Network Device Clustering via Communication Link Profiles
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for linking devices in a network environment are unreliable and lack accuracy, making it difficult to detect and associate devices with users effectively, which is crucial for protecting against cyberattacks.
Innovation Solution
A method that generates environment profiles for devices with similar communication links by collecting information about devices and their surroundings, using heuristic rules and machine learning models to identify and cluster devices based on communication link characteristics, and modifies the environment profile to defend against cyberattacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional automatic methods of linking devices are used, then device linkage can be established, but the linkage is unreliable and lacks accuracy
Solution Approach 1:
The patent segments the device identification process into multiple independent components: device fingerprints (hardware identifiers), environmental context data, communication patterns, and behavioral characteristics. Each segment is analyzed separately and then combined to form a comprehensive device profile, improving both reliability and precision of device linkage
Solution Approach 2:
The patent changes multiple parameters simultaneously to create a unique device signature: hardware configuration parameters, software environment parameters, network communication parameters, and temporal behavior parameters. This multi-parameter approach transforms the unreliable single-factor identification into a robust multi-dimensional identification system
2Duration of action of stationary object
If devices are linked using removable data such as cookies, then device association can be achieved, but the linkage is not long-lasting
Solution Approach 1:
The patent performs preliminary actions by collecting and analyzing device fingerprints, environmental data, and communication patterns before establishing the device-user linkage. This pre-characterization creates a stable baseline profile that persists beyond temporary data like cookies, ensuring long-lasting and reliable device association
Solution Approach 2:
The patent creates a persistent copy of the device's unique characteristics (hardware identifiers, environmental footprint, communication signature) that is stored and reused for ongoing identification. This copied device profile serves as a permanent reference, replacing temporary identifiers like cookies that can be easily removed
3Object-affected harmful factors
If all devices in a networked environment need to be protected, then comprehensive security can be achieved, but device detection and association becomes more complex
Solution Approach 1:
The patent merges the detection and security functions by integrating device characterization data collection with security monitoring. The same environmental sensors, network analyzers, and behavior trackers used for device identification also serve as security monitoring tools, reducing overall system complexity while achieving comprehensive protection
Solution Approach 2:
The patent creates a universal device profiling system that serves multiple functions simultaneously: device identification, user association, security baseline establishment, and anomaly detection. This multi-functional approach eliminates the need for separate complex detection systems for each security function
Data Source
AI summary
A method for defending a network of electronic devices from cyberattacks includes obtaining information about a plurality of devices and information about communication links between the plurality of devices and surrounding environment and determining types of the communication links using heuristic rules. The types of communication links are compared using corresponding link profiles. One or more similar communication links are identified based on the comparison. A cluster of devices is generated by combining a subset of the plurality of devices. The cluster includes one or more devices having one or more similar communication links. A surrounding environment profile is generated for the generated cluster of devices. When a cyberattack is detected on one of the devices in the cluster, the surrounding environment profile is modified for the cluster of devices in order to defend all devices in the cluster from the cyberattack.


