Network Device Identification via Behavioral Fingerprinting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network management systems face challenges in uniquely identifying devices connected to a network due to MAC address randomization, which prevents accurate device inventory, traceability, and security management.
Innovation Solution
A system that analyzes network traffic to build profiles of device characteristics, merging profiles associated with different MAC addresses if they correspond to the same device, using characteristics such as DHCP hostname, FQDN, device behavior patterns, and network characteristics to create a unique identification 'fingerprint' for each device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If MAC address randomization is implemented to protect device privacy and security, then device identity security is improved, but network management and device identification capability deteriorates
Solution Approach 1:
The patent introduces network behavior characteristics as an intermediary identifier. Instead of directly using MAC addresses for identification, the system observes and analyzes intermediate behavioral patterns (packet timing, flow characteristics, protocol usage) that serve as mediators between the device and the network management system, enabling identification without exposing the device's true identity
Solution Approach 2:
The system changes the identification parameters from static MAC addresses to dynamic network behavior parameters. By monitoring and analyzing changing parameters such as packet inter-arrival times, data flow patterns, and communication protocols, the system can identify devices based on their behavioral fingerprint rather than their identity label
2Adaptability or versatility
If MAC address changes are allowed to protect privacy, then device anonymity is improved, but network inventory accuracy deteriorates
Solution Approach 1:
The system maintains continuous monitoring of network behavior characteristics across multiple time periods and communication sessions. By continuously collecting and analyzing behavioral data even when MAC addresses change, the system ensures uninterrupted device identification capability, maintaining both anonymity and inventory accuracy over time
Solution Approach 2:
The system implements feedback mechanisms where observed network behaviors are continuously analyzed and used to update device profiles. When MAC addresses change, the feedback loop detects behavioral patterns that indicate the same device, allowing the system to correct and maintain accurate inventory records despite identity changes
Data Source
AI summary
Techniques are described for analyzing information network traffic to identify distinct devices connected to a network based on characteristics exhibited by the devices. Techniques may analyze some or all of network characteristics, device behavioral patterns, and/or device characteristics detected in network traffic. One or more of these characteristics, may be assigned to a profile associated with a device. This profile, by establishing one or more patterns of behavior and/or characteristics, may be used as a “fingerprint” to uniquely identify a device connected to a network even for devices that employ randomized identifiers, such as MAC addresses, that would otherwise obscure unique identification of the device. Profiles exhibiting similar patterns of behaviors and/or characteristics may be identified and merged to avoid duplicate identification of a same device.


