireless entity is adapted to employ at least two of the plurality of communication protocols;

wherein, the wireless entity is a network element deployed in the wireless environment; and

wherein the at least one network sensor is further configured to:

collect data related to the network element deployed in the wireless environment;

determine, based at least on the collected network element data, whether the network element is an unmanaged element; and

send, to the control system, the results of the determination.

12. The system of claim 11 , wherein the network sensor includes at least one hardware sensor deployed in the wireless environment, wherein each hardware sensor includes at least one microprocessor; and

at least two transceivers, wherein each microprocessor is configured to process signals according to a wireless protocol for a respective transceiver of the at least two transceivers.

13. The system of claim 11 , wherein the at least one network sensor includes at least one agent sensor, wherein each agent sensor is installed on a wireless device, wherein each agent sensor is further configured to:

collect data related to the at least wireless device; and

send, to the control system, the collected wireless device data.

14. The system of claim 11 , wherein the at least one network sensor includes at least one network infrastructure sensor, wherein each network infrastructure sensor is configured to:

collect data related to a set of network elements, the set including at least the network element deployed in the wireless environment; and

send, to the control system, the collected network element data.

15. The system of claim 11 , wherein at least one of the at least one network sensor is further configured to:

probe a wireless device connected to a network of the wireless environment;

identify, based at least on the probing, the wireless device; and

send, to the control system, the identification of the wireless device.

16. The system of claim 11 , wherein at least one of the at least one network sensor is further configured to:

identify, based on the collected wireless traffic data, sensitive data being transmitted in the wireless environment; and

send, to the control system, the identification of the transmitted sensitive data.

17. The system of claim 11 , wherein at least one of the at least one network sensor is further configured to perform at least one of: disconnect an active connection in real-time, block a device from connecting to a network of the wireless environment, generating an alert, modifying configuration of a device, and contain a device outside of a network of the wireless environment.

18. The system of claim 11 , wherein at least one of the at least one network sensor is further configured to:

collect data related to a wireless device in the wireless environment;

determine, based on the collected wireless device data, a geographical location of the wireless device; and

send, to the control system, the determined geographical location.

19. The system of claim 11 , wherein at least one of the at least one network sensor is further configured to:

check if the detected wireless entity meets the security policy based on the collected at least wireless traffic data, wherein the security policy is enforced when the wireless entity meets the security policy, wherein enforcing the security policy includes at least one of: performing at least one mitigation action, logging a detected incident, and initiating a probe of the wireless entity.

20. The system of claim 11 , wherein the control system and the at least one network sensor are integrated in a same device.

21. A network sensor, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the network sensor to:

collect at least wireless traffic data in a wireless environment;

analyze the collected wireless traffic data to detect at least activity initiated by a wireless entity in the wireless environment, wherein the wireless entity is a network element deployed in the wireless environment;

send, to a control system, data indicating the detected wireless entity; and

enforce a security policy on the detected wireless entity based on instructions received from the control system;

collect data related to the network element;

determine, based at least on the collected network element data, whether the network element is an unmanaged element; and

send, to the control system, the results of the determination; and

wherein the network sensor is an out-of-band network sensor that can process the complete protocol stack for each respective one of a plurality of communication protocols deployed in the wireless environment, wherein the wireless traffic data employs at least two of the plurality of communication protocols, and wherein the wireless entity is adapted to employ at least two of the plurality of communication protocols.

22. The network sensor of claim 21 , wherein the network sensor is a hardware sensor deployed in the wireless environment, further comprising:

at least one microprocessor; and

at least two transceivers, wherein each microprocessor is configured to process signals according to a wireless protocol for a respective transceiver of the at least two transceivers.

23. The network sensor of claim 21 , wherein the network sensor is an agent sensor installed on a wireless device operable in the wireless environment, wherein the network sensor is further configured to:

collect data related to the wireless device; and

send, to the control system, the collected wireless device data.

24. The network sensor of claim 21 , wherein the network sensor is a network infrastructure sensor connected to the network element deployed in the wireless environment, wherein the network sensor is further configured to:

collect data related to the network element; and

send, to the control system, the collected network element data.

25. The network sensor of claim 21 , wherein the network sensor is further configured to:

probe a wireless device in the wireless environment; and

identify, based at least on the probing, the wireless device; and

send, to the control system, the identification of the wireless device.

26. The network sensor of claim 21 , wherein the network sensor is further configured to:

identify, based on the collected wireless traffic data, sensitive data being transmitted in the wireless environment; and

send, to the control system, the identification of the transmitted sensitive data.

27. The network sensor of claim 21 , wherein the network sensor is further configured to perform at least one of: disconnect an active connection in real-time, block a device from connecting to a network of the wireless environment, generate an alert, modify configuration of a device, and contain a device outside of a network of the wireless environment.

28. The network sensor of claim 21 , wherein the wireless environment further includes a wireless device, wherein the network sensor is further configured to:

collect data related to the wireless device;

determine, based on the collected wireless device data, a geographical location of the wireless device; and

send, to the control system, the determined geographical location.

29. The network sensor of claim 21 , wherein the network sensor is further configured to:

check if the wireless entity meets the security policy based on the collected at least wireless traffic data, wherein the security policy is enforced when the wireless entity meets the security policy, wherein the network sensor is further configured to perform at least one of: performing at least one mitigation action, logging a detected incident, and initiating a probe of the wireless entity.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Apr 21, 2026
From: HERCULES CAPITAL, INC.
To: ARMIS SECURITY LTD; ARMIS INC.
Reel/Frame 075477/0965 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 5, 2024
From: ARMIS SECURITY LTD.
To: HERCULES CAPITAL, INC., AS ADMINISTRATIVE AND COLLATERAL AGENT
Reel/Frame 066740/0499 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2017
From: SCHWARTZ, TOMER; IZRAEL, NADIR
To: ARMIS SECURITY LTD.
Reel/Frame 042842/0810 →
Cited By (5)
US 12,301,632 US 12,470,593 US 12,572,846 US 12,574,399 US 12,695,752