Passive Network Event Attribution via Fingerprinting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network and security systems struggle to map network events to their originating users within internal corporate local area networks, as IP addresses are dynamically leased and do not statically correspond to users, making it difficult for insider threat detection to attribute anonymous network events to their associated users.

Innovation Solution

The method involves filtering network events over a predetermined time interval to generate a filtered event list, where anonymous network events are attributed to users based on nearest-neighbor events or by maximizing an event attribution function, allowing for passive user attribution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If DHCP dynamically leases IP addresses to hosts, then network address allocation flexibility is improved, but IP address to user mapping reliability deteriorates

Engineering Contradiction:
ImproveIP address allocation flexibilityVSAvoidIP address to user mapping reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces passive fingerprinting as an intermediary mechanism between network events and user identification. By analyzing TCP/IP protocol characteristics, window sizes, and timing patterns, the system creates a fingerprint profile that serves as a mediator to link anonymous network events to user identities without relying on direct IP-to-user mapping

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical IP address assignment system with a statistical fingerprinting approach. Instead of relying on static IP mappings or authentication mechanisms, the system uses pattern recognition and probabilistic algorithms to attribute network events to users based on behavioral fingerprints

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Difficulty of detecting and measuring

If passive fingerprinting analyzes network protocols, then application detection capability is improved, but user attribution capability deteriorates

Engineering Contradiction:
Improveapplication detection capabilityVSAvoiduser identity information
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of information

Solution Approach 1:

The patent segments the passive fingerprinting process into two distinct phases: (1) extracting protocol characteristics and timing patterns from network events, and (2) matching these fingerprints against stored user profiles. This segmentation allows the system to maintain application detection capabilities while adding user attribution by separating the detection and identification functions

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary action by pre-establishing user fingerprints through authentication events or initial network behavior analysis. These pre-computed fingerprints serve as reference profiles that enable subsequent network events to be attributed to users without requiring real-time authentication, thus preserving user identity information

Inventive Principle:
Principle #10Preliminary action

3Productivity

If network events are filtered by time interval, then event processing efficiency is improved, but attribution accuracy may deteriorate

Engineering Contradiction:
Improveevent processing efficiencyVSAvoidattribution accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent applies partial action by filtering events based on a predetermined time interval that balances processing efficiency with attribution accuracy. The time window is set to capture sufficient contextual information for accurate fingerprint matching while excluding events that would unnecessarily increase processing complexity

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8996681B2Passively attributing anonymous network events to their associated users
Publication Date: 2015.03.31 THE MITRE CORPORATION
  • US8996681B2 patent drawing
  • US8996681B2 patent drawing
  • US8996681B2 patent drawing

AI summary

Systems, methods, and computer program products for passively attributing anonymous network events to their associated users are provided herein. Embodiments include filtering network events over a pre-determined time interval to generate a filtered event list. In an embodiment, event attribution includes attributing an anonymous network event to a user associated with a nearest-neighbor event relative to the anonymous network event. In another embodiment, event attribution includes attributing an anonymous network event to a user associated with an event in the filtered event list, wherein that user maximizes an event attribution function. In a further embodiment, event attribution includes determining a first potential attribution user for an anonymous network event based on a nearest-neighbor attribution approach; determining a second potential attribution user for the anonymous network event based on an event attribution function approach; and comparing the first and second potential attribution users to determine the attribution of the anonymous event.