Network Device Identification via Feature Transformation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems face challenges in identifying and classifying devices on private networks, particularly in feature-poor environments, which can hinder the effectiveness of malware protection and compatibility with security appliances.
Innovation Solution
A method is developed to transform feature-rich device characteristics into feature-poor characteristics, allowing for the creation of statistical models that can identify network devices in both feature-rich and feature-poor environments, reducing the workload for developers by using the same data set for training models across different platforms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If feature-rich device characteristics are used for device identification, then identification accuracy is improved, but device complexity and resource requirements increase
Solution Approach 1:
The patent extracts only the necessary feature-poor characteristics from the complete feature-rich data set, transforming comprehensive device characteristics into a simplified subset that maintains identification capability while reducing complexity. This is achieved through dimensionality reduction techniques that select and transform relevant features.
Solution Approach 2:
The patent changes the parameters of device characteristics by transforming feature-rich data into feature-poor representations through statistical modeling and dimensionality reduction. This parameter transformation allows the system to operate with reduced feature sets while maintaining identification accuracy through learned statistical relationships.
2Measurement precision
If separate models are trained for feature-rich and feature-poor environments, then model accuracy is improved, but development workload and time increase
Solution Approach 1:
The patent creates a universal training framework where a single statistical model can be trained on transformed feature-poor data and then deployed to both feature-rich and feature-poor environments. This multi-functional approach allows the same model to serve multiple deployment scenarios, eliminating the need for separate development cycles.
Solution Approach 2:
The patent performs preliminary transformation of feature-rich data into feature-poor representations during the training phase, preparing the data in advance to match the constraints of feature-poor environments. This preliminary action ensures that the model learns from data that reflects the actual deployment conditions, improving transferability.
3Reliability
If ARP spoofing is used to monitor network traffic, then malware detection capability is improved, but compatibility with various routers and devices decreases
Solution Approach 1:
The patent changes the parameters of network monitoring by transforming the data representation from feature-rich to feature-poor characteristics. This transformation allows the ARP spoofing mechanism to work effectively across different router and device types by focusing on essential, universally-available network features rather than device-specific characteristics.
Data Source
AI summary
A method of identifying network devices includes transforming a first data set of feature-rich device characteristics of devices with known device identities to a second data set comprising feature-poor device characteristics with the known device identities. A third data set of feature-poor device characteristics of devices with known identities is collected. A statistical model is derived comprising one or more adjustments to the transformed data set, the statistical model reflecting a difference in statistical distribution between one or more characteristics of the second data set of transformed device characteristics and one or more corresponding and/or related characteristics of the third data set of feature-poor device characteristics. A device identification module is trained based on the second data set of feature-poor characteristics and the statistical model adjustments, the trained device identification module operable to use feature-poor device characteristics to identify network devices.


