Dynamic Host Tracking via Multi-Identifier Aggregation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing blocking techniques that rely on static network attributes, such as IP addresses, fail to provide effective protection when these attributes change, leading to potential misclassification of host devices and improper blocking of clean devices.
Innovation Solution
A security platform that aggregates threat information across multiple host identifiers, even when attributes change, to improve classification accuracy and prevent improper blocking by deprioritizing previously associated attributes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If blocking is based on static network attributes like IP addresses, then blocking implementation is simple, but classification accuracy deteriorates when attributes change
Solution Approach 1:
The system transitions from static IP address-based blocking to dynamic multi-identifier tracking. When a device changes its network attribute (e.g., IP address), the security platform detects the change through attribute mapping and continues to track the device using alternative identifiers, maintaining both operational simplicity and classification accuracy in dynamic network environments.
Solution Approach 2:
The patent introduces an attribute mapping system that acts as an intermediary between network attributes and device identification. This mapping layer correlates multiple host identifiers (IP addresses, MAC addresses, hostnames) to maintain accurate device identification even when primary attributes change, resolving the contradiction between simple blocking and accurate classification.
2Measurement precision
If multiple host identifiers are aggregated to track device changes, then classification accuracy improves, but system complexity increases
Solution Approach 1:
The attribute mapping system serves multiple functions simultaneously: it tracks device identifiers, detects attribute changes, maintains identification continuity, and supports blocking decisions. This multi-functionality allows the system to achieve accurate classification through identifier aggregation without proportionally increasing complexity, as a single infrastructure handles multiple security tasks.
3Reliability
If blocking is maintained after attribute changes, then security protection is continuous, but clean devices may be improperly blocked
Solution Approach 1:
The system implements feedback through attribute mapping and threat information aggregation. When network attributes change, the platform queries the mapped attributes to determine if the new identifier belongs to the same device. This feedback loop ensures continuous security protection for infected devices while preventing improper blocking of clean devices by verifying identifier relationships before maintaining blocks.
Data Source
AI summary
A security platform may determine mapped attribute information associated with a plurality of host identifiers. The mapped attribute information may include information that identifies a set of related attributes. The security platform may determine, based on the mapped attribute information, that a host device is associated with at least two host identifiers of the plurality of host identifiers. The security platform may aggregate, based on the at two least host identifiers, threat information as aggregated threat information associated with the host device. The security platform may classify the host device as an infected device or a suspicious device based on the aggregated threat information.


