Device Classification Service Detecting Spoofing via Behavioral Modeling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Device classification systems in computer networks are vulnerable to spoofing attacks, where malicious devices mimic benign devices' attributes and behaviors, leading to unauthorized access and altered classification, which can result in inappropriate permissions or access levels.

Innovation Solution

A machine learning-based approach that models the relationship between declarative and behavioral attributes of devices to detect spoofing, using a device classification service that initiates mitigation actions based on identified spoofing, employing components like a device type classifier, declarative likelihood estimator, device behavior clustering engine, spoofing detection component, and network attribute predictor to verify and correct device type classifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If device classification is based on observed behavior during a short period after joining the network, then automated device type identification is achieved, but the system becomes vulnerable to spoofing attacks where malicious devices can mimic benign device behaviors

Engineering Contradiction:
Improveautomated device classificationVSAvoidclassification accuracy
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the device classification system continuously monitors device behavior and compares it against the classified device type profile. When discrepancies are detected between expected behavior and actual behavior, the system triggers re-evaluation and reclassification. This closed-loop feedback ensures that spoofed devices are detected and reclassified, maintaining reliability while preserving automated classification.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary actions by establishing a baseline device profile during an initial observation period before final classification is made. This preliminary profiling captures the device's natural behavior patterns, which then serves as a reference for detecting spoofing attempts. By preparing this baseline in advance, the system can quickly identify deviations without compromising the automated classification process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If device classification rules are applied to observed behavior to automatically configure access control policies, then network security is enhanced through automated policy enforcement, but malicious devices can exploit this by spoofing device attributes to gain inappropriate permissions

Engineering Contradiction:
Improveaccess control securityVSAvoidspoofing attack impact
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing behavior validation checks before access control policies are enforced. The system validates that a device's observed behavior is consistent with its classified type before granting permissions. This preliminary validation prevents spoofed devices from gaining inappropriate access, as their behavior will not match their spoofed identity, thereby countering the harmful effect before it can manifest.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent introduces an intermediary validation layer between device classification and access control policy enforcement. This intermediary component verifies the consistency between device behavior and classification before policies are applied. It acts as a mediator that blocks spoofed devices from exploiting the classification system, ensuring that only genuinely classified devices receive appropriate access permissions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If the system monitors device behavior continuously to detect spoofing, then detection accuracy is improved, but system complexity and computational overhead increase

Engineering Contradiction:
Improvespoofing detection accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies partial action by implementing selective monitoring rather than continuous monitoring of all device attributes. The system focuses on monitoring specific behavioral parameters that are most indicative of spoofing attempts, based on the device's classified profile. This partial monitoring approach maintains high detection accuracy by concentrating resources on critical indicators while reducing overall system complexity and computational overhead.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11729210B2Detecting spoofing in device classification systems
Publication Date: 2023.08.15 CISCO TECHNOLOGY INC
  • US11729210B2 patent drawing
  • US11729210B2 patent drawing
  • US11729210B2 patent drawing

AI summary

In various embodiments, a device classification service obtains device telemetry data indicative of declarative attributes of a device in a network and indicative of behavioral attributes of that device. The device classification service labels the device with a device type, based on the device telemetry data. The device classification service detects device type spoofing exhibited by the device using a model that models a relationship between the declarative attributes and the behavioral attributes. The device classification service initiates, based on the device type spoofing, a mitigation action regarding the device.