IP Library Granted Patent US 10,524,130
Granted Patent B2
US 10,524,130 · App. 15/649,548 · Granted Dec 31, 2019

Threat index based WLAN security and quality of service

Inventors: Senthilraj Shanmugavadivel (Coimbatore, IN); Dirk Bolte (Birkenfeld, DE); Shail Talati (Santa Clara, CA)
Assignee: Sophos Limited
H04W12/08H04L63/10H04L63/1441H04L63/20H04W12/12H04W72/04H04L63/0272H04W84/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,524,130
App. No.
15/649,548
Granted
Dec 31, 2019
Kind
B2
Abstract

Implementations generally relate methods, systems, and computer readable media for providing threat index based wireless local area networks (WLAN) security and quality of service. In one implementation, a method includes receiving a request from a client device connected to a network via a network link. The method further includes determining a threat index value for the client device. The method further includes determining one or more security policies associated with one or more respective network resources, where each security policy applies one or more rules for allocating one of the network resources. The method further includes determining allocation of one or more of the network resources to the client device based on the one or more security policies and the threat index value.

Claims (36)

1. A computer-implemented method comprising:

receiving a request from a client device connected to a network via a wireless link, wherein the request is communicated from the client device over the wireless link to a wireless access point;

determining, by the wireless access point, a threat index value for the client device, wherein the threat index value is determined based on one or more radio frequency (RF) characteristics of the client device communicating over the wireless link and a reliability index value associated with the client device, wherein the one or more RF characteristics comprise an angle of arrival, a beamforming characteristic, or a received signal strength indicator (RSSI);

determining one or more security policies associated with one or more respective network resources, wherein each security policy applies one or more rules for allocating one of the network resources; and

determining allocation of one or more of the network resources to the client device based on the one or more security policies and the threat index value.

2. The method of claim 1 , wherein the determining the threat index value for the client device by the wireless access point comprises:

monitoring, by the wireless access point, the one or more RE characteristics of the client device communicating over the wireless link; and

comparing the one or more RF characteristics to baseline characteristics.

3. The method of claim 1 , wherein the reliability index value is based on one or more physical characteristics of the client device.

4. The method of claim 1 , wherein one of the network resources includes virtual local area network (VLAN) assignments, and wherein the method further comprises applying one of the security policies to the VLAN assignments based on the threat index value.

5. The method of claim 1 , wherein one of the network resources includes airtime, and wherein the method further comprises applying one of the security policies to airtime allocation based on the threat index value.

6. The method of claim 1 , wherein one of the network resources includes band steering, and wherein the method further comprises applying one of the security policies to the band steering based on the threat index value.

7. The method of claim 1 , wherein one of the network resources includes service set identifier (SSID) steering, and wherein the method further comprises applying one of the security policies to the SSID steering based on the threat index value.

8. A system comprising:

one or more processors coupled to a computer-readable medium having stored thereon software instructions that, when executed by the one or more processors, cause the one or more processors to perform operations including:

receiving a request from a client device connected to a network via a wireless link to a wireless access point, wherein the request is communicated from the client device over the wireless link;

determining a threat index value for the client device, wherein the threat index value is determined based on one or more radio frequency (RF) characteristics of the client device communicating over the wireless link and a reliability index value associated with the client device, wherein the one or more RF characteristics comprise an angle of arrival, a beamforming characteristic, or a received signal strength indicator (RSSI);

determining one or more security policies associated with one or more respective network resources, wherein each security policy applies one or more rules for allocating one of the network resources; and

determining allocation of one or more of the network resources to the client device based on the one or more security policies and the threat index value.

9. The system of claim 8 , wherein determining the threat index value for the client device comprises:

monitoring the one or more RF characteristics of the client device communicating over the wireless link; and

comparing the one or more RF characteristics to baseline RF characteristics.

10. The system of claim 8 , wherein one of the network resources includes virtual local area network (VLAN) assignments, and wherein the operations further comprise applying one of the security policies to the VLAN assignments based on the threat index value.

11. The system of claim 8 , wherein one of the network resources includes airtime, and wherein the operations further comprise applying one of the security policies to airtime allocation based on the threat index value.

12. The system of claim 8 , wherein one of the network resources includes band steering, and wherein the operations further comprise applying one of the security policies to the band steering based on the threat index value.

13. The system of claim 8 , wherein one of the network resources includes service set identifier (SSID) steering, and wherein the operations further comprise applying one of the security policies to the SSID steering based on the threat index value.

14. A non-transitory computer-readable medium having stored thereon software instructions that, when executed by one or more processors, cause the one or more processors to perform operations including;

receiving a request from a client device connected to a network via a wireless link to a wireless access point, wherein the request is communicated from the client device over the wireless link;

determining a threat index value for the client device, wherein the threat index value is determined based on one or more radio frequency (RF) characteristics of the client device communicating over the wireless link and a reliability index value associated with the client device, wherein the one or more RF characteristics comprise an angle of arrival, a beamforming characteristic, or a received signal strength indicator (RSSI);

determining one or more security policies associated with one or more respective network resources, wherein each security policy applies one or more rules for allocating one of the network resources; and

determining allocation of one or more of the network resources to the client device based on the one or more security policies and the threat index value.

15. The non-transitory computer-readable medium of claim 14 , wherein determining the threat index value for the client device comprises:

monitoring, by the wireless access point, the one or more RF characteristics of the client device communicating over the wireless link; and

comparing the one or more RF characteristics to baseline RF characteristics.

16. The non-transitory computer-readable medium of claim 14 , wherein one of the network resources includes virtual local area network (VLAN) assignments, and wherein the operations further comprise applying one of the security policies to the VLAN assignments based on the threat index value.

17. The non-transitory computer-readable medium of claim 14 , wherein one of the network resources includes airtime, and wherein the operations further comprise applying one of the security policies to airtime allocation based on the threat index value.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2017
From: SHANMUGAVADIVEL, SENTHILRAJ; BOLTE, DIRK; TALATI, SHAIL
To: SOPHOS LIMITED
Reel/Frame 043194/0419 →
Continuity (1)
Related Publication 20190021004A1 · Jan 17, 2019