Hybrid Network Entity Classification Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number and diversity of network-connected devices pose challenges for network security, as existing classification methods are limited by local resources and rely on periodic profile updates, leading to reduced visibility and effectiveness in identifying and securing entities within the network.

Innovation Solution

A hybrid classification architecture utilizing both local and cloud-based classification engines, where the local engine performs initial classification and the cloud engine provides secondary validation and access to updated profiles, optimizing resource usage and scalability by storing popular profiles locally and less common ones in the cloud.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If local classification resources are used, then classification speed is improved, but classification accuracy deteriorates due to limited local profiles

Engineering Contradiction:
Improveclassification speedVSAvoidclassification accuracy
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The classification system is segmented into two parts: a local classification engine that performs rapid initial classification using locally stored profiles, and a cloud-based classification engine that provides comprehensive profile matching for accuracy. This segmentation allows each component to specialize - local for speed and cloud for accuracy - resolving the contradiction between classification speed and accuracy.

Inventive Principle:
Principle #1Segmentation

2Use of energy by moving object

If periodic profile updates are implemented, then resource consumption is reduced, but visibility and security effectiveness deteriorate

Engineering Contradiction:
Improveresource consumptionVSAvoidsecurity effectiveness
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The system implements continuous feedback mechanisms where the local classification engine monitors network traffic and device characteristics in real-time, automatically updating classifications without requiring periodic profile updates. This feedback loop maintains high security effectiveness while minimizing resource consumption by only processing necessary classification data on-demand.

Inventive Principle:
Principle #23Feedback

3Loss of time

If cloud-based classification is used, then profile update frequency is reduced, but resource dependency increases

Engineering Contradiction:
Improveprofile update timeVSAvoidcloud dependency
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system performs preliminary classification actions locally using cached profiles before cloud validation is needed. The local classification engine maintains a cache of recently used profiles and performs initial classifications independently, only contacting the cloud when profile validation or updates are required. This preliminary local action reduces cloud dependency while maintaining accurate classifications.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11876827B2Multiple sourced classification
Publication Date: 2024.01.16 FORESCOUT TECHNOLOGIES INC
  • US11876827B2 patent drawing
  • US11876827B2 patent drawing
  • US11876827B2 patent drawing

AI summary

Systems, methods, and related technologies for improving classification use multiple classification resources. The method includes accessing network traffic from a network comprising a plurality of entities, and determining, based on the network traffic, one or more values associated with one or more properties of an entity of the plurality of entities. The method also includes determining, by a processing device, a first classification result of the entity based on the one or more values and at least one local profile, and determining a second classification result of the entity, wherein the second classification result of the entity is based on the one or more values and at least one remote profile.