IP Library Granted Patent US 11,412,384
Granted Patent B1
US 11,412,384 · App. 16/591,741 · Granted Aug 9, 2022

Incident detection and response using wireless access point data

Inventors: John Robert Southern (Toronto, CA); Jack Matthew Heysel (Toronto, CA); Tyler Stiller (Lovettsville, MA); Kasra Asadzadeh (Toronto, CA); Sharon Katz (Toronto, CA)
Assignee: Rapid7, Inc.
H04W12/122H04W12/63H04W64/003H04W88/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,412,384
App. No.
16/591,741
Granted
Aug 9, 2022
Kind
B1
Abstract

Disclosed herein are methods, systems, and processes to detect rogue wireless access points and determine their approximate location in a geospatial location. Wireless access point data collected from wireless access points by fixed sensor nodes and agent-based sensor nodes in a geospatial location is received. A wireless site survey is performed at the geospatial location based on the wireless access point data. Based on the wireless site survey, an approximate location of a rogue wireless access point at the geospatial location is determined.

Claims (66)

1. A computer-implemented method, comprising:

receiving wireless access point (WAP) data associated with wireless access points from fixed sensor nodes that provide a first part of the WAP data at a periodic interval and agent-based sensor nodes that provide a second part of the WAP data at a non-synchronized interval, wherein

the WAP data comprises a Service Set Identifier (SSID), a Basic Service Set Identifier (BSSID), and a Receive Signal Strength Indicator (RSSI) for each wireless access point;

performing a wireless site survey at a geospatial location based on the WAP data, wherein

the agent-based sensor nodes are mobile within the geospatial location to improve spatial resolution by filling one or more coverage gaps missed by the fixed sensor nodes as part of the wireless site survey; and

based on the wireless site survey:

generating a visualization indicating a coverage area of each of the wireless access points in the geospatial location, and

generating an alert indicating an approximate location at the geospatial location, of a rogue wireless access point that is one of the wireless access points.

2. The computer-implemented method of claim 1 , wherein for each wireless access point, the WAP data further comprises at least a channel number, an encryption type, and a hidden status.

3. The computer-implemented method of claim 2 , wherein performing the wireless site survey comprises:

accessing a floor plan for the geospatial location, and

mapping the RSSI for a wireless access point as indicated by one or more fixed sensor nodes and one or more agent-based sensor nodes.

4. The computer-implemented method of claim 3 , wherein determining the approximate location of the rogue wireless access point comprises:

accessing a set of trusted wireless access points, and

identifying a wireless access point that shares an SSID but not a BSSID with one or more of the trusted wireless access points.

5. The computer-implemented method of claim 4 , further comprising:

designating the wireless access point as the rogue wireless access point; and

indicating the approximate location of the rogue wireless access point on the floor plan.

6. The computer-implemented method of claim 2 , further comprising:

classifying the each wireless access point into one of the following classes: a trusted class for customer managed wireless access points, a trusted class for non-customer managed wireless access points, an untrusted class for non-customer managed wireless access points, a malicious class for the wireless access point, and a malicious class for all other wireless access points.

7. A non-transitory computer readable storage medium comprising program instructions executable to:

receive wireless access point (WAP) data associated with wireless access points from fixed sensor nodes that provide a first part of the WAP data at a periodic interval and agent-based sensor nodes that provide a second part of the WAP data at a non-synchronized interval, wherein

the WAP data comprises a Service Set Identifier (SSID), a Basic Service Set Identifier (BSSID), and a Receive Signal Strength Indicator (RSSI) for each wireless access point;

perform a wireless site survey at a geospatial location based on the WAP data, wherein

the agent-based sensor nodes are mobile within the geospatial location to improve spatial resolution by filling one or more coverage gaps missed by the fixed sensor nodes as part of the wireless site survey; and

based on the wireless site survey:

generate a visualization indicating a coverage area of each of the wireless access points in the geospatial location, and

generate an alert indicating an approximate location at the geospatial location, of a rogue wireless access point that is one of the wireless access points.

8. The non-transitory computer readable storage medium of claim 7 , wherein

for each wireless access point, the WAP data further comprises at least a channel number, an encryption type, and a hidden status.

9. The non-transitory computer readable storage medium of claim 8 , wherein

performing the wireless site survey comprises:

accessing a floor plan for the geospatial location, and

mapping the RSSI for a wireless access point as indicated by one or more fixed sensor nodes and one or more agent-based sensor nodes.

10. The non-transitory computer readable storage medium of claim 9 , wherein

determining the approximate location of the rogue wireless access point comprises:

accessing a set of trusted wireless access points, and

identifying a wireless access point that shares an SSID but not a BSSID with one or more of the trusted wireless access points.

11. The non-transitory computer readable storage medium of claim 10 , further comprising:

designating the wireless access point as the rogue wireless access point; and

indicating the approximate location of the rogue wireless access point on the floor plan.

12. The non-transitory computer readable storage medium of claim 8 , further comprising:

classifying the each wireless access point into one of the following classes: a trusted class for customer managed wireless access points, a trusted class for non-customer managed wireless access points, an untrusted class for non-customer managed wireless access points, a malicious class for the wireless access point, and a malicious class for all other wireless access points.

13. A system comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

receive wireless access point (WAP) data associated with wireless access points from fixed sensor nodes that provide a first part of the WAP data at a periodic interval and agent-based sensor nodes that provide a second part of the WAP data at a non-synchronized interval, wherein

the WAP data comprises a Service Set Identifier (SSID), a Basic Service Set Identifier (BSSID), and a Receive Signal Strength Indicator (RSSI) for each wireless access point;

perform a wireless site survey at a geospatial location based on the WAP data, wherein the agent-based sensor nodes are mobile within the geospatial location to improve spatial resolution by filling one or more coverage gaps missed by the fixed sensor nodes as part of the wireless site survey; and

based on the wireless site survey:

generate a visualization indicating a coverage area of each of the wireless access points in the geospatial location, and

generate an alert indicating an approximate location at the geospatial location, of a rogue wireless access point that is one of the wireless access points.

14. The system of claim 13 , wherein

for each wireless access point, the WAP data further comprises at least a Service Set Identifier (SSID), a Basic Service Set Identifier (BSSID), a Receive Signal Strength Indicator (RSSI), a channel number, an encryption type, and a hidden status.

15. The system of claim 14 , wherein

performing the wireless site survey comprises:

accessing a floor plan for the geospatial location, and mapping the RSSI for a wireless access point as indicated by one or more fixed sensor nodes and one or more agent-based sensor nodes.

16. The system of claim 15 , wherein

determining the approximate location of the rogue wireless access point comprises:

accessing a set of trusted wireless access points, and

identifying a wireless access point that shares an SSID but not a BSSID with one or more of the trusted wireless access points.

17. The system of claim 16 , further comprising:

designating the wireless access point as the rogue wireless access point; and

indicating the approximate location of the rogue wireless access point on the floor plan.

18. The system of claim 13 , further comprising:

classifying the each wireless access point into one of the following classes: a trusted class for customer managed wireless access points, a trusted class for non-customer managed wireless access points, an untrusted class for non-customer managed wireless access points, a malicious class for the wireless access point, and a malicious class for all other wireless access points.

Assignments (4)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7, INC.
Reel/Frame 069785/0328 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2020
From: ASADZADEH, KASRA; HEYSEL, JACK MATTHEW; KATZ, SHARON; SOUTHERN, JOHN; STILLER, TYLER
To: RAPID7, INC.
Reel/Frame 053756/0334 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7, INC.
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052489/0939 →
Cited By (1)
US 12,621,331