IP Library Granted Patent US 8,392,990
Granted Patent B2
US 8,392,990 · App. 12/824,928 · Granted Mar 5, 2013

Mitigating excessive operations attacks in a wireless communication network

Inventors: Snthilraj Shanmugavadivel (Tamil Nadu, IN); Vinodh Kumar (Tamil Nadu, IN); Srinvasan K. Thirukonda (Karnataka, IN)
Assignee: Symbol Technologies, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,392,990
App. No.
12/824,928
Granted
Mar 5, 2013
Kind
B2
Abstract

A technique for mitigating excessive operations attacks in a wireless communication network includes receiving message requests from stations, detecting an excessive operation attack, checking if a received request is a first request or a retry request, and ignoring any first requests. The method can also include saving information about the first request, and wherein if checking reveals that the received request is a retry request, the method further confirms that the retry request and the saved information about the first request meet matching conditions, whereupon the retry request is further processed as normal. Since attacks rarely utilize retry requests, this technique effectively ignores attack messages.

Claims (28)

1. A method to mitigate excessive operations attacks in a wireless communication network, the method comprising:

receiving message requests at an access node in wireless management frames from stations;

detecting a number of short, concurrent message requests in wireless management frames causing a denial-of-service attack, whereupon;

checking if a received request has a retry bit that is set and that the request is the same as a previous request, whereupon the access node accepts the request; and

ignoring and storing any requests having a retry bit that is not set.

2. The method of claim 1 , further comprising retrying a wireless management frame if an acknowledgement is not received for a valid frame.

3. The method of claim 1 , wherein ignoring includes saving information about the first request, and wherein if checking reveals that the received request is a retry request, further comprising confirming that the retry request and the saved information about the first request meet matching conditions between the first request and retry request, whereupon further processing the retry request.

4. The method of claim 3 , wherein saving includes recording at least a MAC address and a sequence number of the first request, and confirming includes confirming that a MAC address of the retry request is the same as the MAC address of the recorded information, and confirming that a sequence number of the retry request is the same as the sequence number of the recorded information.

5. The method of claim 4 , wherein saving includes recording a time stamp of the first request, and confirming includes confirming that a difference between a time stamp of the retry request and the time stamp of the recorded information is within a predetermined time interval.

6. The method of claim 4 , wherein saving includes recording a request-type of the first request, and confirming includes confirming that a request-type of the retry request is the same as the request-type of the recorded information, wherein the request-type is one of the group of an authorization, and an association request.

7. The method of claim 3 , wherein confirming includes removing the saved information about the first request.

8. The method of claim 1 , wherein ignoring includes ignoring any retry requests if there is no recorded information from a corresponding first request.

9. The method of claim 1 , wherein detecting includes detecting whether the rate of requests exceeds a predetermined threshold.

10. An access node, comprising:

a transceiver operable to receive message requests in wireless management frames from stations; and

a processor coupled to the transceiver, the processor operable for detecting a number of short, concurrent message requests causing a denial-of-service attack, check if a received request has a retry bit that is set and that the request is the same as a previous request, whereupon the access node accepts the request, and ignoring and storing any requests having a retry bit that is not set.

11. The access node of claim 10 , further comprising a memory coupled to the processor, wherein the processor is also operable to record information about the first request in the memory, and wherein if the received request is a retry request, the processor is further operable to confirm that the retry request and the saved information about the first request meet matching conditions, whereupon the processor will further process the retry request.

12. The access node of claim 11 , wherein the information includes at least a MAC address and a sequence number of the first request, and the processor can confirm that a MAC address of the retry request is the same as the MAC address of the recorded information, and confirm that a sequence number of the retry request is the same as the sequence number of the recorded information.

13. The access node of claim 12 , wherein the information also includes a time stamp of the first request, and the processor can confirm that a difference between a time stamp of the retry request and the time stamp of the recorded information is within a predetermined time interval.

14. The access node of claim 12 , wherein the information also includes a request-type of the first request, and the processor can confirm that a request-type of the retry request is the same as the request-type of the recorded information, wherein the request-type is one of the group of an authorization, and an association request.

15. The access node of claim 10 , wherein the processor can ignore any retry requests if there is no recorded information from a corresponding first request.

16. The access node of claim 10 , wherein the processor is further operable to detect whether the rate of requests exceeds a predetermined threshold.

17. A method to mitigate excessive operations attacks in a wireless communication network, the method comprising:

receiving message requests at an access node in wireless management frames from stations;

detecting a number of short, concurrent message requests in wireless management frames causing a denial-of-service attack;

checking if a received request has a retry bit that is set and that the request is the same as a previous request, whereupon the access node accepts the request; wherein

if the received request has a retry bit that is not set, ignoring the first request and saving information about the first request, and

if the received request has a retry bit that is set, confirming that the retry request and the saved information about the first request meet matching conditions, whereupon further processing the retry request.

Assignments (14)
RELEASE OF PATENT AND TRADEMARK SECURITY INTEREST AT REEL/FRAME NO. 46050/0546 Recorded Jul 30, 2026
From: BANK OF MONTREAL, AS AGENT
To: EXTREME NETWORKS, INC.
Reel/Frame 076081/0088 →
SECURITY INTEREST Recorded Jul 29, 2026
From: EXTREME NETWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 076078/0590 →
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2016
From: SYMBOL TECHNOLOGIES, LLC
To: EXTREME NETWORKS, INC.
Reel/Frame 040579/0410 →
AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2016
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 040521/0762 →
RELEASE OF SECURITY INTEREST Recorded Aug 17, 2015
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 036371/0738 →
CHANGE OF NAME Recorded Jul 8, 2015
From: SYMBOL TECHNOLOGIES, INC.
To: SYMBOL TECHNOLOGIES, LLC
Reel/Frame 036083/0640 →
SECURITY AGREEMENT Recorded Oct 31, 2014
From: ZIH CORP.; LASER BAND, LLC; ZEBRA ENTERPRISE SOLUTIONS CORP.; SYMBOL TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC. AS THE COLLATERAL AGENT
Reel/Frame 034114/0270 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDRESS OF SYMBOL TECHNOLOGIES, INC. PREVIOUSLY RECORDED ON REEL 024604 FRAME 0453. ASSIGNOR(S) HEREBY CONFIRMS THE ADDRESS OF SYMBOL TECHNOLOGIES, INC. SHOULD READ ONE MOTOROLA PLAZA, HOLTSVILLE, NY 11742. Recorded Jan 30, 2013
From: SHANMUGAVADIVEL, SENTHILRAJ; KUMAR, VINODH; THIRUKONDA, SRINVASAN K.
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 029722/0078 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2010
From: SHANMUGAVADIVEL, SENTHILRAJ; KUMAR, VINODH; THIRUKONDA, SRINVASAN K.
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 024604/0453 →
Continuity (1)
Related Publication 20110321161A1 · Dec 29, 2011