EP1522020B1

System for managing wireless network activity

Abstract

This record has no abstract on file.

EP1522020B1, drawing sheet 1
Sheet 1 of 20

Term

Term ended

Expired 20 May 2023, 3.3 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

24 claims: 11 independent, 13 dependent

  1. 1
    A network security system, the system comprising:a) a system data store (110) capable of storing risk criteria data, network default data, and network performance and usage data;b) a first communication interface comprising a receiver that receives inbound communications from a communication channel associated with the communication interface;c) a system processor (120) comprising one or more processing elements, wherein the system processor (120) is in communication with the system data store (110) and is programmed or adapted to perform the steps of: (i) receiving (310) data corresponding to a frame transmitted over an encrypted wireless computer network and a signal used to transmit the frame via the communication interface;(ii) detecting (325, 330, 335, 340) a violation within an encrypted data stream by applying a plurality of tests that comprise a statistical anomaly test (335) that compares the received data with statistical data in the system data store (110) or information derived therefrom and performs anomaly-based detection based on the comparison between the received data and the statistical data, wherein the plurality of tests further comprise a policy test (340) that compares the received data to predetermined policy, and wherein the statistical data comprises any of mean, non-zero mean, standard deviation, autocorrelation, and peak for each time slice for a plurality of thresholds;(iii) generating (345) an alarm signal if the violation was detected;wherein the first communication interface further comprises a transmitter that transmits outbound communications to the communication channel and wherein the system processor (120) is programmed or adapted to perform the step of triggering an active defense of the wireless computer network in response to a generated alarm;and wherein the triggered active defense is: 1) introducing CRC errors;2) transmitting frames comprising random data;or 3) activating a honeypot defense by: (a) determining from the received data the channel used for transmitting the signal, an access point to which the signal was directed and a station originating the signal;(b) reconfiguring the access point and authorized stations to communication using a channel other than the determined channel;and (c) interacting with the station originating the signal using the determined channel.
  2. 5
    The system of any previous claim, wherein the first communication interface's receiver receives signals corresponding to a frame transmitted between stations and access points (180) within the wireless computer network and forwards data corresponding to the frame to the system processor (120).
  3. 11
    The system of any previous claim, further comprising a device housing that houses the first communication interface and at least one processing element of the system processor (120), thereby forming a first device, and one or more additional devices, wherein each additional device comprises a housing, a device communication interface allowing communication via the communication channel and at least one processing element of the system processor (120), wherein the signals received by any of the first or the additional devices' respective communication interfaces originate from an access point within the wireless computer network, from a station within the wireless computer network, or from a different device.
  4. 13
    The system of any previous claim, wherein each generated alarm comprises a type or a severity.
  5. 16
    The system of any previous claim, wherein the system processor (120) is further programmed or adapted to perform the steps comprising of receiving (410) configuration information and storing (470) the received configuration information in the system data store (110).
  6. 19
    The system of any previous claim, wherein the system data store (110) comprises a station data store and wherein the system processor (120) is further programmed or adapted to perform the step comprising of updating the station data store based upon the received data.
  7. 20
    The system of any of claims 1-18, wherein the system data store (110) comprises an access point data store and wherein the system processor (120) is further programmed or adapted to perform the step comprising of updating the access point data store based upon the received data.
  8. 21
    The system of any previous claim, wherein the system processor (120) is further programmed or adapted to perform the step comprising of notifying (444) an administrator of the generated alarm if the violation was detected.
  9. 22
    The system of any previous claim, wherein the plurality of tests applied by the system processor (120) further comprises at least one test selected from the group consisting of signature test, and protocol test.
  10. 23
    The system of any previous claim, wherein the system processor (120) is further programmed or adapted to perform the step comprising of mapping station identity.
  11. 24
    The system of any previous claim, wherein the system processor (120) is further programmed or adapted to perform the step comprising of mapping station location.