Device Fingerprinting for Dynamic Network Security Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network mapping technologies rely on single configuration scans that provide information about devices at a specific time, which may vary over time due to device changes in physical and/or virtual locations, leading to inefficiencies in network security and management.

Innovation Solution

Utilizing a trained encoder to dynamically assign unique identification codes to devices based on similarity scores calculated from features like IP addresses, MAC addresses, and operating systems, and generating network security maps to facilitate security actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If single configuration scans are used to map network devices, then the network mapping process is simple and quick, but the accuracy and reliability of device identification deteriorates due to device changes in physical and virtual locations

Engineering Contradiction:
Improvenetwork mapping speedVSAvoiddevice identification accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system transitions from static single-time network scanning to dynamic continuous scanning. Multiple scans are performed at different time points to capture device movements and changes. The scanner continuously monitors the network, updating device locations and characteristics, thereby maintaining reliable device identification despite physical or virtual location changes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary device fingerprinting by collecting multiple characteristics (MAC address, IP address, operating system, services) before final device identification. This preliminary action creates a comprehensive device profile that can be matched across multiple scans, ensuring accurate device identification even when some characteristics change.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple scans are performed to track device changes, then device identification accuracy improves, but the complexity and time consumption of the network mapping process increases

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidnetwork mapping process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple scan results are merged into a unified network map. The system combines data from multiple scans, consolidating device information and resolving conflicts through fingerprint matching. This merging process maintains comprehensive device tracking while organizing the complexity into a manageable unified representation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system creates digital fingerprints (copies) of devices based on their characteristics. These fingerprints serve as simplified representations that can be quickly compared across multiple scans without requiring full device analysis each time, reducing processing complexity while maintaining identification accuracy.

Inventive Principle:
Principle #26Copying

3Measurement precision

If comprehensive device characteristics are collected for fingerprinting, then the uniqueness and accuracy of device identification improves, but the data processing requirements and system resource consumption increase

Engineering Contradiction:
Improvedevice identification precisionVSAvoiddata processing volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system extracts only the most distinctive and reliable characteristics from comprehensive device data for fingerprinting. By selecting key identifying features rather than processing all available data, the system achieves high identification precision while reducing the volume of data that requires processing and storage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system transforms comprehensive device characteristics into a standardized fingerprint format with specific parameters. This parameter transformation consolidates multiple data points into a compact representation that maintains identification precision while reducing data volume for storage and comparison operations.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12519787B1Systems and methods configured for automatically assigning a unique identifier to a detected device
Publication Date: 2026.01.06 VIRTUALITICS INC
  • US12519787B1 patent drawing
  • US12519787B1 patent drawing
  • US12519787B1 patent drawing

AI summary

In some embodiments, the present disclosure provides an exemplary method that may include steps of obtaining data associated with a device within a network; determining a digital fingerprint via identification data of the device based on a scan of the network and data associated with the device by: comparing the identification data of the device to a plurality of devices within the, generating a unique identification code that uniquely identifies the device based on a similarity score for the device, and determining the unique identification code for the device based on the digital fingerprint; and generating a network security map that represents a topology of the network, wherein the network security map maps the device within the topology according to the unique identification code so as to facilitate causing at least one security action with respect to the device within the network.