Dynamic Host Tracking via Multi-Identifier Aggregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing blocking techniques that rely on static network attributes, such as IP addresses, fail to provide effective protection when these attributes change, leading to potential misclassification of host devices and improper blocking of clean devices.

Innovation Solution

A security platform that aggregates threat information across multiple host identifiers, even when attributes change, to improve classification accuracy and prevent improper blocking by deprioritizing previously associated attributes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If blocking is based on static network attributes like IP addresses, then blocking implementation is simple, but classification accuracy deteriorates when attributes change

Engineering Contradiction:
Improveblocking implementationVSAvoidclassification accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system transitions from static IP address-based blocking to dynamic multi-identifier tracking. When a device changes its network attribute (e.g., IP address), the security platform detects the change through attribute mapping and continues to track the device using alternative identifiers, maintaining both operational simplicity and classification accuracy in dynamic network environments.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an attribute mapping system that acts as an intermediary between network attributes and device identification. This mapping layer correlates multiple host identifiers (IP addresses, MAC addresses, hostnames) to maintain accurate device identification even when primary attributes change, resolving the contradiction between simple blocking and accurate classification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If multiple host identifiers are aggregated to track device changes, then classification accuracy improves, but system complexity increases

Engineering Contradiction:
Improveclassification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The attribute mapping system serves multiple functions simultaneously: it tracks device identifiers, detects attribute changes, maintains identification continuity, and supports blocking decisions. This multi-functionality allows the system to achieve accurate classification through identifier aggregation without proportionally increasing complexity, as a single infrastructure handles multiple security tasks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If blocking is maintained after attribute changes, then security protection is continuous, but clean devices may be improperly blocked

Engineering Contradiction:
Improvesecurity protection continuityVSAvoidimproper blocking
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system implements feedback through attribute mapping and threat information aggregation. When network attributes change, the platform queries the mapped attributes to determine if the new identifier belongs to the same device. This feedback loop ensures continuous security protection for infected devices while preventing improper blocking of clean devices by verifying identifier relationships before maintaining blocks.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10834103B2Tracking and mitigation of an infected host device
Publication Date: 2020.11.10 JUNIPER NETWORKS INC
  • US10834103B2 patent drawing
  • US10834103B2 patent drawing
  • US10834103B2 patent drawing

AI summary

A security platform may determine mapped attribute information associated with a plurality of host identifiers. The mapped attribute information may include information that identifies a set of related attributes. The security platform may determine, based on the mapped attribute information, that a host device is associated with at least two host identifiers of the plurality of host identifiers. The security platform may aggregate, based on the at two least host identifiers, threat information as aggregated threat information associated with the host device. The security platform may classify the host device as an infected device or a suspicious device based on the aggregated threat information.