Automated Network Device Classification for Protection Groups

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Administrators face inefficiencies and inaccuracies in assigning protected devices to protection groups due to the cumbersome process of manual configuration and the lack of real-time adaptation to network changes, leading to reduced effectiveness and increased false alerts.

Innovation Solution

An interactive method using machine learning to classify IP addresses into protection groups, allowing for dynamic assignment based on observed network behavior, with user feedback to refine and automate the process, ensuring optimal protection settings are applied.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If administrators manually assign protected devices to protection groups, then the assignment process is simple and direct, but it is time consuming and tedious

Engineering Contradiction:
Improveease of device assignmentVSAvoidtime for device assignment
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs automated classification of protected devices into protection groups using machine learning algorithms. The classifier automatically analyzes device attributes, network traffic patterns, and behavioral characteristics to assign devices to appropriate protection groups without requiring manual administrator intervention, thereby eliminating the time-consuming manual assignment process while maintaining operational simplicity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the manual mechanical process of device assignment with an automated computational system. Machine learning models and classification algorithms substitute for human administrators in the device assignment task, processing device data and making classification decisions automatically, thus converting a manual operational task into an automated intelligent system.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If administrators create a small number of protection groups to avoid tedious assignment, then the assignment process is simplified, but the granularity of protection settings is reduced

Engineering Contradiction:
Improveease of device assignmentVSAvoidgranularity of protection settings
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The automated classification system handles the complexity of creating and managing numerous granular protection groups without requiring administrator intervention. The machine learning classifier automatically determines the appropriate level of granularity and creates protection groups based on device characteristics, enabling fine-grained protection while maintaining operational simplicity for administrators.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically adjusts the granularity of protection groups based on device behavior and network conditions. Rather than using a fixed number of protection groups, the automated classifier adapts the level of detail and number of groups according to the specific needs identified through machine learning analysis, optimizing both operational ease and protection granularity.

Inventive Principle:
Principle #15Dynamics

3Reliability

If protection group assignments are updated frequently to adapt to network changes, then the protection effectiveness is improved, but the system complexity increases

Engineering Contradiction:
Improveprotection effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements continuous monitoring of network traffic and device behavior, using this feedback to automatically update protection group assignments. The machine learning classifier receives ongoing data about device characteristics and network conditions, processes this feedback, and adjusts classifications accordingly, maintaining protection effectiveness through adaptive updates without requiring complex manual reconfiguration.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The automated classification system performs self-updating of protection group assignments based on changing network conditions and device behavior. The machine learning models continuously learn from new data and automatically reclassify devices when necessary, enabling the system to adapt to changes without increasing operational complexity or requiring manual intervention.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If manual device assignment is used, then the configuration process is straightforward, but false positive alerts and dropped legitimate traffic increase

Engineering Contradiction:
Improveease of configurationVSAvoidaccuracy of protection classification
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent replaces manual configuration with automated machine learning-based classification to improve measurement precision in determining appropriate protection groups. The system analyzes multiple device attributes, network traffic patterns, and behavioral characteristics using computational algorithms, achieving more accurate classification decisions than manual methods while maintaining straightforward operation through automation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The automated classification system independently analyzes device characteristics and determines optimal protection group assignments without human intervention. This self-service approach uses machine learning to evaluate device behavior and network patterns, achieving high classification accuracy that reduces false positives and protects legitimate traffic while keeping the configuration process simple for administrators.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11985043B2Automated classification of network devices to protection groups
Publication Date: 2024.05.14 ARBOR NETWORKS INC
  • US11985043B2 patent drawing
  • US11985043B2 patent drawing
  • US11985043B2 patent drawing

AI summary

A method and system for aggregating into a unique aggregated group (AG), protection groups (PGs) that are possible classifications with at least a threshold probability for a same unique combination of IP addresses. The PGs and the unique combination of IP addresses are included in the AG. Each of the IP addresses of the unique combination of IP addresses have respective associated probabilities for each PG included in the AG. The method further includes selecting and providing for display AGs based on the probabilities associated with the respective IP addresses included in the AGs, and providing for display at least one interactive graphical element in association with each AG selected for display. User activation of one of the interactive graphical element accepts assignment of one or more selected IP addresses included in the AG to a selected one of the one or more PGs included in the AG.