Network Device Spoofing Detection via Switch Log Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network systems are unable to preemptively identify and block malicious network devices, allowing unauthorized access and data leakage, as they typically detect malicious activity after it has occurred, limiting their ability to provide effective information security and data access control.
Innovation Solution
The system identifies and blocks potentially malicious network devices by comparing device and location information from device logs with actual switch data, activating temporary port leases based on device authentication status, and enabling port authentication to monitor and control access, thereby preventing malicious activities before they occur.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional detection systems are used, then the system can detect malicious devices after they have performed malicious activities, but the system cannot preemptively identify and block malicious devices before they cause harm
Solution Approach 1:
The system performs preliminary actions by comparing device information against stored logs and verifying device identities before allowing network access. This preemptive verification process identifies malicious devices before they can execute harmful activities, resolving the contradiction by maintaining detection accuracy while eliminating the time loss associated with post-incident detection.
Solution Approach 2:
The system applies preliminary anti-action by blocking suspicious devices before they can perform malicious activities. By proactively identifying devices with mismatched information and preventing their network access, the system counteracts potential harm in advance, achieving both reliable detection and timely response.
2Object-affected harmful factors
If the system blocks devices based on information discrepancies, then network security is improved, but false positives may block legitimate devices
Solution Approach 1:
The system implements feedback by continuously monitoring network traffic and comparing device information against stored logs. When discrepancies are detected, the system can dynamically adjust its response based on the severity and nature of the mismatch, allowing legitimate devices with minor variations to access the network while blocking devices with significant suspicious discrepancies, thus balancing security with ease of operation.
3Measurement precision
If comprehensive device verification is performed, then the ability to identify spoofed devices is improved, but the complexity of the system increases
Solution Approach 1:
The system applies segmentation by dividing the verification process into distinct stages: initial device connection detection, information extraction, log comparison, and blocking decisions. This segmented approach maintains high measurement precision for device identification while managing system complexity through modular processing steps, each handling a specific aspect of verification.
Data Source
AI summary
A system that includes a threat management server configured to store a device log identifying location information for endpoint devices that have passed authentication. The threat management server identifies a first instance and a second instance of an endpoint device in the device log file. The threat management server identifies a first switch connected to the first instance of the endpoint device and a second switch connected to the second instance of the endpoint device. The threat management server sends location information request to the first switch and the second switch requesting location information for the first instance and the second instance of the endpoint device, respectively. The threat management server compared the received location information to the information in the device log file to identify a spoofed instance of the endpoint device and blocks the spoofed instance of the endpoint device from accessing the communications network.


