Network Device Spoofing Detection via Switch Log Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network systems are unable to preemptively identify and block malicious network devices, allowing unauthorized access and data leakage, as they typically detect malicious activity after it has occurred, limiting their ability to provide effective information security and data access control.

Innovation Solution

The system identifies and blocks potentially malicious network devices by comparing device and location information from device logs with actual switch data, activating temporary port leases based on device authentication status, and enabling port authentication to monitor and control access, thereby preventing malicious activities before they occur.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional detection systems are used, then the system can detect malicious devices after they have performed malicious activities, but the system cannot preemptively identify and block malicious devices before they cause harm

Engineering Contradiction:
Improvedetection accuracyVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by comparing device information against stored logs and verifying device identities before allowing network access. This preemptive verification process identifies malicious devices before they can execute harmful activities, resolving the contradiction by maintaining detection accuracy while eliminating the time loss associated with post-incident detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies preliminary anti-action by blocking suspicious devices before they can perform malicious activities. By proactively identifying devices with mismatched information and preventing their network access, the system counteracts potential harm in advance, achieving both reliable detection and timely response.

Inventive Principle:
Principle #9Preliminary anti-action

2Object-affected harmful factors

If the system blocks devices based on information discrepancies, then network security is improved, but false positives may block legitimate devices

Engineering Contradiction:
Improvemalicious activity preventionVSAvoidnetwork access
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system implements feedback by continuously monitoring network traffic and comparing device information against stored logs. When discrepancies are detected, the system can dynamically adjust its response based on the severity and nature of the mismatch, allowing legitimate devices with minor variations to access the network while blocking devices with significant suspicious discrepancies, thus balancing security with ease of operation.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive device verification is performed, then the ability to identify spoofed devices is improved, but the complexity of the system increases

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidverification process
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system applies segmentation by dividing the verification process into distinct stages: initial device connection detection, information extraction, log comparison, and blocking decisions. This segmented approach maintains high measurement precision for device identification while managing system complexity through modular processing steps, each handling a specific aspect of verification.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10375099B2Network device spoofing detection for information security
Publication Date: 2019.08.06 BANK OF AMERICA CORP
  • US10375099B2 patent drawing
  • US10375099B2 patent drawing
  • US10375099B2 patent drawing

AI summary

A system that includes a threat management server configured to store a device log identifying location information for endpoint devices that have passed authentication. The threat management server identifies a first instance and a second instance of an endpoint device in the device log file. The threat management server identifies a first switch connected to the first instance of the endpoint device and a second switch connected to the second instance of the endpoint device. The threat management server sends location information request to the first switch and the second switch requesting location information for the first instance and the second instance of the endpoint device, respectively. The threat management server compared the received location information to the information in the device log file to identify a spoofed instance of the endpoint device and blocks the spoofed instance of the endpoint device from accessing the communications network.