Claims
- 1. A method for mapping the topology of a wireless network, the method comprising the steps of:
(a) receiving scan data associated with monitoring of one or more wireless access points, one or more wireless network nodes or combinations thereof; (b) identifying a relationship (1) between at least one of the wireless access points and at least one of the wireless network nodes or (2) between any two wireless network nodes based on the received scan data, a characteristic of at least one of the wireless access points, a characteristic of at least one of the wireless network nodes or combinations thereof; and (c) storing the identified relationship, access point characteristic, node characteristic or combinations thereof in a system data store as topology data.
- 2. The method of claim 1, and further comprising the step of initiating one or more scans of wireless transmissions to generate the scan data.
- 3. The method of claim 2, wherein the step of initiating one or more scans comprises initiating a plurality of scans.
- 4. The method of claim 3, wherein each of the plurality of scans is initiated upon a different wireless sensor.
- 5. The method of claim 4, wherein each of the plurality of scans occurs simultaneously.
- 6. The method of claim 4, and further comprising the step of repeating the step of initiating the plurality scans.
- 7. The method of claim 6, wherein the repetition step occurs over a particular time period.
- 8. The method of claim 7, and further comprising the step of determining the particular time period based upon configuration data, network security threat level, current network activity, historical network activity or combinations thereon.
- 9. The method of claim 3, wherein each of the plurality of scans occurs within a particular time period.
- 10. The method of claim 9, and further comprising the step of determining the particular time period based upon configuration data, network security threat level, current network activity, historical network activity or combinations thereof.
- 11. The method of claim 2, and further comprising the step of receiving a mapping request from a user or a computer and wherein the scan initiation step is responsive to the received mapping request.
- 12. The method of claim 2, wherein the one or more initiated scans are initiated continuously or at periodic intervals.
- 13. The method of claim 1, and further comprising the step of (d) formatting the stored topology data based upon a desired output format.
- 14. The method of claim 13, and further comprising the step of repeating steps (a) through (d) a plurality of times.
- 15. The method of claim 13, and further comprising the step of (e) storing the formatted topology data in a data store accessible by a server system.
- 16. The method of claim 15, wherein the server system is an HTTP server, a WAIS server, a gopher server, or an FTP server.
- 17. The method of claim 13, wherein the desired output format is TIFF, GIF, JPEG, HTML, SMS, MIME, S/MIME, ZIP, SML, SGML, WAP, BMP or combinations thereof.
- 18. The method of claim 13, and further comprising the step of receiving a mapping request and wherein the formatting step is responsive to the received mapping request.
- 19. The method of claim 18, wherein the mapping request is received from a user or a computer system.
- 20. The method of claim 13, and further comprising detecting a mapping trigger event based upon the received scan data and wherein the formatting step is responsive to the detected trigger event.
- 21. The method of claim 20, wherein the trigger event is a usage volume anomaly, a connectivity pattern anomaly, a policy violation, a security violation or combinations thereof.
- 22. The method of claim 1, and further comprising the step of (d) transmitting the stored topology data to a desired output device.
- 23. The method of claim 22, and further comprising the step of repeating steps (a) through (d) a plurality of times.
- 24. The method of claim 22, and further comprising the steps of (e) determining a desired output format and (f) formatting the stored topology data based upon the desired output format prior to transmission.
- 25. The method of claim 24, wherein the step of determining the desired output format comprises the step of determining the desired output format based upon configuration data, the desired output device, a mapping request or combinations thereof.
- 26. The method of claim 22, and further comprising the step of (e) determining the desired output device.
- 27. The method of claim 26, wherein step (e) comprises the step of determining the desired output device based upon configuration data, a mapping request or combinations thereof.
- 28. The method of claim 22, wherein the desired output device is a monitor, a printer, a further processing system, a pager, a telephone, a personal data assistant (PDA), an e-mail account or a combination thereof.
- 29. The method of claim 22, wherein the desired output device is capable of rendering graphical output and further comprising the step of (e) formatting the topology data in a manner to graphically represent characteristics or relationships prior to transmission.
- 30. The method of claim 29, wherein the desired output device is capable of rendering color output and wherein the formatting step (e) comprises the step of formatting the topology data in manner using color to represent characteristics or relationships prior to transmission.
- 31. The method of claim 22, wherein the desired output device is capable of rendering color output and further comprising the step of (e) formatting the topology data in manner using color to represent characteristics or relationships prior to transmission.
- 32. The method of claim 1, and further comprising the step of identifying a relationship between a plurality of the wireless nodes based on the received scan data in which no wireless access point is involved.
- 33. A system for mapping the topology of a wireless network, the system comprising:
(a) storage means for storing topology data comprising access point characteristic data, wireless network node characteristic data, access point/node relationship data, node/node relationship data or combinations thereof; (b) monitoring means for scanning wireless transmissions within a wireless network and generating scan data therefrom; (c) receiving means for receiving scan data from the monitoring means; (d) analysis means for generating topology data by identifying from scan data received by the receiving means a characteristic of a wireless network node, a characteristic of an access point, an access point-node relationship, a node-node relationship or combinations thereof and for storing the generated topology data in the storage means; and (e) output means for formatting topology data generated by the analysis means based upon a desired output format and for transmitting the formatted topology data to a desired output device.
- 34. The system of claim 33, wherein the output means is responsive to a mapping request from a user or a computer system or to a trigger event selected form the group consisting of a usage volume anomaly, a connectivity pattern anomaly, a policy violation, a security violation or combinations thereof.
- 35. The system of claim 33, wherein the monitoring means is responsive to a mapping request from a user or a computer system or to a trigger event selected form the group consisting of a usage volume anomaly, a connectivity pattern anomaly, a policy violation, a security violation or combinations thereof.
- 36. A system for mapping the topology of a wireless network, the system comprising:
(a) a system data store (SDS) capable of storing topology data comprising access point characteristic data, wireless network node characteristic data, access point/node relationship data, node/node relationship data or combinations thereof; and (b) a system processor comprising one or more processing elements, wherein the system processor is in communication with the SDS and wherein the one or more processing elements are programmed or adapted at least to:
(1) initiate at least one scan of one or more wireless access points, one or more wireless network nodes or combinations thereof; (2) receive scan data associated with monitoring of one or more wireless access points, one or more wireless network nodes or combinations thereof; (3) identify a relationship (i) between at least one of the wireless access points and at least one of the wireless network nodes or (ii) between any two wireless network nodes based on the received scan data, a characteristic of at least one of the wireless access points, a characteristic of at least one of the wireless network nodes or combinations thereof; (4) store the identified relationship, access point characteristic, node characteristic or combinations thereof in the SDS as topology data; and (5) format topology data generated based upon a desired output format; and (6) output the formatted topology data to a desired output device.
- 37. The system of claim 36, and further comprising (c) a wireless receiver that monitors wireless transmissions, wherein the wireless receiver is in communication with the system processor and wherein-the system processor's programming or adaptation to initiate at least one scan includes at least programming or adaptation to initiate the scan using the wireless receiver and wherein its programming or adaptation to receive scan data includes at least programming or adaptation to receive scan data from the wireless receiver or from an interface therewith.
- 38. One or more computer-readable media storing instructions that upon execution by a system processor cause the system processor to map the topology of a wireless network by performing at least the steps comprising of:
(a) initiating a scan of one or more wireless access points, one or more wireless network nodes or combinations thereof; (b) receiving scan data associated with monitoring of one or more wireless access points, one or more wireless network nodes or combinations thereof; (c) identifying a relationship (i) between at least one of the wireless access points and at least one of the wireless network nodes or (ii) between any two wireless network nodes based on the received scan data, a characteristic of at least one of the wireless access points, a characteristic of at least one of the wireless network nodes or combinations thereof; (d) storing the identified relationship, access point characteristic, node characteristic or combinations thereof as topology data; and (e) formatting topology data generated based upon a desired output format; and (f) outputting the formatted topology data to a desired output device.
CROSS-REFERENCE TO RELATED PATENT APPLICATIONS
[0001] This application claims priority to, and incorporates by reference in its entirety for all purposes, commonly assigned provisional U.S. Patent Application Serial No. 60/464,464, filed Apr. 21, 2003, entitled “SYSTEMS AND METHODS FOR NETWORK SECURITY”.
Provisional Applications (1)
|
Number |
Date |
Country |
|
60464464 |
Apr 2003 |
US |