US 12,382,292 B2
Mitigation of rogue Wi-Fi 6E compatible access points
Ruchir Mishra, Sunnyvale, CA (US); and Shrikant Gambheer Patil, Sunnyvale, CA (US)
Assigned to Fortinet, Inc., Sunnyvale, CA (US)
Filed by Fortinet, Inc., Sunnyvale, CA (US)
Filed on Dec. 31, 2022, as Appl. No. 18/092,309.
Application 18/092,309 is a continuation in part of application No. 18/088,980, filed on Dec. 27, 2022.
Prior Publication US 2024/0214813 A1, Jun. 27, 2024
Int. Cl. H04W 12/122 (2021.01); H04W 24/08 (2009.01)
CPC H04W 12/122 (2021.01) [H04W 24/08 (2013.01)] 7 Claims
OG exemplary drawing
 
1. In a Wi-Fi controller, a method for coordinated channel switch announcement (CSA) disruption of rogue Wi-Fi 6E access point connections with Wi-Fi 6E stations, the method comprising:
identifying authorized Wi-Fi 6E access points;
on-wire monitoring of SSID/BSSID data including a channel occupied for Wi-Fi traffic, and generating an SSID/BSSID scan table of on-wire SSID/BSSID combinations of the Wi-Fi 6E access points;
Wi-Fi monitoring of SSID/BSSID data including channel occupied for Wi-Fi traffic, from RF scanning by the authorized Wi-Fi 6E access points managed over wire by the Wi-Fi controller, wherein the Wi-Fi data packets are encapsulated within on -wire data packets for transmission from the Wi-Fi 6E access points to the Wi-Fi controller;
detecting the rogue Wi-Fi access point from an unregistered BSSID combined with a registered SSID within RF range of a first Wi-Fi 6E access point from the SSID/BSSID scan table;
at a subsequent time, detecting the rogue access point from the unregistered BSSID within range of a second Wi-Fi 6E access point, physically distinct from the first Wi-Fi 6E access point, communicating with a Wi-Fi 6E station; and
transmitting the SSID/BSSID data for the rogue Wi-Fi 6E access point from the SSID/BSSID scan table to the second Wi-Fi 6E access point for disruption, wherein, in response to the transmission, the second Wi-Fi 6E access point generates an action frame modified for the Wi-Fi 6E station with a spoofed BSSID associated with the rogue Wi-Fi access point as scanned by the first Wi-Fi 6E access point, and including CSA values, causing the Wi-Fi 6E station to change a channel used to communicate with the rogue Wi-Fi 6E access point.