Home Network Device Identification via Traffic Telemetry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device identification methods in home networks are prone to misclassification due to compromised devices falsifying their identities, leading to inadequate security measures and potential malicious activity, as they can spoof MAC addresses, mDNS, UPnP protocols, and HTTP user agent headers, and may not provide reliable fingerprinting data, especially for IoT devices.

Innovation Solution

A system and method that combines active device fingerprinting probes with network traffic telemetry to verify device identities over time, correlating real-time fingerprinting data with long-term network behavior to detect inconsistencies and reclassify devices accurately, using a home gateway engine that includes a device identification module for robust identification and anomaly detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional device fingerprinting methods (MAC address, mDNS, UPnP, HTTP user agent) are used for device identification, then device classification can be performed quickly, but the identification reliability deteriorates because compromised devices can spoof these identifiers

Engineering Contradiction:
Improvedevice identification reliabilityVSAvoididentification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple identification approaches into a unified system. It merges traditional fingerprinting methods (MAC address, mDNS, UPnP, HTTP user agent) with network traffic behavior analysis and machine learning classification. This combination allows the system to cross-validate identification results and detect spoofing attempts, thereby improving reliability without relying on any single identification method alone.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements continuous feedback mechanisms by monitoring network traffic patterns over time and comparing them against the device's claimed identity. The machine learning model continuously learns from network behavior data and updates its classification decisions. This feedback loop enables the system to detect inconsistencies between a device's reported identity and its actual behavior, improving identification reliability dynamically.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If network traffic monitoring over extended periods is performed to verify device identity, then identification accuracy improves, but the time required for identification increases

Engineering Contradiction:
Improvedevice identity verification accuracyVSAvoididentification time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by collecting and analyzing network traffic data continuously in the background, even before final identification decisions are needed. The machine learning model is pre-trained on normal device behavior patterns, allowing the system to quickly compare new device traffic against established patterns. This preliminary data collection and pre-processing enables faster, more accurate identification without requiring extended real-time monitoring periods.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial action by selecting and analyzing only the most relevant network traffic features and parameters rather than monitoring all possible network activity. It focuses on key behavioral indicators that are most indicative of device identity and spoofing attempts. This selective monitoring approach provides sufficient accuracy for identification while significantly reducing the time and computational resources required compared to comprehensive network traffic analysis.

Inventive Principle:
Principle #16Partial or excessive action

3Object-affected harmful factors

If comprehensive security monitoring is implemented to detect misidentified devices, then security improves, but the system complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity against device spoofingVSAvoidsecurity system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent replaces complex mechanical inspection methods with machine learning-based automated classification. Instead of manually analyzing multiple fingerprinting protocols and network behaviors, the system uses trained machine learning models that automatically process network traffic data and make identification decisions. This substitution reduces the complexity of security monitoring by automating pattern recognition and anomaly detection, making comprehensive security monitoring feasible without proportionally increasing system complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20240283674A1Device identification
Publication Date: 2024.08.22 MCAFEE LLC
  • US20240283674A1 patent drawing
  • US20240283674A1 patent drawing
  • US20240283674A1 patent drawing

AI summary

There is disclosed a computer-implemented system and method of detecting a device that deceptively misidentifies itself on a home network, including sending, to the device, discovery probes, and receiving in response to the discovery probes a self-reported identity; performing a verification of the self-reported identity, comprising over a time greater than one hour, monitoring network traffic from the device to determine whether network traffic over the time is consistent with expected network traffic for the self-reported identity; and upon determining that the network traffic is not consistent, designating the device as potentially deceptively misidentified, and acting to mitigate the device's activity.