Network Visibility via Discovery Protocol Metadata
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security and visibility technologies face challenges due to excessive filtering and bandwidth consumption, particularly in dynamic network topologies, leading to insufficient coverage and inefficient resource utilization.
Innovation Solution
The implementation of discovery protocols such as DHCP, DNS, mDNS, and LLDP to collect low-volume, high-value metadata for analytics, leveraging network edge tap points and filtering techniques to enhance network visibility and security while minimizing bandwidth and resource usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network traffic is excessively filtered by IP, subnet, or VLAN using DNS or discovery protocols, then network security is improved, but network visibility and coverage are insufficient
Solution Approach 1:
The patent segments network monitoring into two distinct functions: (1) Security filtering at the network edge that blocks malicious traffic, and (2) Discovery protocol monitoring that captures metadata about legitimate network resources. This segmentation allows security filtering to maintain its protective function while discovery protocols independently provide visibility into network topology and resource locations without being blocked by the same filters.
Solution Approach 2:
The patent introduces discovery protocol metadata as an intermediary information layer between network traffic and security filtering decisions. Instead of directly filtering raw traffic packets, the system uses discovered resource information (service names, locations, types) as intermediaries to make informed security decisions while maintaining visibility into the full network topology through the discovery protocol data.
2Loss of information
If discovery protocols are used to discover network resources, then network visibility is improved, but bandwidth and computational resources are excessively consumed
Solution Approach 1:
The patent extracts only the essential metadata from discovery protocol traffic (such as service names, locations, and types) while discarding the bulk of the actual network traffic data. This extraction approach provides sufficient network visibility for security and monitoring purposes without requiring full traffic mirroring, thereby significantly reducing bandwidth consumption compared to traditional deep packet inspection methods.
Solution Approach 2:
The patent applies partial action by monitoring only specific portions of network traffic - namely the discovery protocol metadata - rather than implementing comprehensive full-traffic monitoring. This selective monitoring provides adequate visibility into network resources and topology while consuming minimal bandwidth and computational resources compared to complete traffic analysis systems.
3Loss of information
If comprehensive network monitoring is implemented, then network visibility is improved, but device complexity increases
Solution Approach 1:
The patent makes discovery protocols multi-functional by using them simultaneously for (1) network resource discovery, (2) topology mapping, and (3) security monitoring. Instead of requiring separate dedicated systems for each function, the same discovery protocol infrastructure serves multiple purposes, reducing overall system complexity while maintaining comprehensive network visibility.
Solution Approach 2:
The patent enables the network itself to provide monitoring information through its own discovery protocols. The network devices automatically advertise their services and locations through standard discovery protocols, and this self-provided information is captured and analyzed by the monitoring system. This self-service approach eliminates the need for complex external monitoring infrastructure, reducing device complexity while maintaining thorough network visibility.
Data Source
AI summary
A method including correlating a network address of a user to a domain name in a domain name system of a computing network, based on a service log, is provided. The method includes identifying a user group, generating a watch list of servers that control access to a new resource, and establishing a baseline behaviour for a client device based on a first access and a last access to one server in the watch list of servers during a time to live period. The method also includes adding the true network address and a correlated domain name to the baseline behaviour, retrieving a timestamp of an access by the client device to the network address, and flagging, as a violation, the access by the client device to the network address when the access is outside of a legitimate window around the baseline behaviour.


