Dynamic Network Classification via Authenticated Neighbor Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network classification methods fail to dynamically and accurately identify managed networks, leading to potential security breaches from rogue or unknown devices, as they lack effective mechanisms for authenticated neighbor detection and adaptive sensor operation modes.

Innovation Solution

The implementation of a managed device detector that uses authenticated neighbor detection to classify networks by transmitting discovery packets, analyzing responses, and adjusting sensor operation modes based on network configuration comparisons to a whitelist or blacklist, ensuring appropriate data collection and security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network classification methods use static detection approaches, then device detection capability is maintained, but dynamic adaptation to rogue devices and network changes is lost

Engineering Contradiction:
Improvedynamic network classification capabilityVSAvoiddetection mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic network classification by enabling the device detector to transition between different operational modes (discovery mode and data collection mode) based on real-time network conditions and authenticated neighbor detections. This allows the system to adapt its detection behavior dynamically rather than using a static approach, resolving the contradiction between adaptability and complexity by making the system flexible only when necessary.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-authentication and self-classification by using authenticated neighbor detection to automatically determine network type without requiring external verification. The device detector autonomously detects managed devices, authenticates neighbors, and classifies the network based on detection results, eliminating the need for complex external validation mechanisms while achieving dynamic adaptability.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If authenticated neighbor detection is implemented, then network classification accuracy is improved, but detection time and processing overhead increase

Engineering Contradiction:
Improvenetwork classification accuracyVSAvoiddetection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial authentication by detecting a threshold number of authenticated neighbors rather than requiring full authentication of all devices. The system transitions to data collection mode when a sufficient number of managed devices are detected, achieving accurate network classification without the time overhead of exhaustive authentication of every device on the network.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary discovery by transmitting discovery packets to identify potential managed devices before conducting full authentication. This preliminary action allows the system to quickly filter devices and focus authentication resources only on relevant candidates, reducing overall detection time while maintaining classification accuracy.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If sensor operation modes are dynamically adjusted, then security against rogue devices is enhanced, but system complexity and control mechanisms increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsensor control mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements feedback control by continuously monitoring authenticated neighbor counts and using this information to automatically adjust sensor operation modes. When the number of authenticated neighbors exceeds a threshold, the system transitions from discovery mode to data collection mode, and vice versa. This feedback mechanism enhances security through dynamic adaptation without requiring complex manual control systems.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system uses an intermediary classification mechanism that sits between raw detection data and security actions. The device detector acts as an intermediary that processes detection results, determines network classification, and then triggers appropriate sensor modes based on this classification. This intermediary layer simplifies control by abstracting the complexity of mode transitions behind a clear classification decision process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10951476B1Methods and apparatus for dynamic network classification using authenticated neighbor detection
Publication Date: 2021.03.16 MCAFEE LLC
  • US10951476B1 patent drawing
  • US10951476B1 patent drawing
  • US10951476B1 patent drawing

AI summary

Methods, apparatus, systems, and articles of manufacture are disclosed for dynamic network classification using authenticated neighbor detection. An example includes a network comparator to determine whether a network to be connected by a computing device is a managed network based on network configuration information associated with the network, in response to determining the network is not a managed network, a neighbor comparator to determine a number of different computing devices on the network that are managed computing devices, and in response to determining that the number of the managed computing devices satisfies a threshold, a sensor controller to invoke a sensor of the computing device to obtain data from computing devices associated with the network, the computing devices including the managed computing devices.