Layer-2 Network Scanner for Firewall Traversal and Device Profiling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network scanners lack internetwork visibility and cannot traverse or bypass firewalls, making them ineffective in detecting devices that use firewalls to avoid detection.
Innovation Solution
Performing a layer-2 scan of communication networks to collect detailed information about devices, generating device profiles, and using these profiles for inventory control, wireless vendor integration, and security operations, including determining non-benign devices and initiating mitigating actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional network scanners operate at higher layers of the OSI model, then they can perform port discovery and service detection, but they cannot traverse or bypass firewalls and lack internetwork visibility
Solution Approach 1:
The patent transitions from conventional layer-3/Layer-4 scanning to layer-2 scanning, adding a dimensional shift in the OSI model. This enables the scanner to operate at the data link layer where it can capture and analyze frames directly, bypassing firewall restrictions that operate at higher layers. The layer-2 approach provides both port discovery capabilities and firewall traversal by operating at a lower protocol level.
Solution Approach 2:
The patent introduces a layer-2 scanner as an intermediary component that operates between the network infrastructure and target devices. This intermediary captures traffic at the data link layer, performs fingerprinting and device identification, and generates alerts without being blocked by firewalls that filter at higher layers. The scanner acts as a mediator that can see through firewall protections.
2Loss of information
If conventional network scanners are used for port discovery, then service detection is achieved, but internetwork visibility is lost and detection can be avoided by firewalls
Solution Approach 1:
The patent implements layer-2 scanning that provides omnidirectional visibility across the network infrastructure. By operating at the data link layer, the scanner can capture all traffic on the network segment regardless of firewall rules. This dimensional shift enables complete network mapping and device identification without information loss, while maintaining reliable detection of all devices including those protected by firewalls.
Solution Approach 2:
The patent performs preliminary layer-2 scanning and device fingerprinting before higher-layer communication occurs. By establishing visibility at the data link layer first, the system creates a complete inventory of network devices and their characteristics before any application-layer interactions. This preliminary action ensures no devices are missed and provides a foundation for reliable detection throughout the network.
3Measurement precision
If layer-2 scanning is performed to collect detailed device information, then comprehensive device profiling is achieved, but scanning speed and processing time increase
Solution Approach 1:
The patent performs preliminary layer-2 scanning to establish basic device identification, MAC addresses, and network topology. This preliminary information is cached and used to guide subsequent higher-layer scans. By performing the broad layer-2 scan first and storing results, the system avoids redundant scanning and accelerates subsequent device profiling while maintaining comprehensive information collection.
Solution Approach 2:
The patent segments the scanning process into multiple phases: initial layer-2 discovery, followed by targeted layer-3/Layer-4 scanning of identified devices. This segmentation allows the system to collect detailed device information through layer-2 scanning without scanning the entire network at the slowest layer level continuously. The segmented approach maintains measurement precision while improving overall scanning productivity through intelligent phase transitions.
Data Source
AI summary
Systems, methods, and devices for performing a layer-2 scan of one or more communication networks to collect detailed information regarding the components/devices attached to the networks at a particular location (e.g., metropolitan area, city, university campus, building, floor within a building, etc.), and using the collected detailed information to generate a device profile for each of the devices attached to the one or more communication networks at the particular location. A server computing device may use the generated device profiles to perform inventory control operations, wireless vendor integration operations and/or security operations. For example, the server may use the device profiles to determine whether a component/device attached to any of the networks is non-benign (e.g., improperly configured, running malware, operated by hacker, spoofing a server, dropping packets, etc.), and initiate a reactive or mitigating action (e.g., quarantine the device, etc.).


