Network Device Identification Using Passive Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for identifying devices in computer networks, such as network scanning and passive analysis of network traffic, are inefficient and may interrupt running processes or fail to accurately determine device attributes, particularly in cyber-physical systems with obsolete software and complex network architectures.

Innovation Solution

The use of inventory rules to identify network devices by intercepting and analyzing data traffic, applying conditions and weighting factors to determine device parameters such as identifiers, models, security status, and software characteristics, with rules like vendor, asset, protocol, and fingerprint rules to enhance accuracy and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network scanning is used to identify devices, then device identification is achieved, but running processes of equipment may be interrupted

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidprocess continuity
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces a passive analysis system that acts as an intermediary between device identification needs and network traffic. Instead of directly scanning devices (which interrupts processes), the system intercepts and analyzes existing network traffic to extract device information, thereby achieving identification without disrupting running processes

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the active mechanical scanning approach with a passive traffic analysis approach. Rather than sending active scan requests that interrupt devices, the system passively observes and analyzes network traffic packets to extract device identifiers and attributes, substituting the mechanical scan action with information extraction from existing communications

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If passive analysis of network traffic is used, then process interruption is avoided, but determination level of device attributes is low

Engineering Contradiction:
Improveprocess continuityVSAvoiddevice attribute determination
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent applies partial action by selectively analyzing only the portions of network traffic packets that contain device identification information (headers, specific fields) rather than processing entire packets. This allows sufficient device attribute determination while maintaining efficiency and avoiding information overload

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent segments the device identification process into multiple analysis stages: intercepting packets, extracting headers, analyzing specific fields, and determining device attributes. This segmentation allows the system to achieve comprehensive device identification through systematic analysis of different packet components rather than attempting to determine all attributes simultaneously

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If multiple inventory rules are applied to identify devices, then identification accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidinventory rule system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent employs parameter changes by using multiple inventory rules that check different parameters and attributes of devices (device type, manufacturer, model, software version, security status). Each rule evaluates specific parameters, and the combination of rules provides comprehensive device identification through multi-parameter analysis rather than relying on a single complex rule

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11356468B2System and method for using inventory rules to identify devices of a computer network
Publication Date: 2022.06.07 AO KASPERSKY LAB
  • US11356468B2 patent drawing
  • US11356468B2 patent drawing
  • US11356468B2 patent drawing

AI summary

A method for using inventory rules to identify devices of a computer network includes intercepting data traffic across one or more communication links of the computer network. The intercepted data traffic is analyzed to determine whether one or more of a plurality of inventory rules is satisfied by the intercepted data traffic. Each of the plurality of inventory rules includes one or more conditions indicating the presence of a particular computer network device having a set of parameters. Devices of the computer network are identified using one or more satisfied inventory rules.