Device Classification Using Ranked Passive and Active Properties
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The rapid proliferation of network-connected devices poses challenges in accurately and efficiently classifying devices for network security, as existing methods are computationally expensive and do not scale well, leading to difficulties in managing access and identifying vulnerabilities.
Innovation Solution
The proposed solution involves ranking device properties by scalability and effectiveness to optimize classification, using a combination of passive and active properties, and resolving conflicts through hierarchical evaluation, allowing for faster and more accurate device classification with reduced resource usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If comprehensive device properties are analyzed for accurate classification, then classification accuracy is improved, but computational cost and processing time increase
Solution Approach 1:
The patent segments device properties into two distinct categories: passive properties (obtained without device interaction such as MAC address, IP address, hostname) and active properties (obtained through device interaction such as OS type, application list). This segmentation allows the system to first perform quick classification using passive properties, then selectively apply active property analysis only when needed, thereby maintaining high classification accuracy while significantly reducing overall computational cost and processing time for the majority of devices.
Solution Approach 2:
The patent implements preliminary action by first collecting and analyzing passive device properties before proceeding to active property analysis. The system performs an initial classification pass using readily available passive properties, and only when classification confidence is insufficient does it proceed to the more computationally expensive active property collection. This preliminary filtering approach ensures that most devices are classified quickly without requiring full computational analysis, thus improving processing speed while maintaining accuracy for devices that need detailed analysis.
2Use of energy by moving object
If passive properties are used for classification, then resource consumption is reduced, but classification accuracy decreases
Solution Approach 1:
The patent merges passive and active property analysis into a unified two-stage classification system. The system first performs classification using passive properties alone for low-resource consumption scenarios, then combines passive and active properties when higher accuracy is required. This merging allows the system to adapt resource consumption levels based on classification needs, achieving both energy efficiency and high accuracy depending on the specific classification scenario.
Solution Approach 2:
The patent implements dynamics by making the property analysis depth adaptive rather than static. The system dynamically adjusts whether to perform passive-only or combined passive-active analysis based on factors such as classification confidence thresholds, device criticality, and available resources. This dynamic approach ensures that passive properties are used for routine low-risk devices (minimizing resource consumption) while active properties are engaged for high-risk or uncertain classifications (maximizing accuracy).
3Reliability
If device classification is performed on all network devices, then security coverage is improved, but system complexity increases
Solution Approach 1:
The patent applies local quality by implementing risk-based differential classification strategies. Instead of applying the same comprehensive classification process to all devices, the system assigns different classification depths to different devices based on their risk profiles, device types, and network roles. High-risk devices receive full passive-active analysis while low-risk devices receive passive-only analysis. This local quality approach ensures comprehensive security coverage for critical devices while reducing system complexity for routine devices.
Solution Approach 2:
The patent utilizes parameter changes by adjusting classification thresholds and property analysis depths based on device characteristics and network context. The system dynamically modifies parameters such as classification confidence thresholds, property collection depth, and analysis intensity based on device risk assessments. This parameter adaptation allows the system to maintain high security coverage for vulnerable devices while simplifying the classification process for stable, low-risk devices, thereby managing overall system complexity.
Data Source
AI summary
Systems, methods, and related technologies for device classification are described. In certain aspects, one or more properties are selected based on associated respective ranks. The selected one or more properties are used with information associated with the device to determine a classification. The classification may then be stored.


