Network Traffic Fingerprinting for Unauthorized Device Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional device and device-type fingerprinting techniques are inadequate for identifying unauthorized devices within a network, as they often require specific protocols, physical proximity, or expensive hardware, and cannot distinguish between devices and device types effectively, leaving networks vulnerable to insider threats.

Innovation Solution

The method involves analyzing network traffic to generate a signature comprising encoded information about a device's hardware and software architecture, using packet inter-arrival times and statistical analysis to create a feature vector that identifies both device types and individual devices without requiring device-side software clients or physical possession.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional fingerprinting techniques are used, then device identification is possible, but the techniques are limited to specific device types or require physical proximity

Engineering Contradiction:
Improvedevice type coverageVSAvoidoperational constraints
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent applies universality by developing a fingerprinting technique that works across multiple device types (wireless access points, wireless clients, wired devices) without requiring device-specific implementations. The system uses general network traffic analysis principles that can identify any networked device, making the solution universally applicable rather than limited to specific device categories.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses network traffic as an intermediary medium to indirectly identify devices. Instead of directly accessing or physically proximity to the target device, the system analyzes traffic patterns (inter-arrival times, packet sizes, protocols) that carry implicit device information, serving as a mediator between the analyzer and the target device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If protocol-specific fingerprinting techniques are used, then identification accuracy for certain protocols is improved, but the techniques become dependent on particular protocol features

Engineering Contradiction:
Improveidentification accuracyVSAvoidprotocol independence
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent applies parameter changes by analyzing multiple traffic characteristics (inter-arrival times, packet sizes, protocol types) rather than relying on a single protocol-specific feature. The system adapts its analysis parameters based on the observed traffic patterns, allowing it to accurately identify devices across different protocols without being locked into protocol-specific implementations.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If active probing techniques are used, then device identification is achieved, but the target device may be alerted to the identification process

Engineering Contradiction:
Improvedevice identification capabilityVSAvoiddevice alerting
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent applies self-service by having the target device inadvertently reveal its own identification characteristics through its normal network traffic operations. The device's own packet transmission patterns (inter-arrival times, packet sizes) serve as the identification signal without requiring external probing or active manipulation, thus the device is not alerted to the identification process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent converts the potentially harmful effect of network traffic analysis into a beneficial identification mechanism. By analyzing normal traffic patterns that devices already transmit for communication purposes, the system turns what could be considered surveillance into a useful passive identification process that doesn't require active probing.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

4Reliability

If physical possession or close proximity is required for fingerprinting, then identification reliability is improved, but the system becomes dependent on physical access

Engineering Contradiction:
Improveidentification reliabilityVSAvoidphysical access requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces mechanical/physical access requirements with network-based identification. Instead of requiring physical proximity or possession of the target device, the system uses network traffic analysis to remotely identify devices, substituting the mechanical concept of physical access with a network communication-based approach.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

5Measurement precision

If expensive signal-analyzer hardware is used, then fingerprinting effectiveness is improved, but the system becomes cost-dependent

Engineering Contradiction:
Improvefingerprinting effectivenessVSAvoidhardware requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies the principle of using simple, inexpensive analysis methods rather than expensive specialized hardware. The system uses standard network traffic capture and analysis capabilities that can be implemented with conventional networking equipment and software, avoiding the need for costly signal analyzer hardware while maintaining effective device fingerprinting.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS9225732B2Systems and methods for fingerprinting physical devices and device types based on network traffic
Publication Date: 2015.12.29 GEORGIA TECH RES CORP
  • US9225732B2 patent drawing
  • US9225732B2 patent drawing
  • US9225732B2 patent drawing

AI summary

Systems and methods for providing device and/or device type fingerprinting based on properties of network traffic originating from a device to be identified. In one implementation, the method includes capturing packets routed through a network at an intermediate node between the originating device to be identified and destination, measuring properties of the captured traffic, including packet inter-arrival time, and generating a signature based on the measured properties that includes identifying information about the hardware and/or software architecture of the device. Various implementations do not require deep packet inspection, do not require a managed device-side client, are protocol and packet payload agnostic, and effective for MAC or IP-level encrypted streams. Also, various implementations can provide wired-side detection of wireless devices and device types and can detect both previously detected and unknown devices.