Network Device Type Identification from Port State Features
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security scan solutions fail to accurately identify the device type of network-connected devices due to the erasure of port identities for security reasons.
Innovation Solution
A method involving transmitting port open/closed state probe packets to target devices, receiving and extracting port open/closed state information, performing decision classification using a decision tree classifier, and determining device types based on the classification results.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional security scan solutions use port request packets to identify device types, then device type identification can be performed, but identification accuracy deteriorates because port identities are erased for security reasons
Solution Approach 1:
The patent extracts the identification task from relying on port identities and instead focuses on extracting features from port open/closed state information. By taking out the dependency on erased port identities and substituting with alternative observable features, the solution resolves the contradiction between needing identification accuracy and facing information loss.
Solution Approach 2:
The patent changes the identification parameters from port identities to port open/closed state features. By transforming the basis of identification from erased identity information to observable state information, the solution maintains identification capability while adapting to the security constraint that erases port identities.
2Measurement precision
If port open/closed state probe packets are transmitted to multiple target devices, then device type identification accuracy is improved, but the number of probe packets and time consumption increase
Solution Approach 1:
The patent applies partial action by transmitting probe packets to at least two target devices rather than exhaustive scanning of all devices or all ports. By selecting a minimal sufficient sample size for classification, the solution achieves accurate device type identification while minimizing time consumption and probe packet transmission.
3Productivity
If conventional security scan solutions analyze message data from port requests, then device type can be determined, but identification fails when port identities are erased
Solution Approach 1:
The patent introduces port open/closed state information as an intermediary between the probe packets and device type determination. This intermediary carries identification-relevant features without relying on erased port identities, thus maintaining identification efficiency while ensuring reliability in the presence of security-based information erasure.
Data Source
AI summary
This application relates to a device type identification method performed by a computer device. The method includes: transmitting a port open/closed state probe packet to at least two target devices; receiving port open/closed state information returned by the at least two target devices in response to the port open/closed state probe packet, wherein the port open/closed state information comprises port open/closed state vectors indicating whether each port of the at least two target devices is open or closed; extracting a port open/closed state feature from the port open/closed state information; performing decision classification on the port open/closed state feature through a decision tree classifier; and determining a device type of each of the at least two target devices according to a result obtained from the decision classification.


