IP Library Granted Patent US 12,375,921
Granted Patent B2
US 12,375,921 · App. 17/835,117 · Granted Jul 29, 2025

Wireless intrusion prevention

Inventors: Jatin Parekh (Mumbai, IN); Anubhav Gupta (Jaipur, IN); Amogh Dasture (Pune, IN); Nadeem Akhtar (Navi Mumbai, IN)
Assignee: Arista Networks, Inc.
H04W12/088H04W12/009
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,375,921
App. No.
17/835,117
Granted
Jul 29, 2025
Kind
B2
Abstract

A networking system may disrupt an unauthorized wireless connection to the network. In particular, the networking system may detect a wireless connection between a client device and an unauthorized wireless access point. The networking system may receive a probe request management frame from the client device. The network system may, responsive to the detection of the wireless connection, send a probe response management frame to the client device.

Claims (30)

1. A method of disrupting an unauthorized wireless connection to a network, the method comprising:

detecting the wireless connection, wherein the wireless connection is between a client device in the network and an unauthorized wireless access point and wherein the client device is an authorized client device;

detecting a wireless local area network (WLAN) media access control (MAC) Probe Request management frame from the client device, wherein the WLAN MAC Probe Request management frame includes a header portion, a payload portion, and a frame check sequence and wherein the header portion includes a frame type field having bits indicative of a management frame and a frame subtype field having bits indicative of a type of management frame; and

responsive to detecting the wireless connection, sending a WLAN MAC Probe Response management frame to the client device.

2. The method defined in claim 1 , wherein the WLAN MAC Probe Request management frame includes a set of information elements indicating capabilities of the client device, and the WLAN MAC Probe Response management frame includes a corresponding set of information elements indicating capabilities at least matching the indicated capabilities of the client device.

3. The method defined in claim 2 , wherein the capabilities of the client device comprise a list of supported rates, and the matching capabilities indicated in the WLAN MAC Probe Response management frame comprise at least each supported rate in the list of support rates.

4. The method defined in claim 1 , wherein the WLAN MAC Probe Response management frame includes information indicative of a wireless connection parameter that is an improvement over a corresponding connection parameter offered by the unauthorized wireless access point as perceived by the client device.

5. The method defined in claim 4 , wherein the wireless connection parameter comprises at least one of a signal strength parameter, a noise level parameter, or a channel utilization parameter.

6. The method defined in claim 1 , wherein the detected wireless connection uses Management Frame Protection (MFP).

7. The method defined in claim 1 , wherein the unauthorized wireless access point is an access point connected to an additional network different from the network.

8. The method defined in claim 1 , wherein the unauthorized wireless access point is connected to the network.

9. One or more non-transitory computer-readable storage media comprising computer-executable instructions that, when executed by one or more processors for a wireless intrusion prevention system, cause the one or more processors to:

identify a control signal indicative of an external network connection between a client device and an unauthorized wireless access point, the external network connection utilizing Management Frame Protection (MFP) that encrypts communication of some types of wireless local area network (WLAN) media access control (MAC) management frames; and

send a WLAN MAC management frame to the client device, in response to the identified control signal indicative of the external network connection utilizing MFP, to disrupt the external network connection, wherein the sent WLAN MAC management frame includes a header portion, a payload portion, and a frame check sequence and wherein the header portion includes a frame type field having bits indicative of a management frame and a frame subtype field having bits indicative of a type of management frame.

10. The one or more non-transitory computer-readable storage media defined in claim 9 , wherein sending the WLAN MAC management frame to the client device comprises sending a WLAN MAC Probe Response management frame to the client device, in response to the identified control signal indicative of the external network connection utilizing MFP, to disrupt the external network connection.

11. The one or more non-transitory computer-readable storage media defined in claim 10 , wherein sending the WLAN MAC Probe Response management frame to the client device is responsive to a WLAN MAC Probe Request management frame from the client device.

12. The one or more non-transitory computer-readable storage media defined in claim 9 , wherein the identified control signal is received from a centralized controller.

13. The one or more non-transitory computer-readable storage media defined in claim 9 , wherein the identified control signal is generated internally within an authorized wireless access point.

14. The one or more non-transitory computer-readable storage media defined in claim 9 , wherein the unauthorized wireless access point is a rogue access point or an external access point.

15. A method of operating a wireless access point to disrupt an unauthorized wireless connection to a network that includes the wireless access point, the method comprising:

generating a control signal indicative of an external network connection between a client device and an external wireless access point in an external network, the external network connection utilizing Management Frame Protection (MFP); and

causing the wireless access point to send a wireless local area network (WLAN) media access control (MAC) Probe Response management frame to the client device based at least in part on the generated control signal indicative of the external network connection utilizing MFP, wherein the WLAN MAC Probe Response management frame includes a header portion, a payload portion, and a frame check sequence and wherein the header portion includes a frame type field having bits indicative of a management frame and a frame subtype field having bits indicative of a type of management frame.

16. The method defined in claim 15 further comprising:

selecting the wireless access point out of a set of wireless access points in the network to send the WLAN MAC Probe Response management frame to the client device based at least in part on capabilities of the selected wireless access point.

17. The method defined in claim 16 further comprising:

sending the generated control signal indicative of the external network connection utilizing MFP to the selected wireless access point over a wired network path.

18. The method defined in claim 15 further comprising:

determining a type of the client device and a type of the external wireless access point based at least in part on obtained sensor data, wherein generating the control signal indicative of the external network connection is based at least in part on the determined type of the client device and the determined type of the external wireless access point.

19. The method defined in claim 18 , wherein the obtained sensor data is gathered at the wireless access point.

20. The method defined in claim 19 , wherein generating the control signal indicative of the external network connection comprises generating the control signal indicative of the external network connection at the wireless access point.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2022
From: PAREKH, JATIN; GUPTA, ANUBHAV; DASTURE, AMOGH; AKHTAR, NADEEM
To: ARISTA NETWORKS, INC.
Reel/Frame 060165/0775 →
Continuity (1)
Related Publication 20230413053A1 · Dec 21, 2023
References Cited (42)
US 7002943B2 · Bhagwat et al. · 2006 [cited by applicant]
US 7154874B2 · Bhagwat et al. · 2006 [cited by applicant]
US 7216365B2 · Bhagwat et al. · 2007 [cited by applicant]
US 7333481B1 · Rawat et al. · 2008 [cited by applicant]
US 7333800B1 · Gopinath · 2008 [cited by applicant]
US 7339914B2 · Bhagwat et al. · 2008 [cited by applicant]
US 7406320B1 · Kumar et al. · 2008 [cited by applicant]
US 7440434B2 · Chaskar et al. · 2008 [cited by applicant]
US 7447184B1 · Kharvandikar et al. · 2008 [cited by applicant]
US 7496094B2 · Gopinath et al. · 2009 [cited by applicant]
US 7536723B1 · Bhagwat et al. · 2009 [cited by applicant]
US 7558253B1 · Rawat et al. · 2009 [cited by applicant]
US 7710933B1 · Sundaralingam et al. · 2010 [cited by applicant]
US 7751393B2 · Chaskar et al. · 2010 [cited by applicant]
US 7764648B2 · Gopinath et al. · 2010 [cited by applicant]
US 7804808B2 · Bhagwat et al. · 2010 [cited by applicant]
US 7856209B1 · Rawat · 2010 [cited by applicant]
US 7856656B1 · Kharvandikar et al. · 2010 [cited by applicant]
US 7970894B1 · Patwardhan · 2011 [cited by applicant]
US 7971253B1 · Gupta · 2011 [cited by applicant]
US 8032939B2 · Panitkar et al. · 2011 [cited by applicant]
US 8099107B2 · Thomson · 2012 [cited by examiner]
US 8789191B2 · Bhagwat et al. · 2014 [cited by applicant]
US 9003527B2 · Bhagwat et al. · 2015 [cited by applicant]
US 9775019B2 · Mestanov · 2017 [cited by examiner]
US 9913201B1 · Harmon · 2018 [cited by examiner]
US 10129211B2 · Heath · 2018 [cited by examiner]
US 10257779B2 · Jung · 2019 [cited by examiner]
US 10785703B1 · V · 2020 [cited by examiner]
US 11284474B1 · Chu · 2022 [cited by examiner]
US 20090016529A1 · Gopinath et al. · 2009 [cited by applicant]
US 20150012971A1 · Ram et al. · 2015 [cited by applicant]
US 20180007030A1 · Penov · 2018 [cited by examiner]
US 20190116545A1 · Verma · 2019 [cited by examiner]
US 20210045052A1 · Nellore · 2021 [cited by examiner]
US 20210112414A1 · Huang · 2021 [cited by examiner]
US 20210377369A1 · Patil · 2021 [cited by examiner]
US 20220084066A1 · Kisko · 2022 [cited by examiner]
US 20230007487A1 · Jain · 2023 [cited by examiner]
US 20230247422A1 · Lin · 2023 [cited by examiner]
US 20230300751A1 · Ficara · 2023 [cited by examiner]
Arista Networks, Inc., Review of Detection, Classification, and Prevention Techniques in WIPS, Arista.com, n.d. (2018), Arista Networks, Inc., Santa Clara, CA, United States. [cited by applicant]