IP Library Granted Patent US 7,823,199
Granted Patent B1
US 7,823,199 · App. 10/794,203 · Granted Oct 26, 2010

Method and system for detecting and preventing access intrusion in a network

Assignee: Extreme Networks
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,823,199
App. No.
10/794,203
Granted
Oct 26, 2010
Kind
B1
Abstract

A wireless computer network includes components cooperating together to prevent access intrusions by detecting unauthorized devices connected to the network, disabling the network connections to the devices, and then physically locating the devices. The network can detect both unauthorized client stations and unauthorized edge devices such as wireless access points (APs). The network can detect intruders by monitoring information transferred over wireless channels, identifying protocol state machine violations, tracking roaming behavior of clients, and detecting network addresses being improperly used in multiple locations. Upon detecting an intruder, the network can automatically locate and shut off the physical/logical port to which the intruder is connected.

Claims (36)

1. In a system comprising one or more network switches that communicate with a network manager through a network using a standard network protocol, the one or more switches having a plurality of ports connected to a plurality of authorized wireless edge devices that permit a plurality of mobile, client stations to access the network over one or more wireless channels, and the network manager running application software that allows a network administrator to configure the ports of the one or more switches and the plurality of authorized wireless edge devices to facilitate communication over the network, a system for preventing access intrusion to the network by an unauthorized wireless edge device connected to or attempting to connect to one of the ports comprising:

the one or more switches and the plurality of authorized wireless edge devices configured, by running intrusion detection application software, to (1) collect information transmitted over the one or more wireless channels, (2) record such information in one or more statistics databases resident on the one or more switches, and (3) periodically update such information as mobile, client stations roam throughout the network;

the network manager configured, by running network-wide analysis application software, to (1) periodically query, using the standard network protocol, the one or more statistics databases resident on the one or more switches for collected information transmitted over the one or more wireless channels, and (2) record the queried information in a network-wide database resident on the network manager;

the network manager further configured, by running the network-wide analysis application software, to apply algorithms to the information stored in the network-wide database resident on the network manager to detect access intrusion to the network by the unauthorized wireless edge device connected to one of the ports; and

the network manager further configured to, when access intrusion by the unauthorized wireless edge device is so detected, (1) locate the port to which the unauthorized wireless edge device is connected or attempting to connect, and (2) transmit a command to the switch containing the port, using the standard network protocol, directing the switch to automatically shut down the port, thereby denying network access to the unauthorized wireless edge device, even when the unauthorized wireless edge device does not adhere to IEEE 802.11 protocol conventions.

2. The system of claim 1 wherein the plurality of authorized wireless edge devices includes one or more wireless access points.

3. The system of claim 1 wherein the plurality of authorized wireless edge devices includes one or more sniffing access points.

4. The system of claim 1 wherein either or both the one or more switches and the plurality of authorized wireless edge devices are configured to collect the information by monitoring beacon frames emitted by the unauthorized wireless edge device.

5. The system of claim 1 wherein either or both the one or more switches and the plurality of authorized wireless edge devices are configured to collect the information by:

transmitting a probe request; and

detecting a probe response from the unauthorized wireless edge device.

6. The system of claim 1 wherein either or both the one or more switches and the plurality of authorized wireless edge devices are configured collect the information by:

monitoring packet information transmitted on a wireless channel used by the unauthorized wireless edge device.

7. The system of claim 1 wherein the network manager is configured to locate the port connected to the unauthorized wireless edge device by:

triangulating on location attributes of the unauthorized wireless edge device to determine the geographic location of the device.

8. The system of claim 1 wherein the unauthorized wireless edge device has a MAC address, a SSID, and security policies, and the network manager is configured to detect the unauthorized wireless edge device by checking one or more of the following:

whether the MAC address is from an approved vendor;

whether the SSID is from a list of supported SSIDs; and

whether the security policies match the network administrator's security policies.

9. In a system comprising one or more network switches that communicate with a network manager through a network using a standard network protocol, the one or more switches having a plurality of ports connected to a plurality of authorized wireless edge devices that permit a plurality of mobile, client stations to access the network over one or more wireless channels, and the network manager running application software that allows a network administrator to configure the ports of the one or more switches and the plurality of authorized wireless edge devices to facilitate communication over the network, a method of preventing access intrusion to the network by an unauthorized wireless edge device connected to or attempting to connect to one of the ports comprising:

in or by the one or more network switches and the plurality of authorized wireless edge devices running intrusion detection application software, (1) collecting information transmitted over the one or more wireless channels, (2) recording such information in one or more statistics databases resident on the one or more switches, and (3) periodically updating such information as mobile, client stations roam throughout the network; and

in or by the network manager running network-wide analysis application software, (1) periodically querying, using the standard network protocol, the one or more statistics databases resident on the one or more switches for collected information transmitted over the one or more wireless channels; (2) recording the queried information in a network-wide database resident on the network manager; (3) applying algorithms to the information stored in the network-wide database resident on the network manger, thereby detecting access intrusion to the network by the unauthorized wireless edge device connected to one of the ports; (4) locating the port to which the unauthorized wireless edge device is connected or attempting to connect, and (5) transmitting a command to the switch containing the port, using the standard network protocol, directing the switch to automatically shut down the port, thereby denying network access to the unauthorized wireless edge device, even when the unauthorized wireless edge device does not adhere to IEEE 802.11 protocol conventions.

10. The method of claim 1 wherein the plurality of authorized wireless edge devices include one or more wireless access points.

11. The method of claim 1 wherein the plurality of authorized wireless edge devices includes one or more sniffing access points.

12. The method of claim 1 wherein the collecting step comprises collecting the information by monitoring beacon frames emitted by the unauthorized wireless edge device.

13. The method of claim 1 wherein the collecting step comprises:

transmitting a probe request; and

detecting a probe response from the unauthorized wireless edge device.

14. The method of claim 1 wherein the collecting step comprises:

monitoring packet information transmitted on a wireless channel used by the unauthorized wireless edge device.

15. The method of claim 1 wherein the locating step comprises:

triangulating on location attributes of the unauthorized wireless edge device to determine the geographic location of the device.

16. The method of claim 1 wherein the unauthorized wireless edge device has a MAC address, a SSID, and security policies, and the detecting comprises the network manager detecting the unauthorized wireless edge device by checking one or more of the following:

whether the MAC address is from an approved vendor;

whether the SSID is from a list of supported SSIDs; and

whether the security policies match the network administrator's security policies.

Assignments (10)
RELEASE OF PATENT AND TRADEMARK SECURITY INTEREST AT REEL/FRAME NO. 46050/0546 Recorded Jul 30, 2026
From: BANK OF MONTREAL, AS AGENT
To: EXTREME NETWORKS, INC.
Reel/Frame 076081/0088 →
SECURITY INTEREST Recorded Jul 29, 2026
From: EXTREME NETWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 076078/0590 →
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2016
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 040521/0762 →
SECURITY AGREEMENT Recorded Jul 27, 2015
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 036189/0284 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2004
From: RATHI, MANISH M.; JAIN, VIPIN K.; MERCHANT, SHEHZAD T.; LIN, VICTOR C.
To: EXTREME NETWORKS
Reel/Frame 015474/0692 →
Continuity (3)
Continuation In Part 1077407900 · Feb 6, 2004
Continuation In Part 1077348700 · Feb 6, 2004
Continuation In Part 1077339400 · Feb 6, 2004