<

Home → Data Tables

Data Tables

Reference examples of descriptive tables.

This page provides reference information tables and table examples. The tables that are included in observation summaries vary based on relevance to the capture and analysis.

Module 1: Analyze

The Analyze module provides tables that are basic to observing wireless services. These tables include the following.

  • Capture Summary
  • Observation Constraints
  • Frame Census
  • Channel Activity
  • Vendor OUI
  • Persistence
  • Device Class Census
  • Network Relationships
  • Mobility Indicators
  • RSSI
  • Reasons To Doubt

Capture Summary

The Capture Summary table provides a high-level view of the analyzed collection.

FieldDescription
Output modeThe options that the user specifies for output generation. The mode can be Standard or Extended. Standard mode generates analysis data to Explorer without anonymization. This is the default mode. Extended mode includes the optional generation of analysis data to CSV format for spreadsheets and to the JSON data exchange format. Extended mode also includes the optional specification of basic anonymization of MAC addresses and SSIDs.
Capture fileThe filename of the uploaded capture file. The filenames of capture files are read on upload and retained.
Capture sizeThe size of the capture file, in megabytes.
Total frames parsedThe total number of packets that the capture file contains.
802.11 packetsThe total number of packets in the capture file that comply with the 802.11 protocol specification.
Beacon framesThe number of frames of beacon subtype that were observed in the capture file.
Probe requestsThe number of frames of subtype probe request that were observed in the capture file.
Probe responsesThe number of frames observed in the capture that represent the probe response subtype.
Association requestsThe number of frames observed to be of the association request subtype.
Reassociation requestsThe number of frames in the capture file that were observed to represent reassociation requests.
AP candidatesThe number of entities acting in the role of access point (AP). The assessment is made based on behavior and relationship. These entities are identified by MAC address.
Client candidatesThe number of entities acting in the role of client to one or more APs. The assessment is made based on behavior and relationship. These entities are identified by MAC address.
Observed devicesThe number of devices that were observed in the capture, identified by MAC address.

Observation Constraints

This table documents the constraints that affect an analysis. The constraints are applied based on analyzer inspective of the capture collection that is uploaded for analysis.

ConstraintImpact
Single uploaded captureThe observation is a point-in-time collection, not a long-term baseline.
20 channel values appear in outputChannel visibility depends on capture adapter and capture settings; absence on a channel is not evidence of absence.
RSSI samples present for 691 devicesRSSI supports proximity estimates, but readings vary with receiver position, walls, antenna orientation, and motion.
0 devices have unavailable average RSSINull means the value could not be derived from available signal observations; it should not be read as zero.
Standard output selectedMAC/BSSID/client identifiers are not anonymized in this trial view.

Frame Census

Counts of selected frame categories found in the collection.

Frame TypeCount
Beacon20,689
Probe Request190
Probe Response741
Association Request2
Reassociation Request0
Other 802.110

Data provenance: Parsed from 802.11 frame type/subtype values.

Note: Selected management-frame subtypes are classified; other 802.11 frames may be counted as Other.

See also: 802.11 Frame Types; Fields Used by CBS Module 1

Channel Activity

The Channel Activity table provides basic information about activity on the observed channels.

ChannelBandAPsDevice CountSSID CountAverage RSSINotes
Band2.4 GHz253113-85.62Observed in job output.
APs2.4 GHz497-86.44Observed in job output.
Device Count2.4 GHz3105-88.55Observed in job output.
SSID Count2.4 GHz202610-85.99Observed in job output.
Average RSSI2.4 GHz011-88.40Observed in job output.
Notes2.4 GHz202412-82.81Observed in job output.
72.4 GHz032-82.60Observed in job output.
82.4 GHz10136-84.69Observed in job output.
92.4 GHz266-84.55Observed in job output.
102.4 GHz898-82.46Observed in job output.
112.4 GHz343810-82.03Observed in job output.
122.4 GHz011-70.84Observed in job output.
132.4 GHz021-76.79Observed in job output.
365 GHz332-91.52Observed in job output.
445 GHz553-91.10Observed in job output.
485 GHz221-93.88Observed in job output.
525 GHz111-86.10Observed in job output.
1005 GHz111-93.46Observed in job output.
1535 GHz111-94.00Observed in job output.
1575 GHz994-87.62Observed in job output.

Data provenance: RadioTap channel/frequency and signal metadata, plus derived counts.

Note: Channel observations depend on capture settings and receiver behavior.

See also: RSSI Interpretation; Observation Constraints

Summary of Findings

MAC address: a2:cf:84:xx:xx:xx
Vendor not found -- Locally administered/randomized -- Default OUI
Captures observed: # files
Capture fileCapture channels
Capture fileCapture channels
FieldObserved, Derived, or InferredValueNotes
RolesObservedAP
SSIDsObserved1
BSSIDsObserved1
Frame types and counts
ProbeReqObserved0
ReassocObserved0
BeaconObserved3228
ProbeRespObserved100
Scope and presence
ChannelsObserved7
DurationObserved2.41hThe duration of the capture.
PresenceDerivedPersistent
MobilityDerivedLikely mobile
RSSI values
Average RSSIObserved-69.9 dBm
RSSI rangeObserved-84 to -56 dBm
RSSI variationDerived28 dBm
Inference information
TBD

Device Classification

Captures are assessed for devices that can be classified with reasonable confidence based on frame data and behavior. The following section lists tables that are used to classify and describe the devices that are represented in wireless captures.

Basic device information is provided based on inferred device class and inventory, device taxonomy and wireless ecology.

Device variants

Variant Purpose
Device Class Census Counts of inferred device types
Device Taxonomy Classification rules and evidence
Wireless Ecology Table Environmental composition view
Device Inventory Detailed per-device reporting

The Analysis module provides the following device class information.

Device Class Table -- Module 1

Device Class Count Confidence Evidence Basis
Infrastructure APs 12 High Beaconing behavior
Mesh / Extenders 3 Medium Multi-BSSID patterns
Client Devices 34 Medium Association activity
Client Scanners 9 High Probe activity only
Mobile Hotspots 2 Medium AP + handset indicators
Vehicle-Associated Devices 1 Medium CarPlay/dashcam indicators
Provisioning Networks 1 High XFSETUP pattern
Unknown Devices 15 Unknown Insufficient evidence

Infrastructure

This table summarizes and describes the wireless infrastructure that was observed at the site. This includes access points (APs), mesh nodes, extenders, and hotspots.

Field Description
TBD TBD

Client Activity

This table describes the client activity that was observed at the site. This includes client and scanner behavior.

Field Description
TBD TBD

Vendor OUI

This table provides a summary of the vendor names and OUIs that the observation discovered at the site. Context By Signal uses this information to report manufacturer attribution and confidence findings.

Observed Vendor attribution Attribution source
(OUI file)
Confidence Reason
TBDTBDTBDTBDTBD
TBDTBDTBDTBDTBD

Channel Utilization

This table provides a measure of channel crowding or "co-channel pressure." High airtime utilization is associated with visible AP density and increased risk of radio frequency (RF) contention. The higher the channel device count, the greater the competition for airtime. The result is latency, dropped connections, and degraded performance. Channel utilization is derived from AP count and RSSI.

AP RSSI (dBm) Pressure
A -48 1.00
B -62 0.70
C -74 0.35
D -83 0.10

Channel utilization is subject to channel overlap. This affects the 2.4 GHz band; the 25 channels on the 5 GHz band do not overlap at 20 Mhz wide. Co-channel pressure is adjusted based on channel overlap as follows:

Area of overlap Adjust by
Same channel1.0
Adjacent overlap0.5 - 0.8
No overlap0

Signal Strength

Received Signal Strength Indicator (RSSI) measures the power of a radio signal on receipt. RSSI is commonly used in wireless protocols, for example, in 802.11 (WiFi), Bluetooth, and ZigBee.

The RSSI field is found in 802.11 packets only when the capture is made with RadioTap headers. In some capture tools, inclusion of the RadioTap header is optional and must be selected. Context By Signal assumes the inclusion of the RadioTap header in packet captures.

RSSI is influenced by variables including the presence of walls, interference, antenna orientation, transmit power, signal reflections, and device hardware. This means that RSSI should be treated as an approximate indicator of relative signal strength rather than an exact measure of physical distance.

The following table lists RSSI values and how they are interpreted within the context of an 802.11 frame capture.

RSSI (dBm) General interpretation
-30 Extremly strong/very close
-50 Strong nearby signal
-67 Good reliable signal
-70 Usable but weaker
-80 Weak / distant / obstructed
-90 Very weak / near detection threshold

The RSSI values of 802.11 transmitters vary from frame to frame. For transmitters whose incidence persists across the timestamps of a capture, this variance might fall into a range or a pattern. The following table provides examples of RSSI patterns relative to the transmitter and their physical interpretation.

RSSI pattern Possible interpretation
Stable strong RSSI over time Nearby persistent device
Rapid RSSI fluctuation Movement or multipath effects
Gradual RSSI decrease Increasing distance or obstruction
Intermittent weak RSSI Edge of range or transient presence

Persistence

Persistence is a measurement of presence, channel "occupancy" across time. Context By Signal measures persistence as a continuing presence across the timestamps of an Airtool capture, in the accumulation of frame counts within the bounds of a capture, and in occupancy across collections of capture files. The cross-file continuity value is omitted for analysis jobs that include only one capture file. Persistence is described by MAC.

MAC address: c0:06:c3:xx:xx:xx
Vendor:
Occupancy# frames
Continuity across framesTime value (6.2 minutes--duration or other increment of measure?)
Continuity across BSSIDsBSSID/origin file and packet
Continuity across filesFile value/list of files?

Travel mode

Field Description
TBD TBD

Site Fingerprint

Field Description
TBD TBD

Observation Constraints

Field Description
TBD TBD

Reasons To Doubt

Field Description
TBD TBD

Evidence

Field Description
TBD TBD

Anomaly

Field Description
TBD TBD

Structural Artifacts

Field Description
TBD TBD