IP Classification via Error-Correction Tree and Range Splitting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network traffic analysis solutions face challenges in accurately identifying dynamic and static IP addresses due to the increasing sophistication of cyber threats, which traditional rule-based approaches can no longer effectively address, especially with the dynamic nature of modern networks and the addition/removal of devices.

Innovation Solution

A computer-implemented method using an IP classifier that applies an error-correction tree to classify IP addresses based on network telemetry, predicting whether an IP address is dynamic or static, and recursively splitting IP ranges for improved accuracy through feature extraction and model training, without requiring expensive integration with asset databases or DHCP servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional rule-based approaches are used for IP classification, then the system is simple to implement, but the accuracy of identifying dynamic and static IP addresses deteriorates due to sophisticated cyber threats

Engineering Contradiction:
ImproveIP classification accuracyVSAvoidclassification system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces traditional rule-based mechanical classification systems with machine learning-based IP classifiers. These classifiers use trained models to automatically identify dynamic and static IP addresses by analyzing network telemetry data, achieving higher accuracy without manual rule configuration. The system substitutes complex human-designed rules with adaptive algorithms that learn from data patterns.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent transforms the classification approach by changing from static rule-based parameters to dynamic machine learning model parameters. The system uses trained models with adjustable parameters that adapt to different network environments and threat patterns, allowing accurate classification across diverse scenarios without重新 designing rules for each case.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If machine learning-based IP classification is implemented, then the accuracy of IP classification improves, but the computational resources and time required for analysis increase

Engineering Contradiction:
ImproveIP classification accuracyVSAvoidclassification processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-training machine learning models offline using historical network telemetry data. Once trained, these models are deployed for rapid real-time classification. The feature extraction pipelines are also pre-configured and optimized, allowing the system to quickly process incoming network data without performing complex training operations during live analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts and focuses on the most critical features from network telemetry data for classification, rather than processing all available data. The system identifies and extracts key features such as traffic patterns, port usage, and protocol behavior that are most indicative of dynamic versus static IP characteristics, reducing computational overhead while maintaining high accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If comprehensive network telemetry analysis is performed to improve classification accuracy, then the reliability of IP classification improves, but the complexity of data collection and processing increases

Engineering Contradiction:
ImproveIP classification reliabilityVSAvoiddata collection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements multi-functionality by using the same machine learning-based classification system for multiple purposes: identifying dynamic and static IP addresses, detecting suspicious activities, and analyzing network anomalies. The system processes various types of network telemetry data (NetFlow, IPFIX, PCAP) through unified pipelines, reducing the need for separate specialized systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements self-service by automatically collecting, processing, and classifying network telemetry data without requiring manual intervention. The machine learning models autonomously analyze network patterns and make classification decisions, and the system continuously adapts to new data patterns without requiring reconfiguration by operators.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12164575B1Dynamic computer-based internet protocol classification
Publication Date: 2024.12.10 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12164575B1 patent drawing
  • US12164575B1 patent drawing
  • US12164575B1 patent drawing

AI summary

In an approach to improve internet protocol (IP) classification, embodiments of the present invention classify, by an IP classifier, a set of samples from a given IP range. Further, embodiments utilize the IP classifier to predict whether an IP address is dynamic or static and apply, by a client computer, an error-correction tree to the set of samples. Additionally, embodiments split, by the client computer, the range into two or more sub-ranges of a smaller size in response to determining a classification certainty does not exceed or is not within a predetermined threshold.