Passive Device Characterization via Network Traffic Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for detecting fraudulent transactions on computing devices are inadequate, particularly in distinguishing between physical, virtual, and container-based devices, and often require active modifications that can alert malicious actors and consume unnecessary network resources.
Innovation Solution
A passive method using a device characterization server that processes observation data from network traffic sessions between a client device and a server, employing a machine learning classifier trained on diverse network traffic patterns to differentiate between physical computing devices, virtual machines, and containers without modifying the client's hardware or software.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If active modifications are made to detect device type, then detection accuracy is improved, but malicious actors are alerted and network resources are consumed
Solution Approach 1:
A device characterization server acts as an intermediary between the payment system and client devices. This server passively observes network traffic and performs device characterization without requiring active participation from client devices, thereby avoiding alerting malicious actors while maintaining detection accuracy
Solution Approach 2:
The system uses existing network traffic that would naturally occur during payment transactions to perform device characterization. No additional active probes or modifications are sent to client devices, allowing the system to self-service the detection function using already-available data
2Object-affected harmful factors
If passive observation of network traffic is used, then malicious actors are not alerted, but device characterization accuracy may be reduced
Solution Approach 1:
The system analyzes multiple traffic parameters including packet timing, data patterns, protocol usage, and session characteristics to compensate for the passive observation approach. By examining numerous parameters simultaneously, the system maintains high characterization accuracy without requiring active device participation
3Reliability
If device characterization is performed for all transactions, then fraudulent transactions are detected, but network resources are consumed
Solution Approach 1:
The system performs comprehensive device characterization only when suspicious patterns are detected or for high-risk transactions, rather than uniformly for all transactions. This partial application of the detection mechanism maintains security reliability while significantly reducing overall network resource consumption
Data Source
AI summary
Techniques are disclosed for passively characterizing a type of host or computing device which may be engaged in a transaction between the host and another computing device. Observation data corresponding to one or more sessions of network traffic between an unclassified host and a second system may be passively generated by a device characterization server. The observation data can be processed by the device characterization server using a machine-learning classifier. The machine-learning classifier can be trained with a set of training data that includes multiple sessions of network traffic from multiple training data hosts. Each session of network traffic includes an exchange of multiple packets in various embodiments, including packets sent from, and packets received by, the training data hosts. Based on the processing, the unclassified host may be characterized by the device characterization server as one of a physical computing device, a virtual machine, or a container.


