Network Appliance Identification via Behavioral Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional methods for identifying computing devices on a local network are inaccurate, yield incomplete lists, fail to detect new devices, and require devices to implement specific protocols, necessitating a more robust and accurate approach.
Innovation Solution
A system that intercepts network communications and uses a device identification tree with rules to analyze Client IDs and metadata, assigning device labels based on matching conditions, enabling the identification of specific devices on the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional identification methods (MAC Address lookup, host name reverse IP lookup, network discovery protocols) are used, then device identification can be performed with simple implementation, but the identification accuracy is low and device lists are incomplete
Solution Approach 1:
The patent segments the device identification process into multiple independent analysis dimensions: protocol analysis, payload examination, header inspection, and behavioral pattern recognition. Each dimension operates independently to evaluate different aspects of network traffic, allowing the system to build a comprehensive device profile through aggregated results from multiple segmentation points rather than relying on a single identification method
Solution Approach 2:
The identification system is designed to handle multiple device types and communication protocols through a single unified analysis framework. The system can identify both known devices matching database entries and unknown devices through behavioral analysis, making it universally applicable to diverse network environments without requiring device-specific implementation
2Adaptability or versatility
If traditional identification methods are used, then the implementation is straightforward, but the system fails to detect new or unknown devices
Solution Approach 1:
The system performs preliminary behavioral analysis on all network traffic before attempting to match devices against known databases. By examining communication patterns, payload structures, and protocol implementations in advance, the system establishes a baseline behavioral profile that enables identification of unknown devices based on their inherent communication characteristics rather than requiring pre-existing device knowledge
Solution Approach 2:
The patent introduces an intermediary behavioral analysis layer between the network traffic and the device identification database. This intermediary layer translates raw network communications into standardized behavioral metrics that can be compared against both known device signatures and unknown device patterns, serving as a mediator that enables flexible adaptation to new device types while maintaining systematic identification
3Adaptability or versatility
If traditional identification methods are used, then devices must implement agreed upon protocols, but this requirement reduces compatibility with adversarial or uncooperative devices
Solution Approach 1:
Instead of requiring devices to implement specific identification protocols or provide identifying information, the patent inverts the approach by analyzing the device's communication behavior to infer its identity. The system examines how devices communicate rather than what devices say about themselves, allowing identification of uncooperative devices based on their inherent communication patterns rather than self-reported information
Data Source
AI summary
A method, system, and computer program product for identifying network appliances on a network which includes a processor configured to intercept network communications from one or more devices between a first network and a second network. The processor may store the information about each connection in a database, the information including a Client Id and a destination address. The processor may query the database for a list of all destination addresses which were attempted to be contacted for each Client Id and generate metadata for each Client Id. The processor may analyze each Client Id, the associated metadata for each Client Id, and the destination addresses associated with each Client Id using one or more rules in a device identification tree and assign a device label to each Client Id of the one or more devices.


