Network Fingerprinting via Frequency Analysis for Security Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

System administrators often face challenges in detecting and addressing security vulnerabilities in internet-connected assets due to the complexity and variety of hardware devices and software configurations, leading to undetected vulnerabilities.

Innovation Solution

A system and process for determining fingerprints of client networks by analyzing client data, using frequency analysis to identify unique indicators that distinguish between network systems within the client network and those on the Internet, and storing these fingerprints in a database for network mapping and security purposes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If system administrators manually monitor and analyze each internet-connected asset, then security vulnerabilities can be detected and addressed, but the complexity and time required increase significantly due to the large number of diverse devices and configurations

Engineering Contradiction:
Improvesecurity vulnerability detectionVSAvoidtime to detect and address vulnerabilities
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates fingerprints (copies) of network systems that capture essential identifying characteristics. These fingerprints serve as simplified representations that can be quickly compared and matched, eliminating the need for administrators to manually analyze each complex system in detail while maintaining reliable vulnerability detection capability

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent transforms complex network system data into standardized fingerprint parameters consisting of identifying characteristics. By changing the representation from raw system data to structured fingerprint parameters, the system enables rapid comparison and matching operations that reduce analysis time while preserving security detection reliability

Inventive Principle:
Principle #35Parameter changes

2Reliability

If system administrators manually monitor and analyze each internet-connected asset, then security vulnerabilities can be detected and addressed, but the complexity of the monitoring process increases due to the variety of hardware devices and software configurations

Engineering Contradiction:
Improvesecurity vulnerability detectionVSAvoidcomplexity of monitoring system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal fingerprinting system that can handle diverse hardware devices and software configurations through a single standardized approach. The fingerprint structure with identifying characteristics serves as a universal representation that works across different asset types, reducing monitoring system complexity while maintaining reliable vulnerability detection

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent transforms diverse network system configurations into standardized fingerprint parameters. By changing the representation to a common format with identifying characteristics, the system simplifies the monitoring process and reduces complexity while preserving the ability to detect vulnerabilities across different device types

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If comprehensive network scanning is performed to identify all client network systems, then complete network mapping is achieved, but the time and computational resources required increase significantly

Engineering Contradiction:
Improvecompleteness of network mappingVSAvoidtime for network scanning
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent creates fingerprints as simplified copies of network systems that retain essential identifying characteristics. These fingerprints enable rapid matching and identification operations, achieving complete network mapping without requiring time-consuming comprehensive scanning of each system

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent performs preliminary fingerprint creation and storage for network systems. By preparing fingerprints in advance, the system enables rapid network mapping through fingerprint matching rather than requiring comprehensive scanning at the time of mapping, significantly reducing the time required while maintaining completeness

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11777807B2Fingerprint determination for network mapping
Publication Date: 2023.10.03 PALO ALTO NETWORKS INC
  • US11777807B2 patent drawing
  • US11777807B2 patent drawing
  • US11777807B2 patent drawing

AI summary

A set of identifying elements of a first network is determined from a set of data. For each identifying element of the set of identifying elements, a first frequency at which the identifying element is associated with a first set of systems connected to the first network is determined, and a second frequency at which the identifying element is associated with a second set of systems of other networks accessible via the Internet is determined. It is determined if each identifying element is associated with the first set of systems at a greater frequency than with the second set of systems based, at least in part, on the first frequency and the second frequency. If an identifying element is associated with the first set of systems at a greater frequency than with the second set of systems, the identifying element is indicated as a fingerprint of the first network.