Crowdsourced Device Classification for Faster Network Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems struggle with accurately classifying unknown devices on computer networks, particularly IoT and OT devices, leading to security vulnerabilities and inefficient network access control, as attackers can exploit unknown devices until classification occurs.
Innovation Solution
Utilizing crowdsourced data and a network monitor entity that analyzes network traffic and applies machine learning models to quickly classify devices, dynamically controlling access and removing malicious clients, while updating classifications for new devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional device classification systems are used, then device classification is performed, but classification accuracy is low and security vulnerabilities remain
Solution Approach 1:
The patent combines multiple data sources including network traffic analysis, device fingerprints, and crowdsourced classification data from a distributed network of monitoring entities. This merging of diverse information sources significantly improves device classification accuracy while reducing security vulnerabilities through cross-validation and consensus mechanisms.
Solution Approach 2:
The system implements continuous feedback loops where classification results are refined over time through learning from new data, correcting misclassifications, and updating device profiles. This feedback mechanism enables the system to improve accuracy dynamically while maintaining security through ongoing validation and adaptation.
2Loss of time
If traditional network monitoring is used, then device detection occurs, but classification time is prolonged allowing attacker exploitation
Solution Approach 1:
The system performs preliminary classification actions immediately upon device detection using pre-configured rules, device fingerprints, and initial traffic analysis. This preliminary action occurs before full classification is complete, enabling rapid response to potential threats while reducing the window for attacker exploitation.
Solution Approach 2:
The patent implements expedited classification pathways for devices exhibiting suspicious behavior or matching known threat patterns. By skipping unnecessary analysis steps and prioritizing critical evaluation, the system rapidly classifies potentially malicious devices, minimizing the time attackers can exploit unclassified devices.
3Measurement precision
If comprehensive device analysis is performed, then classification thoroughness is achieved, but system complexity increases
Solution Approach 1:
The patent segments the device classification system into modular components including network traffic analysis, device fingerprinting, crowdsourced data integration, and classification engine modules. Each segment handles specific aspects of analysis independently, achieving comprehensive classification thoroughness while maintaining manageable system complexity through modular architecture and clear separation of concerns.
Data Source
AI summary
Systems, methods, and related technologies for classifying a device on a network are described. A method includes capturing device information corresponding to a device on a network. The method inputs unstructured crowdsourced data on the network into a machine learning model to produce structured crowdsourced data. The method classifies the device based on evaluating the device information with the structured crowdsourced data.


