IP to Name Resolution for Dynamic Network Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Corporate enterprises face challenges in identifying and tracking users and devices on dynamic TCP/IP networks, as IP addresses change frequently, making it difficult to investigate unauthorized access and impossible travel scenarios without resolving them to device names.
Innovation Solution
A method and system for performing IP to name resolution in organizational environments, which involves determining IP addresses, resolving them to device names, generating profiles with timelines, and querying these profiles to determine device name associations with IP addresses over time, using both active and passive monitoring techniques.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If IP addresses are used to identify devices on a network, then network communication can be established, but the ability to track and identify devices deteriorates because IP addresses are dynamic and change frequently
Solution Approach 1:
The patent introduces device names as an intermediary identifier between IP addresses and device identity. Instead of relying solely on IP addresses for device identification, the system resolves IP addresses to device names through DNS queries and network traffic analysis, creating a stable identifier that persists even when IP addresses change dynamically
Solution Approach 2:
The system performs preliminary actions by proactively resolving IP addresses to device names before security incidents occur. The gateway continuously monitors network traffic and proactively queries DNS to obtain device names associated with IP addresses, building a profile of device identities in advance so that when IP addresses change or security incidents occur, the system already has the contextual information needed for reliable device tracking
2Productivity
If IP addresses are monitored alone, then network traffic can be tracked, but security investigation capability deteriorates because IP addresses provide insufficient information to identify devices and detect impossible travel scenarios
Solution Approach 1:
The patent adds another dimension to network monitoring by incorporating device names into the tracking framework. Instead of monitoring only IP addresses (one dimension), the system now monitors both IP addresses and device names, creating a two-dimensional profile that provides richer contextual information for security investigations and enables detection of impossible travel scenarios
Solution Approach 2:
The system creates a profile that copies and preserves device name information alongside IP address data. This profile acts as a persistent record that captures device identities at different points in time, allowing security specialists to investigate past network activity and track device movements even after the original network traffic has occurred
3Measurement precision
If active querying of devices for IP addresses is performed, then accurate device identification can be achieved, but network overhead and processing time increase
Solution Approach 1:
The gateway performs periodic monitoring of network traffic and DNS queries rather than continuous active querying of every device. This periodic action allows the system to collect device name information at natural network interaction points (when devices actually query DNS for IP addresses) without imposing continuous monitoring overhead on the network
Solution Approach 2:
The system leverages the devices' own network behavior to provide identification information. When devices naturally query DNS to resolve hostnames to IP addresses, the gateway intercepts and records these queries, obtaining device name information without requiring the devices to actively report their identities. This self-service approach eliminates the need for separate active querying operations
Data Source
AI summary
A system and method for performing IP to name resolution in organizational environments. IP addresses are determined for devices utilizing the corporate network. An IP address is resolved to a first device name and then the same IP address is subsequently resolved to a second device name. A profile is generated such as a timeline for the IP address including both the first and second device names. The timeline may be queried to determine whether the first device name or the second device name was associated with the IP address during a period of time.


