Enterprise Asset Criticality via Network Session Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional asset determination approaches in enterprise networks rely on user-provided network maps or lists, which often result in inaccurate and outdated information, making it difficult to assess asset criticality effectively.
Innovation Solution
A computer-implemented method that captures network session information to identify and determine the criticality of assets by processing this data, using features such as operating systems, web services, and applications, and outputs this criticality information to security-related systems for automated actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If user-provided network maps or asset lists are used to determine assets, then the process is simple and requires minimal input, but the information becomes inaccurate and outdated
Solution Approach 1:
The system performs self-service by automatically discovering and determining asset information through network session analysis without requiring user input. The network session information processing system autonomously identifies assets, services, and their criticality levels by analyzing network traffic patterns, eliminating the need for manual network map provision while ensuring accurate and up-to-date information.
Solution Approach 2:
The patent replaces the mechanical/manual process of users providing network maps with an automated information processing system. By substituting manual asset listing with automated network session analysis, the system achieves both ease of operation (no user input needed) and high measurement precision (accurate real-time asset identification through network traffic analysis).
2Device complexity
If conventional asset determination approaches are used, then the system complexity is low, but the ability to assess asset criticality effectively is reduced
Solution Approach 1:
The system changes the parameters used for asset identification from static user-provided lists to dynamic network session information. By analyzing real-time network traffic parameters (protocol types, data flows, connection patterns), the system effectively determines asset criticality without requiring complex manual configuration, achieving high reliability through automated parameter-based analysis.
Solution Approach 2:
The patent introduces network session information as an intermediary between network traffic and asset criticality assessment. This intermediary layer automatically extracts meaningful asset information from raw network data, enabling effective criticality assessment without directly complexifying the overall system architecture. The intermediary processing layer simplifies the relationship between simple network monitoring and sophisticated security analysis.
Data Source
AI summary
Methods, apparatus, and processor-readable storage media for identifying and determining the criticality of enterprise assets using network traffic information are provided herein. An example computer-implemented method includes capturing network session information from an enterprise network; identifying multiple assets within the enterprise network by processing the captured network session information; determining, for each of the identified assets, one or more predefined features of the asset based at least in part on the processing of the captured network session information; determining, for each of the identified assets, a level of criticality associated with the asset based at least in part on the one or more determined features of the asset; and outputting the level of criticality and an identifier of the asset associated therewith to a security-related system, wherein the level of criticality and the asset identifier are used by the security-related system to take at least one automated action.


