Network Device Clustering for Security Monitoring and Inventory
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The proliferation of network-connectable devices raises concerns about privacy and security, and it is increasingly difficult to identify and track the number and type of devices connected to a network, especially as the variety and number of devices grow.
Innovation Solution
A method of managing networked devices by generating device attributes from network traffic data, applying clustering operations to assign devices into groups based on shared attributes, and initiating responsive actions when changes in clustering indicate potential threats or legitimate activity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network connectivity is provided to an increasing range of devices, then device functionality and inter-device communication are enhanced, but privacy and security concerns increase and device tracking becomes more difficult
Solution Approach 1:
The patent segments devices into clusters based on their attributes and behavior patterns. By dividing the network into multiple clusters rather than treating all devices uniformly, the system can apply different security policies and monitoring strategies to each cluster, thereby improving overall security while maintaining device versatility.
Solution Approach 2:
The patent introduces a network device that acts as an intermediary between devices and the network. This intermediary collects device attributes, performs clustering operations, and enforces security policies, thereby protecting devices and the network without limiting device functionality.
2Productivity
If the number of network-connectable devices grows, then network capabilities and device interconnectivity improve, but device identification and tracking become increasingly difficult
Solution Approach 1:
The patent segments devices into clusters based on their attributes and behavior patterns. By dividing the network into multiple clusters rather than treating all devices uniformly, the system can apply different security policies and monitoring strategies to each cluster, thereby improving overall security while maintaining device versatility.
Solution Approach 2:
The patent merges devices with similar attributes into the same cluster. By combining multiple devices into clusters based on shared characteristics, the system simplifies device tracking and management while still maintaining the ability to identify and monitor individual devices within each cluster.
3Measurement precision
If device clustering is used to improve security and tracking, then device identification accuracy improves, but system complexity increases
Solution Approach 1:
The patent implements a universal clustering mechanism that can handle multiple device types and attributes through a single system. The network device performs multiple functions including attribute collection, clustering, security policy enforcement, and device tracking, thereby improving identification accuracy without proportionally increasing system complexity.
Solution Approach 2:
The system automatically collects device attributes, performs clustering operations, and updates device records without requiring manual intervention. This self-service approach improves device identification accuracy while minimizing the operational complexity for users.
Data Source
AI summary
Systems and methods for managing network devices include performing clustering operations for network devices based on attributes of the network devices. By comparing the results of subsequent clustering operations, changes in network device attributes can be readily identified and any network devices for which attributes have changed may be subject to further investigation or remedial action (e.g., blocking traffic to/from the network device). Clustering may also be used to conduct an inventory of network devices by identifying groups of network devices that have similar attributes.


