| US 7,577,424 B2 | ||
| Systems and methods for wireless vulnerability analysis | ||
| Amit Sinha, Marlborough, Mass. (US); and Nicholas John Darrow, Alpharetta, Ga. (US) | ||
| Assigned to Airdefense, Inc., Alpharetta, Ga. (US) | ||
| Filed on Dec. 19, 2005, as Appl. No. 11/312,042. | ||
| Prior Publication US 2007/0142030 A1, Jun. 21, 2007 | ||
| Int. Cl. H04M 1/66 (2006.01); H04M 3/00 (2006.01); H04W 24/00 (2006.01); H04B 17/00 (2006.01); G06F 11/00 (2006.01) | ||
| U.S. Cl. 455—410 [455/423; 455/67.14; 726/25; 379/189] | 26 Claims |

| 1. A system for identifying security vulnerabilities in a wireless network, the system comprising:
a system data store configured to store a plurality of wireless attack patterns, network default data associated with the
wireless network, and responses received from the wireless network in response to simulated wireless attacks using one or
more of the plurality of wireless attack patterns;
a wireless radio in communication with the system data store; and
a control engine comprising one or more processing elements, wherein the control engine is in communication with the system
data store and the wireless radio, and wherein the control engine is configured to perform the steps comprising of:
performing a sequence of wireless tracks comprising the simulated wireless attacks on the wireless network by communicating
with at least one wireless device on the wireless network, wherein each wireless track of the sequence of wireless tracks
comprises one of a wireless transmit track and a wireless receive track, and wherein each wireless track of the sequence of
wireless tracks is performed responsive to previous wireless tracks in the sequence and with assimilated wireless frame parameters
from previous wireless receive tracks;
receiving a response to the simulated wireless attack from the wireless network;
analyzing the response of the wireless network to the simulated wireless attacks to identify a vulnerability of the wireless
network; and
determining which of the wireless attacks is most probable to occur based on the analyzed vulnerability, such that steps may
be taken to mitigate the analyzed vulnerability.
|