Network Tap Points Using Discovery Protocol Metadata
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security and visibility technologies face challenges due to excessive filtering and bandwidth constraints, particularly in dynamic network topologies, which hinder effective monitoring and detection of external attacks and insider threats, and require optimal tapping nodes for network health and efficiency.
Innovation Solution
The implementation of discovery protocols such as DHCP, DNS, mDNS, and LLDP to gather low-volume, high-value metadata for analytics, positioning tap points closer to the network edge and using filtering techniques to enhance network visibility and security, while minimizing bandwidth and resource usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If extensive filtering of network traffic is applied using IP, subnet, or VLAN, then network security and visibility are improved, but coverage is reduced due to excessive filtering
Solution Approach 1:
The patent extracts and analyzes discovery protocol traffic (DNS, mDNS, SSDP, BitTorrent) separately from general network traffic. By isolating these specific protocol types for analysis, the system achieves comprehensive network coverage without requiring extensive filtering of all traffic, thus resolving the contradiction between security filtering and coverage.
Solution Approach 2:
The patent introduces discovery protocol analysis as an intermediary layer between raw network traffic and security analysis. This intermediary approach enables the system to gain network visibility and coverage through specialized protocol inspection without applying broad filtering rules that would reduce overall coverage.
2Loss of information
If discovery protocols are used to discover network resources, then network coverage is improved, but bandwidth and computational resources are consumed
Solution Approach 1:
The patent applies partial action by focusing analysis only on discovery protocol traffic (DNS, mDNS, SSDP, BitTorrent) rather than all network traffic. This selective approach provides comprehensive network coverage through discovery protocols while consuming minimal bandwidth and computational resources by ignoring unrelated traffic.
Solution Approach 2:
The patent changes the analysis parameter from general network traffic inspection to specific discovery protocol inspection. This parameter change enables the system to achieve thorough network coverage by targeting only the relevant protocol types, thereby minimizing resource consumption while maintaining comprehensive visibility.
3Loss of information
If remote deployments use discovery protocols to discover network resources, then network visibility is improved, but optimal tapping nodes cannot be selected in dynamic network topologies
Solution Approach 1:
The patent enables discovery protocols to self-service the network topology discovery function. By allowing DNS, mDNS, SSDP, and BitTorrent protocols to naturally discover and report network resources, the system achieves comprehensive network visibility without requiring complex manual selection or configuration of tapping nodes in dynamic topologies.
Data Source
AI summary
A system may select a list of servers in a computer network to perform behavioural profiling, wherein each server is associated with a domain name, the list of servers includes domain name entries, and the list of servers is prioritized according to a popularity value for each server. The system may update the list of servers based on a popularity threshold, partition the computer network into one of: subnetworks or subdomains, and establish a hierarchy along one of: the subnetworks or the subdomains based on the domain name entries in the list of servers. The system may update the popularity value for a server associated with a resolved network address, and may update the hierarchy along one of: the subnetworks or the subdomains based on the popularity value.


