Dynamic Network Device Identification via Encoder Similarity Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security methods rely on static scans that fail to account for device changes over time, leading to inaccurate network mappings and security measures.
Innovation Solution
A computer-based method and system that utilize a trained encoder to dynamically assign unique identification codes to devices within a network, comparing identification data to generate similarity scores, and creating a network security map to facilitate security actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If static scans are used for network mapping, then the scanning process is simple and fast, but the accuracy of network mappings deteriorates due to device changes over time
Solution Approach 1:
The patent applies dynamics by transitioning from static network scans to dynamic continuous monitoring. The system performs repeated scans at different time points and compares results to detect device changes, movements, and additions. This dynamic approach ensures network mappings remain accurate despite devices moving or changing states, directly resolving the contradiction between scan simplicity and mapping accuracy.
Solution Approach 2:
The system implements feedback by comparing scan results across multiple time points and using this information to update the network map continuously. The comparison mechanism provides feedback about device changes, enabling the system to adapt and maintain accurate mappings. This feedback loop resolves the contradiction by making the scanning process intelligent and adaptive without excessive complexity.
2Reliability
If continuous monitoring is implemented to track device changes, then the accuracy of security measures improves, but the use of energy and computational resources increases
Solution Approach 1:
The patent applies partial action by performing scans at specific intervals rather than continuously monitoring every moment. The system conducts scans at different time points and compares results, using just enough monitoring to detect changes without excessive resource consumption. This approach maintains security accuracy while optimizing computational resource usage.
Solution Approach 2:
The system maintains continuity of useful action by performing repeated scans and comparisons over time. Rather than single-point checks, the continuous process of scanning and comparing ensures security measures remain accurate while efficiently utilizing resources through automated batch processing of scan results.
3Loss of time
If device movements and changes are tracked in real-time, then the timeliness of security actions improves, but the device complexity increases
Solution Approach 1:
The system applies preliminary action by establishing baseline network maps through initial scans before security incidents occur. These baseline maps are prepared in advance and used for comparison with subsequent scans, enabling rapid detection of changes. This preliminary preparation reduces the complexity of real-time tracking while maintaining timeliness of security responses.
Solution Approach 2:
The patent applies segmentation by dividing the network monitoring task into discrete scan intervals and comparison steps. Rather than complex continuous tracking, the system segments monitoring into periodic scans at different time points, comparing results to detect changes. This segmentation simplifies the tracking system while maintaining real-time security response capability.
Data Source
AI summary
In some embodiments, the present disclosure provides an exemplary method that may include steps of obtaining data associated with a device within a network; determining a digital fingerprint via identification data of the device based on a scan of the network and data associated with the device by: comparing the identification data of the device to a plurality of devices within the, generating a unique identification code that uniquely identifies the device based on a similarity score for the device, and determining the unique identification code for the device based on the digital fingerprint; and generating a network security map that represents a topology of the network, wherein the network security map maps the device within the topology according to the unique identification code so as to facilitate causing at least one security action with respect to the device within the network.


