Network Configuration Detection via Logical Inference

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods face difficulties in detecting detailed changes in network configurations within an organization using passive information, as they either focus on internet topology or endpoint/service-based estimations, failing to accurately capture device relationships.

Innovation Solution

A detection device that converts network information into inference rules and uses an inference engine to derive an answer set satisfying both the converted rules and preset constraints, enabling the detection of network configuration changes through logical inference.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If active scanning is performed to estimate network configuration, then network configuration information can be obtained, but the network may be affected

Engineering Contradiction:
Improvenetwork configuration detection accuracyVSAvoidnetwork impact
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent converts the limitation of passive information (insufficient detail) into a benefit by combining it with event logs to achieve accurate network configuration detection without active scanning. The event logs, which would otherwise be unused, are leveraged to extract device roles and relationships, turning a potential harm (incomplete passive data) into a useful resource for network discovery.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Loss of information

If endpoint or service-based estimation is performed, then some network information can be obtained, but detailed device relationships cannot be estimated

Engineering Contradiction:
Improvenetwork information coverageVSAvoiddevice relationship detection accuracy
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The patent segments the network configuration detection into two parts: basic network information from passive traffic and detailed device relationships from event logs. This segmentation allows each data source to be processed with appropriate methods, achieving both broad information coverage and precise device relationship detection without the limitations of endpoint or service-based estimation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces event logs as an intermediary between passive network traffic and device relationship detection. The event logs serve as a bridge that connects IP address information with device roles and relationships, enabling accurate inference of network configuration without directly scanning devices or relying solely on endpoint information.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If passive information analysis is performed, then network information can be obtained without affecting the network, but detailed configuration changes cannot be detected

Engineering Contradiction:
Improvenetwork impactVSAvoidconfiguration change detection accuracy
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The patent merges passive network traffic analysis with event log analysis to achieve detailed configuration change detection. By combining these two information sources, the system maintains the benefit of non-intrusive passive monitoring while overcoming its limitation of insufficient detail, enabling accurate detection of network configuration changes through the complementary information in event logs.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20230316114A1Detection device, detection method, and detection program
Publication Date: 2023.10.05 NIPPON TELEGRAPH & TELEPHONE CORP
  • US20230316114A1 patent drawing
  • US20230316114A1 patent drawing
  • US20230316114A1 patent drawing

AI summary

A detection device (10) converts each of a plurality of pieces of information on a network to a logical equation. The detection device (10) obtains an answer set satisfying a logical equation and an inference rule through inference. It is possible to detect change in a network configuration on the basis of the answer set.