Global Attacker Database Using Device Fingerprinting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting and preventing cyber attacks, such as blocking IP addresses, are not reliable as attackers can use proxy servers or anonymization services to hide their identity, making it difficult to track and mitigate attacks effectively.

Innovation Solution

A global attacker database utilizing device fingerprinting to uniquely identify attacking devices, generating a fingerprint from characteristics like User Agent, HTTP_ACCEPT headers, and other data points, even if the device changes its IP address or uses anonymization services, and disseminating this information across a cloud-based security service for aggregation and propagation to other security devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IP address blocking is used to prevent cyber attacks, then attack mitigation is simplified, but reliability of attacker identification deteriorates because attackers can use proxy servers or anonymization services to hide their identity

Engineering Contradiction:
Improveattack mitigationVSAvoidattacker identification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent creates a fingerprint copy of the attacker's device characteristics (browser version, operating system, hardware configuration, software environment) that can be used to identify the attacker without relying on their IP address. This fingerprint acts as a persistent identifier that travels with the attacker across different IP addresses and proxy servers, resolving the contradiction by providing reliable identification through a copied representation rather than the original IP address.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a fingerprinting mechanism as an intermediary between the security system and the attacker's identity. Instead of directly tracking the attacker through their changing IP addresses, the system uses device characteristics as an intermediate identifier that remains consistent. This intermediary fingerprint allows the security system to reliably identify attackers even when they use proxy servers or anonymization services, while maintaining ease of operation through automated fingerprint comparison.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If device fingerprinting is implemented to reliably identify attackers, then attacker identification reliability improves, but system complexity increases due to collecting and processing multiple data points

Engineering Contradiction:
Improveattacker identificationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary fingerprinting of the attacker's device during the initial interaction, collecting device characteristics (browser version, operating system, hardware configuration, software environment) before the attack occurs. By establishing the fingerprint in advance, the system avoids the need for complex real-time analysis during the attack, reducing overall system complexity while maintaining high reliability in attacker identification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a universal fingerprinting system that collects multiple types of device characteristics (browser, OS, hardware, software) into a single comprehensive identifier. This multi-functional approach allows the same fingerprinting mechanism to identify attackers across different attack vectors, proxy servers, and anonymization services, improving reliability without proportionally increasing complexity through standardized data collection and processing procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If a global database of attacker fingerprints is created and distributed across security devices, then protection coverage improves for previously untargeted resources, but information aggregation and distribution complexity increases

Engineering Contradiction:
Improveprotection coverageVSAvoidinformation aggregation and distribution
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges fingerprint data from multiple security devices into a centralized global database, combining individual device perspectives into a comprehensive attacker profile. This merging allows any security device to access and use attacker fingerprint information from other devices, improving protection coverage across the entire network infrastructure. The complexity is managed through standardized data formats and automated synchronization protocols that enable efficient information aggregation and distribution.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements a feedback mechanism where security devices continuously share attacker fingerprint information with the global database, which then distributes updated information back to all devices. This feedback loop ensures that all security devices have access to the latest attacker intelligence, improving adaptability and protection coverage. The automated feedback process manages information distribution complexity through structured data exchange protocols and incremental updates rather than complete redistributions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2779574B1Attack detection and prevention using global device fingerprinting
Publication Date: 2017.07.05 JUNIPER NETWORKS INC
  • EP2779574B1 patent drawingFigure 1
  • EP2779574B1 patent drawingFigure 2
  • EP2779574B1 patent drawingFigure 3

AI summary

This disclosure describes a global attacker database that utilizes device fingerprinting to uniquely identify devices. For example, a device includes one or more processors and network interface cards to receive network traffic directed to one or more computing devices protected by the device, send, to the remote device, a request for data points of the remote device, wherein the data points include characteristics associated with the remote device, and receive at least a portion of the requested data points. The device also includes a fingerprint module to compare the received portion of the data points to sets of data points associated with known attacker devices, and determine, based on the comparison, whether a first set of data points of a first known attacker device satisfies a similarity threshold. The device also includes an security module to selectively manage, based on the determination, additional network traffic directed to the computing devices.