Internet Endpoint Profiling via Search Engine Inversion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for profiling Internet endpoints at a global scale are hindered by the inaccessibility and processing power required for analyzing network traces, making state-of-art packet-level traffic classification tools inapplicable.

Innovation Solution

A method involving generating profiling rules using an Internet search engine by inputting IP addresses to classify endpoints based on search results, utilizing a seed set to create key phrases and URL classes, and associating IP tags with these classifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network traces are analyzed at a global scale, then profiling accuracy is improved, but processing complexity and resource requirements increase significantly

Engineering Contradiction:
Improveprofiling accuracyVSAvoidprocessing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the necessary identifying information (IP addresses, domain names, URLs) from public search results rather than analyzing complete network traces. This extraction approach maintains profiling accuracy by focusing on key identifiers while dramatically reducing processing complexity and data volume.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of starting with network traces and extracting endpoint information, the patent inverts the approach by starting with public search results containing endpoint information and using that to build profiles. This inversion eliminates the need for complex network trace analysis while achieving the same profiling objectives.

Inventive Principle:
Principle #13The other way round (Inversion)

2Measurement precision

If packet-level traffic classification tools are used, then classification precision is improved, but accessibility and resource requirements worsen

Engineering Contradiction:
Improveclassification precisionVSAvoidaccessibility
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent introduces public search engines as an intermediary between the profiling system and endpoint information. Instead of directly accessing and analyzing network traces requiring special permissions, the system uses search engines to retrieve publicly available endpoint information, maintaining classification precision while improving accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses publicly available search results as a copy or representation of network trace information. These search results contain sufficient endpoint identifying information to perform classification without requiring access to actual network traces, making the system more accessible while maintaining precision.

Inventive Principle:
Principle #26Copying

3Loss of information

If extensive network trace data is processed, then profiling completeness is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveprofiling completenessVSAvoidprocessing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent applies partial action by processing only the essential elements needed for endpoint profiling (IP addresses, domain names, URLs) from search results rather than processing complete network trace data. This partial processing approach maintains profiling completeness for the purpose of endpoint characterization while significantly reducing processing time and computational resources.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8019764B1System and method for internet endpoint profiling
Publication Date: 2011.09.13 THE BOEING CO
  • US8019764B1 patent drawing
  • US8019764B1 patent drawing
  • US8019764B1 patent drawing

AI summary

The present invention relates to a method of profiling an Internet endpoint associated with an Internet Protocol (IP) address, the method includes generating a profiling rule using an Internet search engine, obtaining a search result by inputting the IP address to the Internet search engine, and classifying the Internet endpoint based on the search result using the profiling rule.