Enterprise Asset Criticality via Network Session Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional asset determination approaches in enterprise networks rely on user-provided network maps or lists, which often result in inaccurate and outdated information, making it difficult to assess asset criticality effectively.

Innovation Solution

A computer-implemented method that captures network session information to identify and determine the criticality of assets by processing this data, using features such as operating systems, web services, and applications, and outputs this criticality information to security-related systems for automated actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user-provided network maps or asset lists are used to determine assets, then the process is simple and requires minimal input, but the information becomes inaccurate and outdated

Engineering Contradiction:
Improvesimplicity of asset determination processVSAvoidaccuracy of asset information
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system performs self-service by automatically discovering and determining asset information through network session analysis without requiring user input. The network session information processing system autonomously identifies assets, services, and their criticality levels by analyzing network traffic patterns, eliminating the need for manual network map provision while ensuring accurate and up-to-date information.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical/manual process of users providing network maps with an automated information processing system. By substituting manual asset listing with automated network session analysis, the system achieves both ease of operation (no user input needed) and high measurement precision (accurate real-time asset identification through network traffic analysis).

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Device complexity

If conventional asset determination approaches are used, then the system complexity is low, but the ability to assess asset criticality effectively is reduced

Engineering Contradiction:
Improvecomplexity of asset determination systemVSAvoideffectiveness of asset criticality assessment
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system changes the parameters used for asset identification from static user-provided lists to dynamic network session information. By analyzing real-time network traffic parameters (protocol types, data flows, connection patterns), the system effectively determines asset criticality without requiring complex manual configuration, achieving high reliability through automated parameter-based analysis.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces network session information as an intermediary between network traffic and asset criticality assessment. This intermediary layer automatically extracts meaningful asset information from raw network data, enabling effective criticality assessment without directly complexifying the overall system architecture. The intermediary processing layer simplifies the relationship between simple network monitoring and sophisticated security analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11140183B2Determining criticality of identified enterprise assets using network session information
Publication Date: 2021.10.05 EMC IP HLDG CO LLC
  • US11140183B2 patent drawing
  • US11140183B2 patent drawing
  • US11140183B2 patent drawing

AI summary

Methods, apparatus, and processor-readable storage media for identifying and determining the criticality of enterprise assets using network traffic information are provided herein. An example computer-implemented method includes capturing network session information from an enterprise network; identifying multiple assets within the enterprise network by processing the captured network session information; determining, for each of the identified assets, one or more predefined features of the asset based at least in part on the processing of the captured network session information; determining, for each of the identified assets, a level of criticality associated with the asset based at least in part on the one or more determined features of the asset; and outputting the level of criticality and an identifier of the asset associated therewith to a security-related system, wherein the level of criticality and the asset identifier are used by the security-related system to take at least one automated action.