Network Asset Identification with Passive Traffic and Weak MAC Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Identifying and managing assets on complex networks is challenging due to the proliferation of diverse networked devices, including IoT and OT systems, MAC address randomization, and inconsistent data from various sources, leading to inaccurate inventories and security risks.

Innovation Solution

A computer-implemented method using machine learning models and network monitoring to analyze MAC addresses, consolidate asset identifiers, and enrich asset properties, including operating systems and applications, to accurately identify and manage network assets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional active network scanning is used for asset identification, then asset inventory can be obtained, but network disruption occurs and completeness is limited

Engineering Contradiction:
Improveasset identification accuracyVSAvoidnetwork disruption
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent uses network traffic flow data as an intermediary to identify assets without directly scanning them. By analyzing packet captures and flow records from network infrastructure, the system extracts asset information passively, avoiding the disruptive nature of active scanning while maintaining identification accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces mechanical active scanning methods with data-driven analysis of existing network traffic. Instead of actively probing devices, the system uses machine learning models to analyze passive network flow data, substituting direct mechanical interaction with indirect observational analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If MAC address randomization is implemented for privacy, then user privacy is protected, but device tracking and identification becomes difficult

Engineering Contradiction:
Improveuser privacy protectionVSAvoiddevice identification accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent employs multiple identification mechanisms simultaneously - MAC addresses, device names, operating system characteristics, and application profiles. This multi-functional approach ensures that even when MAC addresses are randomized, the system can still reliably identify devices through alternative attributes, maintaining both privacy and identification accuracy.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically adjusts identification parameters by switching between different device attributes based on availability and reliability. When MAC addresses are unreliable due to randomization, the system transitions to using other parameters like device names, OS versions, and application signatures to maintain accurate device identification.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If multiple data sources are integrated for asset characteristics, then identification completeness improves, but data consistency and consolidation becomes challenging

Engineering Contradiction:
Improveasset information completenessVSAvoiddata consolidation complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent consolidates data from multiple sources including endpoint agents, network flow analyzers, and cloud services into a unified asset profile. By merging these diverse data streams through standardized processing pipelines and machine learning models, the system achieves comprehensive asset information while managing consolidation complexity through automated reconciliation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system creates composite asset profiles that integrate information from multiple sources into a unified representation. Each asset profile combines characteristics from network traffic analysis, endpoint software data, and cloud service information, creating a composite view that leverages the strengths of each data source while managing complexity through standardized integration frameworks.

Inventive Principle:
Principle #40Composite materials

4Adaptability or versatility

If diverse networked devices including IoT and OT systems are included, then network coverage improves, but identification accuracy decreases due to inability to run security agents

Engineering Contradiction:
Improvedevice type coverageVSAvoidasset identification accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent segments the identification approach by device type, using agent-based methods for traditional devices and agentless network analysis for IoT and OT devices. This segmentation allows the system to maintain high identification accuracy across diverse device types by applying the most appropriate identification methodology to each segment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

For devices that cannot run agents, the system uses network traffic flow data as an intermediary to extract identification information. By analyzing packets and flows from IoT and OT devices, the system can identify these devices accurately without requiring direct software installation, maintaining both coverage and precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250247391A1Systems and methods for asset identification
Publication Date: 2025.07.31 ARMIS SECURITY LTD
  • US20250247391A1 patent drawing
  • US20250247391A1 patent drawing
  • US20250247391A1 patent drawing

AI summary

The present disclosure provides systems and methods for asset identification and consolidation in a network. In some implementations, the methods involve receiving data including a plurality of media access control (MAC) addresses from at least one source, analyzing the received MAC addresses to determine one or more MAC addresses that are repeated in the received data, and labeling the repeated MAC addresses as weak identifiers for asset identification. Some implementations herein enable improved accuracy in identifying and consolidating network assets by distinguishing between reliable and unreliable identifiers, thereby enhancing network security and management capabilities.