Passive Device Characterization via Network Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting fraudulent transactions on computing devices are inadequate, particularly in distinguishing between physical, virtual, and container-based devices, and often require active modifications that can alert malicious actors and consume unnecessary network resources.

Innovation Solution

A passive method using a device characterization server that processes observation data from network traffic sessions between a client device and a server, employing a machine learning classifier trained on diverse network traffic patterns to differentiate between physical computing devices, virtual machines, and containers without modifying the client's hardware or software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If active modifications are made to detect device type, then detection accuracy is improved, but malicious actors are alerted and network resources are consumed

Engineering Contradiction:
Improvedevice type detection accuracyVSAvoidalerting malicious actors and network resource consumption
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

A device characterization server acts as an intermediary between the payment system and client devices. This server passively observes network traffic and performs device characterization without requiring active participation from client devices, thereby avoiding alerting malicious actors while maintaining detection accuracy

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses existing network traffic that would naturally occur during payment transactions to perform device characterization. No additional active probes or modifications are sent to client devices, allowing the system to self-service the detection function using already-available data

Inventive Principle:
Principle #25Self-service

2Object-affected harmful factors

If passive observation of network traffic is used, then malicious actors are not alerted, but device characterization accuracy may be reduced

Engineering Contradiction:
Improveavoiding alerting malicious actorsVSAvoiddevice characterization accuracy
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The system analyzes multiple traffic parameters including packet timing, data patterns, protocol usage, and session characteristics to compensate for the passive observation approach. By examining numerous parameters simultaneously, the system maintains high characterization accuracy without requiring active device participation

Inventive Principle:
Principle #35Parameter changes

3Reliability

If device characterization is performed for all transactions, then fraudulent transactions are detected, but network resources are consumed

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system performs comprehensive device characterization only when suspicious patterns are detected or for high-risk transactions, rather than uniformly for all transactions. This partial application of the detection mechanism maintains security reliability while significantly reducing overall network resource consumption

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11362907B2Systems and methods for characterizing a client device
Publication Date: 2022.06.14 PAYPAL INC
  • US11362907B2 patent drawing
  • US11362907B2 patent drawing
  • US11362907B2 patent drawing

AI summary

Techniques are disclosed for passively characterizing a type of host or computing device which may be engaged in a transaction between the host and another computing device. Observation data corresponding to one or more sessions of network traffic between an unclassified host and a second system may be passively generated by a device characterization server. The observation data can be processed by the device characterization server using a machine-learning classifier. The machine-learning classifier can be trained with a set of training data that includes multiple sessions of network traffic from multiple training data hosts. Each session of network traffic includes an exchange of multiple packets in various embodiments, including packets sent from, and packets received by, the training data hosts. Based on the processing, the unclassified host may be characterized by the device characterization server as one of a physical computing device, a virtual machine, or a container.