Network Adapter Fingerprint for Endpoint Security Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Securing endpoints in heterogeneous enterprise networks is challenging due to the complexity and diversity of networked devices, which makes it difficult to enforce network policies and manage security across various endpoints, especially when devices have different processing capabilities and communication interfaces, and device identification information may be lost through network address translation or from different vendors.

Innovation Solution

Creating a network adapter fingerprint for each endpoint to track and manage its location and connectivity, and using a threat management facility that includes policy management, security management, and remedial actions to secure endpoints, with techniques such as heartbeat systems for monitoring endpoint health and key management for access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional endpoint security management is used in heterogeneous enterprise networks, then security policies can be enforced on individual devices, but the complexity and diversity of networked devices makes it difficult to manage security across various endpoints

Engineering Contradiction:
Improvesecurity managementVSAvoidnetwork device diversity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal network adapter fingerprint that can identify and track any endpoint regardless of its specific device type, vendor, or communication interface. This fingerprint serves as a universal identifier that works across heterogeneous devices including PCs, mobile devices, IoT devices, and virtual machines, eliminating the need for device-specific management approaches.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent transforms the approach to endpoint identification by changing from device-specific parameters (device type, vendor, model) to a unified parameter set based on network adapter characteristics. By fingerprinting network adapters using consistent parameters across all device types, the system achieves simplified management despite device diversity.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If device-specific security management is implemented, then individual devices can be secured, but administrator resources are significantly consumed due to the need to manage each device type separately

Engineering Contradiction:
Improveendpoint securityVSAvoidadministrator resources
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The network adapter fingerprint creates a universal identification mechanism that allows administrators to manage security policies based on endpoint functionality and network behavior rather than device specifics. This reduces administrator workload by eliminating the need to learn and manage separate procedures for each device type while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If network address translation is used to manage network addresses, then IP address management is simplified, but device identification information is lost

Engineering Contradiction:
Improvenetwork address managementVSAvoiddevice identification
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent creates a copy of device identification information in the form of a network adapter fingerprint that is independent of network address translation. This fingerprint captures essential identification characteristics of the network adapter and maintains them through NAT, allowing devices to be identified and tracked even when their IP addresses change or are translated.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10972431B2Device management based on groups of network adapters
Publication Date: 2021.04.06 SOPHOS LTD
  • US10972431B2 patent drawing
  • US10972431B2 patent drawing
  • US10972431B2 patent drawing

AI summary

Secure management of an enterprise network is improved by creating a network adapter fingerprint for an endpoint that identifies all of the network adapters for that endpoint. With this information, the location and connectivity of the endpoint can be tracked and managed independent of the manner in which the endpoint is connecting to the enterprise network.