发明申请
- 专利标题: Detection and management of rogue wireless network connections
- 专利标题(中): 流氓无线网络连接的检测和管理
-
申请号: US11586137申请日: 2006-10-25
-
公开(公告)号: US20070298720A1公开(公告)日: 2007-12-27
- 发明人: Alastair Wolman , Brian D. Zill , Jitendra D. Padhye , Raveer Chandra , Paramvir Bahl , Manpreet Singh , Lenin Ravindranath Sivalingam
- 申请人: Alastair Wolman , Brian D. Zill , Jitendra D. Padhye , Raveer Chandra , Paramvir Bahl , Manpreet Singh , Lenin Ravindranath Sivalingam
- 申请人地址: US WA Redmond
- 专利权人: Microsoft Corporation
- 当前专利权人: Microsoft Corporation
- 当前专利权人地址: US WA Redmond
- 优先权: IN1498/DEL/2006 20060626
- 主分类号: H04B7/00
- IPC分类号: H04B7/00
摘要:
A method of detecting rogue devices that are coupled to a wired network without generating false negative or false positive alerts is provided. When a wireless monitor detects an observed SSID and/or BSSID, various tests are run to determine whether the observed device is actually coupled to the wired network. To guard against the suspect device spoofing an authorized SSID and/or BSSID, location information is gathered so that the network administrator can pinpoint the location of the rogue device. If the device is not recognized, various other tests are run to determine whether the unrecognized device is actually connected to the wired network. These tests include an association test, a MAC address test, an ARP test, a packet replay test, a correlation test, and/or a DHCP fingerprint test. Once it is determined that the suspect device is a rogue connected to the wired network, an appropriate alert is generated.
公开/授权文献
信息查询