"Cassandra WiFi" hardware and software system for monitoring wireless communication devices Wi-Fi

Cassandra-WiFi is a hardware and software system designed to detect and control all active Wi-Fi devices in a controlled area and to identify illegal Wi-Fi devices from all operating devices with the ability to localize them using the amplitude direction finding method.

The operating principle of the system.

The system sequentially scans all Wi-Fi channels in the 2.4 GHz and 5 GHz range, intercepts all data packets of Wi-Fi devices (works as a Wi-Fi sniffer), analyzes the headers of the intercepted Wi-Fi packets, extracts the MAC addresses of the source and receiver of the data, determines the signal level and analyzes the volume of transmitted data. MAC addresses are unique for each Wi-Fi device.

By comparing the MAC addresses extracted from the intercepted data packets with the MAC addresses of legally operating devices from the list of legal devices, the program identifies the addresses of devices that have not been registered as legal. Then, based on the signal level with a given MAC address, it is possible to perform amplitude direction finding of the radiation source. The stored statistical data on intercepted packets allows you to evaluate the activity of each device over a long period of time (a month or more), identify the pattern and regularity of operation, and evaluate the volume of data transferred at different times of the day.

Purpose:

Monitoring all active Wi-Fi devices in the availability zone, identifying and localizing illegal Wi-Fi devices

Features:

Detection of working Wi-Fi network access points;

Detection of Wi-Fi clients (not access points: computers, laptops, smartphones, etc.);

Recording the connection (the fact of data transfer) of Wi-Fi devices, traffic counting;

Graphic display of the topology of working Wi-Fi networks;

Filters for displaying devices with the required parameters;

List of legal devices;

Archive: displaying activity, device operation for a selected time interval;

Combination of several interception modules under the control of one software;

Specifications:

Wi-Fi interception and analysis module

Frequency range 2.4 GHz, 5 GHz
Analyzed standards 802.11 a, b, g, n
Connection to computer LAN 100 Mbit (USB 2.0 via adapter included)
Possibility of autonomous operation 24/7
Minimum data storage time At least a month
Antenna Built-in
Power supply 5 V, 500 mA; powered by USB 2.0 or by an external 5 V power source
Dimensions (LxWxH) 15x9x2.2 cm
Weight of the hardware module no more than 200 grams
Tablet PC

Screen diagonal from 10.8" to 11.6"
Screen resolution 1920x1080
Operating system Windows 10
Built-in memory Not less than 60 GB
Processor Not worse than Intel Core i3 1500 MHz
Connection of external devices via USB Not less than one USB 2.0
Software

Software analysis capabilities Determination of MAC addresses of all devices, including "invisible" ones, but to which data is addressed; determination of the network SSID, equipment manufacturer, equipment type, channels used, encryption type; assessment of the traffic of transmitted data for each device; visualization of Wi-Fi devices by connection to each other; maintaining a list of legal devices and highlighting illegal devices in color
Operating mode Single-server in real time; multi-server in real time; autonomous data collection; delayed analysis of accumulated data
Direction finding capability Available by signal level
Operating algorithm Scanning channels on request or tracking a selected Wi-Fi device
Display of information Graphical, symbolic and in the form of tables
See also