Using cross-channel analysis to detect attacks on spread-spectrum networks
Data of a plurality of channels of a spread-spectrum network are received. For example, the data of the plurality of channels of the spread-spectrum network may be captured by a spread-spectrum router (e.g., a WiFi router). The data of the plurality of channels of the spread-spectrum network is analyzed to identify an anomalous cross-channel pattern across the plurality of channels of the spread-spectrum network. For example, the attack may be a sequential attack across each of the channels of the spread-spectrum network. In response to identifying the anomalous cross-channel pattern across the plurality of channels of the spread-spectrum network, an action is taken to protect the spread-spectrum network. For example, the action may be to notify an administrator of the spread-spectrum network that a potential attack is occurring on the spread-spectrum network or to block access to the spread-spectrum router.
1 . A system comprising:
a microprocessor; and
a computer readable medium, coupled with the microprocessor and comprising microprocessor readable and executable instructions that, when executed by the microprocessor, cause the microprocessor to:
receive data transmitted across a plurality of channels of a spread-spectrum network, the transmitted data comprising header information, the header information comprising data link layer information, network layer information, transport layer header information, session layer header information, presentation layer header information, and application layer header information, and payload information;
analyze the transmitted data of the plurality of channels of the spread-spectrum network to identify one or more cross-channel patterns defined by the transmitted data;
compare the identified one or more cross-channel patterns defined by the transmitted data against one or more known malicious cross-channel patterns to identify an anomalous cross-channel pattern across the plurality of channels of the spread-spectrum network; and
in response to identifying the anomalous cross-channel pattern across the plurality of channels of the spread-spectrum network, take an action to protect the spread-spectrum network.
2 . The system of claim 1 , wherein analyzing the data of the plurality of channels of the spread-spectrum network is done in real-time, wherein the comparing comprises comparing the one or more cross-channel patterns defined by the transmitted data against one or more learned normal cross-channel patterns to determine a variance from normal cross-channel patterns, and wherein the anomalous cross-channel pattern is based on a magnitude of the determined variance.
3 . The system of claim 2 , wherein the microprocessor readable and executable instructions further cause the microprocessor to:
capture, in real-time, the transmitted data of the plurality of channels of the spread-spectrum network; and
send, in real-time, the transmitted data of the plurality of channels of the spread-spectrum network.
4 . The system of claim 1 , wherein the anomalous cross-channel pattern comprises at least one of: a sequential cross-channel pattern, a sequential cross-channel pattern with one or more active channels, a random sequence cross-channel pattern, a random sequence channel pattern with one or more active channels, a ping cross-channel pattern, a failed connection cross-channel pattern, a changing port cross-channel pattern, a new cross-channel hopping pattern, a new inbound cross-channel connection pattern, a new outbound cross-channel connection pattern, and a Denial-of-Service (DoS) cross-channel pattern.
5 . The system of claim 4 , wherein the anomalous cross-channel pattern comprises one of: the sequential cross-channel pattern, the sequential cross-channel pattern with one or more active channels, the random sequence cross-channel pattern, the random sequence channel pattern with one or more active channels, and the failed connection cross-channel pattern, and wherein the anomalous cross-channel pattern further comprises use of a different Media Access Control (MAC) address for each individual channel that is part of the anomalous cross-channel pattern.
6 . The system of claim 1 , wherein comparing comprises comparing information in a selected one of the data link layer information, network layer information, transport layer header information, session layer header information, presentation layer header information, application layer header information and payload information in the identified anomalous cross-channel pattern to the one of the data link layer information, network layer information, transport layer header information, session layer header information, presentation layer header information, application layer header information and payload information in the one or more known malicious cross-channel patterns.
7 . The system of claim 6 , wherein the microprocessor readable and executable instructions further cause the microprocessor to:
retrieve the one or more known malicious cross-channel patterns via a malicious cross-channel pattern database, wherein the malicious cross-channel pattern database is part of a network service provided by a third-party.
8 . The system of claim 1 , wherein the microprocessor readable and executable instructions further cause the microprocessor to:
analyze historical data of the plurality of channels of the spread-spectrum network to identify one or more normal cross-channel patterns of the plurality of channels of the spread-spectrum network, and
wherein the comparing is based on identifying a variance from the one or more normal cross-channel patterns of the plurality of channels of the spread-spectrum network.
9 . The system of claim 1 , wherein the microprocessor readable and executable instructions further cause the microprocessor to:
generate for display, in a graphical user interface, a diagram that comprises at least one of a time-based view, a sequence view, and a pattern view of the anomalous cross-channel pattern.
10 . The system of claim 9 , wherein the diagram comprises the pattern view, wherein the pattern view comprises a plurality of anomalous cross-channel patterns, and wherein the plurality of anomalous cross-channel patterns comprises at least one anomalous cross-channel pattern that has a loop and at least one anomalous cross-channel pattern that does not have a loop.
11 . The system of claim 9 , wherein the diagram comprises the time-based view and wherein the time-based view comprises a plurality of different anomalous cross-channel patterns.
12 . A method comprising:
receiving, by a microprocessor, data transmitted across a plurality of channels of a spread-spectrum network, the transmitted data comprising header information, the header information comprising data link layer information, network layer information, transport layer header information, session layer header information, presentation layer header information, and application layer header information, and payload information;
analyzing, by the microprocessor, the transmitted data of the plurality of channels of the spread-spectrum network to identify one or more cross-channel patterns defined by the transmitted data;
comparing the one or more cross-channel patterns defined by the transmitted data against one or more learned normal cross-channel patterns to determine a variance from normal cross-channel patterns to identify an anomalous cross-channel pattern across the plurality of channels of the spread-spectrum network, wherein the anomalous cross-channel pattern is identified based on a magnitude of the determined variance; and
in response to identifying the anomalous cross-channel pattern across the plurality of channels of the spread-spectrum network, taking, by the microprocessor, an action to protect the spread-spectrum network.
13 . The method of claim 12 , wherein analyzing the transmitted data of the plurality of channels of the spread-spectrum network is done in real-time and further comprising:
capturing, in real-time, the transmitted data of the plurality of channels of the spread-spectrum network;
sending, in real-time, the transmitted data of the plurality of channels of the spread-spectrum network; and
comparing the identified one or more cross-channel patterns defined by the transmitted data against one or more known malicious cross-channel patterns to identify an anomalous cross-channel patter across the plurality of channels of the spread-spectrum network.
14 . The method of claim 12 , wherein the anomalous cross-channel pattern comprises at least one of: a sequential cross-channel pattern, a sequential cross-channel pattern with one or more active channels, a random sequence cross-channel pattern, a random sequence channel pattern with one or more active channels, a ping cross-channel pattern, a failed connection cross-channel pattern, a changing port cross-channel pattern, a new cross-channel hopping pattern, a new inbound cross-channel connection pattern, a new outbound cross-channel connection pattern, and a Denial-of-Service (DoS) cross-channel pattern.
15 . The method of claim 12 , wherein the comparing comprises comparing information in a selected one of the data link layer information, network layer information, transport layer header information, session layer header information, presentation layer header information, application layer header information and payload information in the identified anomalous cross-channel pattern to the one of the data link layer information, network layer information, transport layer header information, session layer header information, presentation layer header information, application layer header information and payload information in a known malicious cross-channel pattern.
16 . The method of claim 12 , further comprising:
analyzing historical data of the plurality of channels of the spread-spectrum network to identify the one or more learned normal cross-channel patterns of the plurality of channels of the spread-spectrum network, and
wherein the comparing comprises comparing information in a selected one of the data link layer information, network layer information, transport layer header information, session layer header information, presentation layer header information, application layer header information and payload information in the anomalous identified cross-channel pattern to the one of the data link layer information, network layer information, transport layer header information, session layer header information, presentation layer header information, application layer header information and payload information in the one or more learned normal cross-channel.
17 . The method of claim 12 , further comprising:
generating for display, in a graphical user interface, a diagram that comprises at least one of a time-based view, a sequence view, and a pattern view of the anomalous cross-channel pattern.
18 . The method of claim 17 , wherein the diagram comprises the pattern view, wherein the pattern view comprises a plurality of anomalous cross-channel patterns, and wherein the plurality of anomalous cross-channel patterns comprises at least one anomalous cross-channel pattern that has a loop and at least one anomalous cross-channel pattern that does not have a loop.
19 . The method of claim 17 , wherein the diagram comprises the time-based view and wherein the time-based view comprises a plurality of different anomalous cross-channel patterns.
20 . A non-transient computer readable medium having stored thereon instructions that cause a processor to execute a method, the method comprising instructions to:
receive data of a plurality of channels of a spread-spectrum network;
analyze the data of the plurality of channels of the spread-spectrum network to identify an anomalous cross-channel pattern across the plurality of channels of the spread-spectrum network;
generate for display, in a graphical user interface, a diagram that comprises at least one of a time-based view, a sequence view, and a pattern view of the anomalous cross-channel pattern, wherein the diagram comprises the pattern view, wherein the pattern view comprises a plurality of anomalous cross-channel patterns, and wherein the plurality of anomalous cross-channel patterns comprises at least one anomalous cross-channel pattern that has a loop and at least one anomalous cross-channel pattern that does not have a loop; and
in response to identifying the anomalous cross-channel pattern across the plurality of channels of the spread-spectrum network, take an action to protect the spread-spectrum network.