Agentless Network Device Identification Through Dynamic Traffic Patterns
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device identification methods in computer networks are hindered by device identity obfuscation measures, such as randomized MAC addresses and dynamic IP assignments, which disrupt traditional identification techniques, leading to challenges in enforcing network policies and managing devices effectively.
Innovation Solution
A method that processes dynamic network data attributes from active devices, comparing them to time series data sets associated with predetermined identifiers (SEEDs) to determine device association scores without requiring additional communication, using algorithms to match and score data sets over time.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device identity obfuscation measures (randomized MAC addresses, dynamic IP assignments) are implemented to protect user privacy and security, then device security and privacy are improved, but device identification capability deteriorates
Solution Approach 1:
The patent transforms the identification approach from relying on static device identifiers (MAC addresses, IP addresses) to analyzing dynamic network traffic parameters. By monitoring packet timing, size, frequency, and protocol patterns over time, the system creates behavioral fingerprints that remain consistent even when traditional identifiers change. This parameter transformation enables continuous device identification despite identity obfuscation measures.
Solution Approach 2:
The patent introduces network traffic analysis as an intermediary layer between the device and the identification system. Instead of directly accessing device identifiers, the system uses traffic patterns as an intermediate representation that indirectly reveals device identity. This intermediary approach allows identification without requiring devices to expose their true identifiers, maintaining privacy while enabling recognition.
2Ease of operation
If traditional device identification methods are used to enable policy enforcement, then network management control is improved, but compatibility with modern privacy-protecting devices deteriorates
Solution Approach 1:
The patent transitions from static identification methods to dynamic behavioral analysis. Instead of relying on fixed device attributes, the system continuously monitors and analyzes changing traffic patterns to identify devices. This dynamic approach adapts to devices that frequently change their identifiers, maintaining network management control while being compatible with privacy-protecting technologies.
Solution Approach 2:
The patent replaces the mechanical system of direct identifier matching with a computational analysis system that processes traffic patterns. Instead of simple comparison of device IDs, the system uses algorithms to analyze temporal and behavioral characteristics of network traffic, substituting complex computational methods for traditional identifier-based mechanisms.
3Measurement precision
If additional communication protocols are implemented for device identification, then identification accuracy is improved, but network overhead and complexity increase
Solution Approach 1:
The patent enables devices to identify themselves indirectly through their existing network traffic without requiring additional communication protocols. Devices continue their normal communication patterns, and the identification system extracts behavioral characteristics from this existing traffic. This self-service approach achieves accurate identification without adding network overhead or device complexity.
Solution Approach 2:
The patent extracts identification information from existing network traffic parameters rather than requiring new communication protocols. By taking out and analyzing relevant features from ordinary traffic (timing, size, frequency patterns), the system achieves accurate device identification without adding any additional communication burden to the network.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
Maintaining in a database of a plurality of time series data sets, wherein each time series data set is associated to a previously known computer device of a computer network; detecting a connection request from a second computer device; collecting new data sets related to the second computer device, wherein each data set comprises one or more second data attributes; comparing the new data sets with time series data sets; calculating value scores related to the plurality of time series data sets based on comparing; and determining a device association score based on the value scores, wherein the device association score determines an association level between the previously known computer device and the second computer device of the computer network.