Device Fingerprinting for Dynamic Network Security Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network mapping technologies rely on single configuration scans that provide information about devices at a specific time, which may vary over time due to device changes in physical and/or virtual locations, leading to inefficiencies in network security and management.
Innovation Solution
Utilizing a trained encoder to dynamically assign unique identification codes to devices based on similarity scores calculated from features like IP addresses, MAC addresses, and operating systems, and generating network security maps to facilitate security actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If single configuration scans are used to map network devices, then the network mapping process is simple and quick, but the accuracy and reliability of device identification deteriorates due to device changes in physical and virtual locations
Solution Approach 1:
The system transitions from static single-time network scanning to dynamic continuous scanning. Multiple scans are performed at different time points to capture device movements and changes. The scanner continuously monitors the network, updating device locations and characteristics, thereby maintaining reliable device identification despite physical or virtual location changes.
Solution Approach 2:
The system performs preliminary device fingerprinting by collecting multiple characteristics (MAC address, IP address, operating system, services) before final device identification. This preliminary action creates a comprehensive device profile that can be matched across multiple scans, ensuring accurate device identification even when some characteristics change.
2Reliability
If multiple scans are performed to track device changes, then device identification accuracy improves, but the complexity and time consumption of the network mapping process increases
Solution Approach 1:
Multiple scan results are merged into a unified network map. The system combines data from multiple scans, consolidating device information and resolving conflicts through fingerprint matching. This merging process maintains comprehensive device tracking while organizing the complexity into a manageable unified representation.
Solution Approach 2:
The system creates digital fingerprints (copies) of devices based on their characteristics. These fingerprints serve as simplified representations that can be quickly compared across multiple scans without requiring full device analysis each time, reducing processing complexity while maintaining identification accuracy.
3Measurement precision
If comprehensive device characteristics are collected for fingerprinting, then the uniqueness and accuracy of device identification improves, but the data processing requirements and system resource consumption increase
Solution Approach 1:
The system extracts only the most distinctive and reliable characteristics from comprehensive device data for fingerprinting. By selecting key identifying features rather than processing all available data, the system achieves high identification precision while reducing the volume of data that requires processing and storage.
Solution Approach 2:
The system transforms comprehensive device characteristics into a standardized fingerprint format with specific parameters. This parameter transformation consolidates multiple data points into a compact representation that maintains identification precision while reducing data volume for storage and comparison operations.
Data Source
AI summary
In some embodiments, the present disclosure provides an exemplary method that may include steps of obtaining data associated with a device within a network; determining a digital fingerprint via identification data of the device based on a scan of the network and data associated with the device by: comparing the identification data of the device to a plurality of devices within the, generating a unique identification code that uniquely identifies the device based on a similarity score for the device, and determining the unique identification code for the device based on the digital fingerprint; and generating a network security map that represents a topology of the network, wherein the network security map maps the device within the topology according to the unique identification code so as to facilitate causing at least one security action with respect to the device within the network.


