Endpoint Host Checking for Unmanaged Device Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network location awareness methods fail to provide sufficient information about unmanaged devices, especially when they physically move, as they rely solely on network analysis and heuristics, lacking behavioral interaction data to accurately identify and classify these devices.

Innovation Solution

Implementing endpoint host checking using a Network Admission Control (NAC) device that receives endpoint information from managed devices to identify and classify unmanaged devices, correlating this information with peer devices' functionality to enhance network awareness and provide accurate network-related functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If traditional network analysis and heuristics are used for location awareness, then network identification is provided, but sufficient information about unmanaged devices is not obtained

Engineering Contradiction:
Improveinformation about unmanaged devicesVSAvoidnetwork analysis complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent introduces managed devices as intermediaries that connect to unmanaged devices and report their presence and characteristics to the NAC system. This mediator approach allows information about unmanaged devices to be obtained without requiring direct interaction with them, thus resolving the information loss problem while avoiding the complexity of analyzing unmanaged device traffic directly.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent enables managed devices to automatically detect and report unmanaged devices connected to them. This self-service mechanism allows the network system to gather information about unmanaged devices through the cooperative actions of managed devices, eliminating the need for complex centralized analysis of all network traffic.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If network sensors and traffic fingerprinting are used to identify unmanaged devices, then identification with varying confidence is achieved, but complete identification is not obtained

Engineering Contradiction:
Improvedevice identification accuracyVSAvoididentification efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent combines multiple identification approaches: network sensors and traffic fingerprinting provide initial identification with varying confidence levels, while endpoint host checking on managed devices provides additional verification. By merging these complementary methods, the system achieves complete identification of unmanaged devices while maintaining identification efficiency through the division of labor between passive network analysis and active host checking.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements a feedback mechanism where the NAC system receives identification results from network sensors, correlates them with endpoint host checking data from managed devices, and refines the identification confidence level. This feedback loop allows the system to progressively improve identification accuracy from initial varying confidence to complete identification.

Inventive Principle:
Principle #23Feedback

3Loss of information

If endpoint host checking is implemented using NAC devices, then complete identification of unmanaged devices is achieved, but additional information processing is required

Engineering Contradiction:
Improveunmanaged device informationVSAvoidinformation processing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent segments the information gathering process into two distinct phases: initial identification through network sensors and traffic fingerprinting, followed by verification and completion through endpoint host checking on managed devices. This segmentation allows the system to process information in manageable stages, reducing the overall processing complexity while ensuring complete identification of unmanaged devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary identification of unmanaged devices using network sensors and traffic fingerprinting before initiating endpoint host checking. This preliminary action filters and pre-processes the data, so that subsequent host checking only needs to verify and complete the identification, thereby reducing the complexity of information processing while achieving complete device identification.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If traditional network location awareness is used, then network identification is provided, but location information is not updated when devices physically move

Engineering Contradiction:
Improvelocation awareness accuracyVSAvoidlocation update time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements continuous location awareness by having managed devices continuously report unmanaged device connections to the NAC system. This continuous monitoring ensures that when unmanaged devices physically move to different locations and connect to different managed devices, their location information is automatically and continuously updated, maintaining reliable location awareness without time losses.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS9602372B2Using endpoint host checking to classify unmanaged devices in a network and to improve network location awareness
Publication Date: 2017.03.21 PULSE SECURE LLC
  • US9602372B2 patent drawing
  • US9602372B2 patent drawing
  • US9602372B2 patent drawing

AI summary

A device receives, from a managed device, endpoint information associated with an unmanaged device connected to the managed device in a network. The device also receives unmanaged device information that partially identifies the unmanaged device, and completely identifies the unmanaged device based on the endpoint information and the unmanaged device information.