Global Attacker Database Using Device Fingerprinting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting and preventing cyber attacks, such as blocking IP addresses, are not reliable as attackers can use proxy servers or anonymization services to hide their identity, making it difficult to track and mitigate attacks effectively.
Innovation Solution
A global attacker database utilizing device fingerprinting to uniquely identify attacking devices, generating a fingerprint from characteristics like User Agent, HTTP_ACCEPT headers, and other data points, even if the device changes its IP address or uses anonymization services, and disseminating this information across a cloud-based security service for aggregation and propagation to other security devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If IP address blocking is used to prevent cyber attacks, then attack mitigation is simplified, but reliability of attacker identification deteriorates because attackers can use proxy servers or anonymization services to hide their identity
Solution Approach 1:
The patent creates a fingerprint copy of the attacker's device characteristics (browser version, operating system, hardware configuration, software environment) that can be used to identify the attacker without relying on their IP address. This fingerprint acts as a persistent identifier that travels with the attacker across different IP addresses and proxy servers, resolving the contradiction by providing reliable identification through a copied representation rather than the original IP address.
Solution Approach 2:
The patent introduces a fingerprinting mechanism as an intermediary between the security system and the attacker's identity. Instead of directly tracking the attacker through their changing IP addresses, the system uses device characteristics as an intermediate identifier that remains consistent. This intermediary fingerprint allows the security system to reliably identify attackers even when they use proxy servers or anonymization services, while maintaining ease of operation through automated fingerprint comparison.
2Reliability
If device fingerprinting is implemented to reliably identify attackers, then attacker identification reliability improves, but system complexity increases due to collecting and processing multiple data points
Solution Approach 1:
The patent performs preliminary fingerprinting of the attacker's device during the initial interaction, collecting device characteristics (browser version, operating system, hardware configuration, software environment) before the attack occurs. By establishing the fingerprint in advance, the system avoids the need for complex real-time analysis during the attack, reducing overall system complexity while maintaining high reliability in attacker identification.
Solution Approach 2:
The patent creates a universal fingerprinting system that collects multiple types of device characteristics (browser, OS, hardware, software) into a single comprehensive identifier. This multi-functional approach allows the same fingerprinting mechanism to identify attackers across different attack vectors, proxy servers, and anonymization services, improving reliability without proportionally increasing complexity through standardized data collection and processing procedures.
3Adaptability or versatility
If a global database of attacker fingerprints is created and distributed across security devices, then protection coverage improves for previously untargeted resources, but information aggregation and distribution complexity increases
Solution Approach 1:
The patent merges fingerprint data from multiple security devices into a centralized global database, combining individual device perspectives into a comprehensive attacker profile. This merging allows any security device to access and use attacker fingerprint information from other devices, improving protection coverage across the entire network infrastructure. The complexity is managed through standardized data formats and automated synchronization protocols that enable efficient information aggregation and distribution.
Solution Approach 2:
The patent implements a feedback mechanism where security devices continuously share attacker fingerprint information with the global database, which then distributes updated information back to all devices. This feedback loop ensures that all security devices have access to the latest attacker intelligence, improving adaptability and protection coverage. The automated feedback process manages information distribution complexity through structured data exchange protocols and incremental updates rather than complete redistributions.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
This disclosure describes a global attacker database that utilizes device fingerprinting to uniquely identify devices. For example, a device includes one or more processors and network interface cards to receive network traffic directed to one or more computing devices protected by the device, send, to the remote device, a request for data points of the remote device, wherein the data points include characteristics associated with the remote device, and receive at least a portion of the requested data points. The device also includes a fingerprint module to compare the received portion of the data points to sets of data points associated with known attacker devices, and determine, based on the comparison, whether a first set of data points of a first known attacker device satisfies a similarity threshold. The device also includes an security module to selectively manage, based on the determination, additional network traffic directed to the computing devices.