Network Host Inventorying via IP-MAC Correlation and Fingerprinting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network scanning devices face difficulties in accurately inventorying host devices across network segments due to the stripping of uniquely identifying MAC addresses, leading to incomplete and inaccurate host inventory databases, which hinders effective vulnerability scanning.

Innovation Solution

A network scanning device employs a machine learning model to identify and apply optimized tests based on network characteristics and test results, obtaining identifiable information to update the host inventory database, even across network segments, without requiring agents on the segments or host devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If ARP packets are used to discover MAC addresses for host inventory, then host identification accuracy is improved within a single network segment, but the ability to inventory hosts across network segments deteriorates due to MAC address stripping at network boundaries

Engineering Contradiction:
Improvehost identification accuracyVSAvoidcross-segment inventory capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent uses IP addresses as intermediary identifiers that can traverse network segments unlike MAC addresses. The system correlates IP addresses with MAC addresses through network control devices, and uses these IP-MAC mappings to identify hosts across segments. Additionally, fingerprinting data serves as another intermediary to uniquely identify hosts when direct MAC address observation is not possible.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transitions from relying solely on link-layer MAC addresses (single dimension) to incorporating network-layer IP addresses and application-layer fingerprinting characteristics (multiple dimensions). This multi-dimensional identification approach enables host tracking across network segments by using identifiers that persist through network boundaries.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If agents are deployed on every segment or host device to enable cross-segment inventory, then host inventory accuracy across segments is improved, but device complexity and deployment cost increase significantly

Engineering Contradiction:
Improvecross-segment host inventory accuracyVSAvoidagent deployment complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent makes the network scanning device universally capable of inventorying hosts across all network segments without requiring segment-specific agents. By using IP addresses that route across segments and correlating them with MAC addresses through network control devices, a single scanning device can perform comprehensive multi-segment inventorying.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables network control devices to automatically contribute their IP-MAC correlation data to the scanning device without requiring manual configuration or agent deployment. The network infrastructure itself provides the necessary identification information through its normal operation, eliminating the need for additional software agents.

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive vulnerability scanning is performed across all network segments, then network security coverage is improved, but the time and resources required for scanning increase due to incomplete host inventory data

Engineering Contradiction:
Improvenetwork security coverageVSAvoidvulnerability scanning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary host inventorying across all network segments before initiating vulnerability scanning. By establishing complete host identification data including IP addresses, MAC addresses, and fingerprinting characteristics in advance, the system prepares accurate target lists for scanning, eliminating time losses from discovering hosts during the scanning process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses fingerprinting data and network control device correlations as feedback mechanisms to continuously refine and update the host inventory database. This feedback ensures that the inventory remains accurate and complete, enabling efficient vulnerability scanning without repeated discovery attempts or scanning of already-known hosts.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20210194916A1Methods for inventorying network hosts and devices thereof
Publication Date: 2021.06.24 INFINITE GROUP INC
  • US20210194916A1 patent drawing
  • US20210194916A1 patent drawing
  • US20210194916A1 patent drawing

AI summary

Methods, network scanning devices, and non-transitory machine readable media that more effectively and efficiently inventory network hosts to facilitate improved vulnerability scanning are illustrated. With this technology, at least one of a plurality of tests is identified based on an application of a model to one or more characteristics of a network following detection of a host device in a segment of the network. The identified at least one of the plurality of tests is applied on the detected host device to obtain at least one result. The at least one result includes identifiable information for the detected host device. A determination is then made when a classification threshold has been satisfied for the detected host device based at least in part on the identifiable information. A host inventory database is updated to include at least the identifiable information, when the determination indicates the classification threshold has been satisfied.