Passive Network Event Attribution via Fingerprinting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network and security systems struggle to map network events to their originating users within internal corporate local area networks, as IP addresses are dynamically leased and do not statically correspond to users, making it difficult for insider threat detection to attribute anonymous network events to their associated users.
Innovation Solution
The method involves filtering network events over a predetermined time interval to generate a filtered event list, where anonymous network events are attributed to users based on nearest-neighbor events or by maximizing an event attribution function, allowing for passive user attribution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If DHCP dynamically leases IP addresses to hosts, then network address allocation flexibility is improved, but IP address to user mapping reliability deteriorates
Solution Approach 1:
The patent introduces passive fingerprinting as an intermediary mechanism between network events and user identification. By analyzing TCP/IP protocol characteristics, window sizes, and timing patterns, the system creates a fingerprint profile that serves as a mediator to link anonymous network events to user identities without relying on direct IP-to-user mapping
Solution Approach 2:
The patent replaces the mechanical IP address assignment system with a statistical fingerprinting approach. Instead of relying on static IP mappings or authentication mechanisms, the system uses pattern recognition and probabilistic algorithms to attribute network events to users based on behavioral fingerprints
2Difficulty of detecting and measuring
If passive fingerprinting analyzes network protocols, then application detection capability is improved, but user attribution capability deteriorates
Solution Approach 1:
The patent segments the passive fingerprinting process into two distinct phases: (1) extracting protocol characteristics and timing patterns from network events, and (2) matching these fingerprints against stored user profiles. This segmentation allows the system to maintain application detection capabilities while adding user attribution by separating the detection and identification functions
Solution Approach 2:
The patent performs preliminary action by pre-establishing user fingerprints through authentication events or initial network behavior analysis. These pre-computed fingerprints serve as reference profiles that enable subsequent network events to be attributed to users without requiring real-time authentication, thus preserving user identity information
3Productivity
If network events are filtered by time interval, then event processing efficiency is improved, but attribution accuracy may deteriorate
Solution Approach 1:
The patent applies partial action by filtering events based on a predetermined time interval that balances processing efficiency with attribution accuracy. The time window is set to capture sufficient contextual information for accurate fingerprint matching while excluding events that would unnecessarily increase processing complexity
Data Source
AI summary
Systems, methods, and computer program products for passively attributing anonymous network events to their associated users are provided herein. Embodiments include filtering network events over a pre-determined time interval to generate a filtered event list. In an embodiment, event attribution includes attributing an anonymous network event to a user associated with a nearest-neighbor event relative to the anonymous network event. In another embodiment, event attribution includes attributing an anonymous network event to a user associated with an event in the filtered event list, wherein that user maximizes an event attribution function. In a further embodiment, event attribution includes determining a first potential attribution user for an anonymous network event based on a nearest-neighbor attribution approach; determining a second potential attribution user for the anonymous network event based on an event attribution function approach; and comparing the first and second potential attribution users to determine the attribution of the anonymous event.


