Network Device Identification Using Passive Traffic Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for identifying devices in computer networks, such as network scanning and passive analysis of network traffic, are inefficient and may interrupt running processes or fail to accurately determine device attributes, particularly in cyber-physical systems with obsolete software and complex network architectures.
Innovation Solution
The use of inventory rules to identify network devices by intercepting and analyzing data traffic, applying conditions and weighting factors to determine device parameters such as identifiers, models, security status, and software characteristics, with rules like vendor, asset, protocol, and fingerprint rules to enhance accuracy and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network scanning is used to identify devices, then device identification is achieved, but running processes of equipment may be interrupted
Solution Approach 1:
The patent introduces a passive analysis system that acts as an intermediary between device identification needs and network traffic. Instead of directly scanning devices (which interrupts processes), the system intercepts and analyzes existing network traffic to extract device information, thereby achieving identification without disrupting running processes
Solution Approach 2:
The patent replaces the active mechanical scanning approach with a passive traffic analysis approach. Rather than sending active scan requests that interrupt devices, the system passively observes and analyzes network traffic packets to extract device identifiers and attributes, substituting the mechanical scan action with information extraction from existing communications
2Reliability
If passive analysis of network traffic is used, then process interruption is avoided, but determination level of device attributes is low
Solution Approach 1:
The patent applies partial action by selectively analyzing only the portions of network traffic packets that contain device identification information (headers, specific fields) rather than processing entire packets. This allows sufficient device attribute determination while maintaining efficiency and avoiding information overload
Solution Approach 2:
The patent segments the device identification process into multiple analysis stages: intercepting packets, extracting headers, analyzing specific fields, and determining device attributes. This segmentation allows the system to achieve comprehensive device identification through systematic analysis of different packet components rather than attempting to determine all attributes simultaneously
3Measurement precision
If multiple inventory rules are applied to identify devices, then identification accuracy is improved, but system complexity increases
Solution Approach 1:
The patent employs parameter changes by using multiple inventory rules that check different parameters and attributes of devices (device type, manufacturer, model, software version, security status). Each rule evaluates specific parameters, and the combination of rules provides comprehensive device identification through multi-parameter analysis rather than relying on a single complex rule
Data Source
AI summary
A method for using inventory rules to identify devices of a computer network includes intercepting data traffic across one or more communication links of the computer network. The intercepted data traffic is analyzed to determine whether one or more of a plurality of inventory rules is satisfied by the intercepted data traffic. Each of the plurality of inventory rules includes one or more conditions indicating the presence of a particular computer network device having a set of parameters. Devices of the computer network are identified using one or more satisfied inventory rules.


