IP Library Granted Patent US 11,463,882
Granted Patent B2
US 11,463,882 · App. 16/848,806 · Granted Oct 4, 2022

Endpoint-controlled rogue AP avoidance + rogue AP detection using synchronized security

Inventors: Anil Kaushik (Karnataka, IN); Andrew J. Thomas (Abingdon, GB); Shail Talati (Santa Clara, CA); Dirk Bolte (Bade-Wuerttemberg, DE)
Assignee: Sophos Limited
H04W12/122H04W64/003H04L63/20H04W88/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,463,882
App. No.
16/848,806
Granted
Oct 4, 2022
Kind
B2
Abstract

Methods, systems and computer readable media for rogue access point detection are described.

Claims (46)

1. A computer-implemented method, comprising:

obtaining, by a threat management system, respective wireless access point (AP) locations corresponding to one or more wireless access points;

receiving, by the threat management system, one or more network status messages that include wireless access point information received by one or more endpoint devices;

determining, by the threat management system, whether a discrepancy exists between the one or more access point locations and the wireless access point information; and

if it is determined that the discrepancy exists:

sending, from the threat management system, one or more parameters to one or more selected access points from among the one or more access points, wherein the one or more selected access points are selected from among access points registered with the threat management system and the one or more parameters cause the one or more selected access points to modify an operational aspect;

receiving, at the threat management system, one or more subsequent status messages containing subsequent access point information received by one or more endpoint devices;

programmatically analyzing, at the threat management system, the subsequent access point information to identify a rogue access point, wherein the rogue access point is identified as an access point that did not modify the operational aspect according to the one or more parameters sent by the threat management system; and

performing, at the threat management system, one or more actions to restrict the rogue access point.

2. The computer-implemented method of claim 1 , wherein the one or more network status messages are transmitted to the threat management system from the one or more endpoint devices.

3. The computer-implemented method of claim 2 , wherein the access point information includes access point information corresponding to at least one access point within wireless signal range of a respective endpoint device.

4. The computer-implemented method of claim 1 , wherein the access point information includes one or more of a received signal strength indicator value, a channel, a frequency, a service set identifier, or a basic service set identifier.

5. The computer-implemented method of claim 1 , wherein the one or more parameters include one or more of a request for the selected access points to skip a given number of beacon messages, turn off for a given period of time, or reduce power while transmitting the beacon messages.

6. The computer-implemented method of claim 1 , wherein the one or more actions include transmitting an indication to one or more endpoints connected to the rogue access point and instructing the endpoint devices to terminate a connection with the rogue access point, or restricting, at the threat management system, the rogue access point from accessing network resources or connections.

7. The computer-implemented method of claim 1 , wherein the one or more selected access points are selected from among access points registered with the threat management system based on the discrepancy, and wherein the one or more selected access points include one or more access points associated with the discrepancy or a location associated with the discrepancy.

8. A threat management system, comprising:

one or more processors; and

a nontransitory computer readable medium coupled to the one or more processors, the nontransitory computer readable medium having stored thereon instructions that, when executed by the one or more processors, causes the one or more processors to perform operations including:

obtaining respective wireless access point (AP) locations corresponding to one or more wireless access points;

receiving one or more network status messages that include wireless access point information received by one or more endpoint devices;

determining whether a discrepancy exists between the one or more access point locations and the wireless access point information; and

if it is determined that the discrepancy exists:

sending one or more parameters to one or more selected access points from among the one or more access points, wherein the one or more selected access points are selected from among access points registered with the threat management system and the one or more parameters cause the one or more selected access points to modify an operational aspect;

receiving one or more subsequent status messages containing subsequent access point information received by one or more endpoint devices;

programmatically analyzing the subsequent access point information to identify a rogue access point; and

performing one or more actions to restrict the rogue access point.

9. The threat management system of claim 8 , wherein the one or more selected access points are selected from among access points registered with the threat management system based on the discrepancy, and wherein the one or more selected access points include one or more access points associated with the discrepancy or a location associated with the discrepancy.

10. The threat management system of claim 9 , wherein the one or more access point locations are obtained during a registration process in which the one or more access points register with the threat management system.

11. The threat management system of claim 8 , wherein the access point information includes one or more of a received signal strength indicator value, a channel, a frequency, a service set identifier, or a basic service set identifier.

12. The threat management system of claim 8 , wherein the one or more parameters include one or more of a request for the access points to skip a given number of beacon messages, turn off for a given period of time, or reduce power while transmitting the beacon.

13. The threat management system of claim 8 , wherein the one or more actions include informing one or more endpoints connected to the rogue access point and instructing the endpoints to terminate an interface with the rogue access point, or restricting, at the threat management system, the rogue access point from accessing any network resources or connections.

14. The threat management system of claim 8 , wherein the rogue access point is identified as an access point that did not modify the operational aspect according to the one or more parameters sent by the threat management system.

15. A nontransitory computer readable medium having stored thereon software instructions that, when executed by one or more processors, causes the one or more processors to perform operations including:

obtaining respective wireless access point (AP) locations corresponding to one or more wireless access points;

receiving one or more network status messages that include wireless access point information received by one or more endpoint devices;

determining whether a discrepancy exists between the one or more access point locations and the wireless access point information; and

if it is determined that the discrepancy exists:

sending one or more parameters to one or more selected access points from among the one or more access points, wherein the one or more selected access points are selected from among access points registered with a threat management system and the one or more parameters cause the one or more selected access points to modify an operational aspect;

receiving one or more subsequent status messages containing subsequent access point information received by one or more endpoint devices;

programmatically analyzing the subsequent access point information to identify a rogue access point, wherein the rogue access point is identified as an access point that did not modify the operational aspect according to the one or more parameters; and

performing one or more actions to restrict the rogue access point.

16. The nontransitory computer readable medium of claim 15 , wherein the one or more selected access points are selected from among access points registered with the threat management system based on the discrepancy, and wherein the one or more selected access points include one or more access points associated with the discrepancy or a location associated with the discrepancy.

17. The nontransitory computer readable medium of claim 16 , wherein the one or more access point locations are obtained during a registration process in which one or more access points register with the threat management system.

18. The nontransitory computer readable medium of claim 15 , wherein the access point information includes one or more of a received signal strength indicator value, a channel, a frequency, a service set identifier, or a basic service set identifier.

19. The nontransitory computer readable medium of claim 15 , wherein the one or more parameters include one or more of a request for access points to skip a given number of beacon messages, turn off for a given period of time, or reduce power while transmitting the beacon.

20. The nontransitory computer readable medium of claim 15 , wherein the one or more actions include informing one or more endpoints connected to the rogue access point and instructing the endpoints to terminate an interface with the rogue access point, or restricting, at the threat management system, the rogue access point from accessing any network resources or connections.

Assignments (2)
SECURITY INTEREST Recorded Mar 15, 2021
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 055593/0624 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2020
From: KAUSHIK, ANIL; THOMAS, ANDREW J.; TALATI, SHAIL; BOLTE, DIRK
To: SOPHOS LIMITED
Reel/Frame 054068/0661 →
Priority Claims (1)
IN 201911015604 · Apr 18, 2019 · national
Continuity (1)
Related Publication 20200336914A1 · Oct 22, 2020