Crowdsourced Device Classification for Faster Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems struggle with accurately classifying unknown devices on computer networks, particularly IoT and OT devices, leading to security vulnerabilities and inefficient network access control, as attackers can exploit unknown devices until classification occurs.

Innovation Solution

Utilizing crowdsourced data and a network monitor entity that analyzes network traffic and applies machine learning models to quickly classify devices, dynamically controlling access and removing malicious clients, while updating classifications for new devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional device classification systems are used, then device classification is performed, but classification accuracy is low and security vulnerabilities remain

Engineering Contradiction:
Improvedevice classification accuracyVSAvoidsecurity vulnerability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent combines multiple data sources including network traffic analysis, device fingerprints, and crowdsourced classification data from a distributed network of monitoring entities. This merging of diverse information sources significantly improves device classification accuracy while reducing security vulnerabilities through cross-validation and consensus mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements continuous feedback loops where classification results are refined over time through learning from new data, correcting misclassifications, and updating device profiles. This feedback mechanism enables the system to improve accuracy dynamically while maintaining security through ongoing validation and adaptation.

Inventive Principle:
Principle #23Feedback

2Loss of time

If traditional network monitoring is used, then device detection occurs, but classification time is prolonged allowing attacker exploitation

Engineering Contradiction:
Improveclassification timeVSAvoidattacker exploitation
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary classification actions immediately upon device detection using pre-configured rules, device fingerprints, and initial traffic analysis. This preliminary action occurs before full classification is complete, enabling rapid response to potential threats while reducing the window for attacker exploitation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements expedited classification pathways for devices exhibiting suspicious behavior or matching known threat patterns. By skipping unnecessary analysis steps and prioritizing critical evaluation, the system rapidly classifies potentially malicious devices, minimizing the time attackers can exploit unclassified devices.

Inventive Principle:
Principle #21Skipping (Rushing through)

3Measurement precision

If comprehensive device analysis is performed, then classification thoroughness is achieved, but system complexity increases

Engineering Contradiction:
Improveclassification thoroughnessVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the device classification system into modular components including network traffic analysis, device fingerprinting, crowdsourced data integration, and classification engine modules. Each segment handles specific aspects of analysis independently, achieving comprehensive classification thoroughness while maintaining manageable system complexity through modular architecture and clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12368646B2Enhanced device classification including crowdsourced classifications for increased accuracy
Publication Date: 2025.07.22 FORESCOUT TECHNOLOGIES INC
  • US12368646B2 patent drawing
  • US12368646B2 patent drawing
  • US12368646B2 patent drawing

AI summary

Systems, methods, and related technologies for classifying a device on a network are described. A method includes capturing device information corresponding to a device on a network. The method inputs unstructured crowdsourced data on the network into a machine learning model to produce structured crowdsourced data. The method classifies the device based on evaluating the device information with the structured crowdsourced data.