IP Library › Granted Patent US 11,924,643
Granted Patent B2
US 11,924,643 · App. 17/887,680 · Granted Mar 5, 2024

Point-controlled rogue AP avoidance + rogue AP detection using synchronized security

Inventors: Anil Kaushik (Karnataka, IN); Andrew J. Thomas (Abingdon, GB); Shail Talati (Santa Clara, CA); Dirk Bolte (Bade-Wuerttemberg, DE)
Assignee: Sophos Limited
H04W12/122H04W64/003H04L63/20H04W88/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,924,643
App. No.
17/887,680
Granted
Mar 5, 2024
Kind
B2
Abstract

Methods, systems and computer readable media for rogue access point detection are described.

Claims (34)

1. A computer-implemented method, comprising:

sending, from a threat management system, one or more parameters to one or more selected access points from a set of one or more access points registered with the threat management system, wherein the one or more parameters, when applied at the one or more selected access points, modify an operational aspect of the one or more selected access points;

after the sending, receiving, at the threat management system, from one or more endpoint devices one or more status messages, wherein each status message includes access point information about one or more access points that the endpoint device connects to, wherein the one or more access points include at least one selected access point and wherein the access point information is indicative of a respective operational parameter of the one or more access points;

detecting that the operational parameter of a particular access point of the one or more access points does not match the operational aspect; and

based on the detecting, performing, by the threat management system, one or more actions to restrict the particular access point.

2. The computer-implemented method of claim 1 , further comprising selecting the one or more selected access points that are associated with a particular location.

3. The computer-implemented method of claim 2 , wherein selecting the one or more selected access points comprises selecting all access points located at a particular facility.

4. The computer-implemented method of claim 1 , wherein the particular access point is classified as a rogue access point, and wherein prior to the sending, the rogue access point and the one or more selected access points have similar operational states.

5. The computer-implemented method of claim 1 , wherein the one or more parameters includes a channel, a roaming feature, or a beacon transmit power.

6. The computer-implemented method of claim 1 , wherein performing the one or more actions comprises restricting the particular access point from accessing a network resource.

7. The computer-implemented method of claim 1 , wherein performing the one or more actions comprises providing a command to one or more endpoint devices to terminate an interface with the particular access point.

8. A threat management system, comprising:

one or more processors; and

a nontransitory computer readable medium coupled to the one or more processors, the nontransitory computer readable medium having stored thereon instructions that, when executed by the one or more processors, causes the one or more processors to perform operations including:

sending, from a threat management system, one or more parameters to one or more selected access points from a set of one or more access points registered with the threat management system, wherein the one or more parameters, when applied at the [[the]] one or more selected access points, modify an operational aspect of the one or more selected access points;

after the sending, receiving, at the threat management system, from one or more endpoint devices one or more status messages, wherein each status message includes access point information about one or more access points that the endpoint device connects to, wherein the one or more access points include at least one selected access point and wherein the access point information is indicative of a respective operational parameter of the one or more access points;

detecting that the operational parameter of a particular access point of the one or more access points does not match the operational aspect; and

based on the detecting, performing, by the threat management system, one or more actions to restrict the particular access point.

9. The threat management system of claim 8 , wherein the operations further comprise selecting the one or more selected access points that are associated with a particular location.

10. The threat management system of claim 9 , wherein selecting the one or more selected access points comprises selecting all access points located at a particular facility.

11. The threat management system of claim 8 , wherein the particular access point is classified as a rogue access point, and wherein prior to the sending, the rogue access point and the one or more selected access points have similar operational states.

12. The threat management system of claim 8 , wherein the one or more parameters includes a channel, a roaming feature, or a beacon transmit power.

13. The threat management system of claim 8 , wherein performing the one or more actions comprises restricting the particular access point from accessing a network resource.

14. The threat management system of claim 8 , wherein performing the one or more actions comprises providing a command to one or more endpoint devices to terminate an interface with the particular access point.

15. A nontransitory computer readable medium having stored thereon software instructions that, when executed by one or more processors, causes the one or more processors to perform operations including:

sending, from a threat management system, one or more parameters to one or more selected access points from a set of one or more access points registered with the threat management system, wherein the one or more parameters, when applied at the one or more selected access points, modify an operational aspect of the one or more selected access points;

after the sending, receiving, at the threat management system, from one or more endpoint devices one or more status messages, wherein each status message includes access point information about one or more access points that the endpoint device connects to, wherein the one or more access points include at least one selected access point and wherein the access point information is indicative of a respective operational parameter of the one or more access points;

detecting that the operational parameter of a particular access point of the one or more access points does not match the operational aspect; and

based on the detecting, performing, by the threat management system, one or more actions to restrict the particular access point.

16. The nontransitory computer readable medium of claim 15 , wherein the operations further comprise selecting the one or more selected access points that are associated with a particular location.

17. The nontransitory computer readable medium of claim 16 , wherein selecting the one or more selected access points comprises selecting all access points located at a particular facility.

18. The nontransitory computer readable medium of claim 15 , wherein the particular access point is classified as a rogue access point, and wherein prior to the sending, the rogue access point and the one or more selected access points have similar operational states.

19. The nontransitory computer readable medium of claim 15 , wherein the one or more parameters includes a channel, a roaming feature, or a beacon transmit power.

20. The nontransitory computer readable medium of claim 15 , wherein performing the one or more actions comprises providing a command to one or more endpoint devices to terminate an interface with the particular access point.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 15, 2023
From: KAUSHIK, ANIL; THOMAS, ANDREW J.; TALATI, SHAIL; BOLTE, DIRK
To: SOPHOS LIMITED
Reel/Frame 062706/0984 →
Priority Claims (1)
IN 201911015604 · Apr 18, 2019 · national
Continuity (2)
Continuation 16848806 · Apr 14, 2020
Related Publication 20220394480A1 · Dec 8, 2022
Cited By (1)
US 12,621,886