Passive User Presence Detection via Network Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current enterprise security systems face challenges in accurately determining user login and logout times due to potential hacking of event logs and manipulation of data packets, necessitating a passive monitoring method to ensure accurate HR and accounting functions.

Innovation Solution

A method and system that collect network traffic from devices to determine login and logoff information over time, generating a timetable to identify user presence and activity, using a gateway, domain controller, and monitor to authenticate and aggregate connection information without requiring software agents on user devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If event logs are maintained on user's device for monitoring, then user activity can be tracked, but the event log is subject to being hacked and manipulated

Engineering Contradiction:
Improveuser presence detection accuracyVSAvoidevent log integrity
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces an intermediary monitoring system that captures network traffic packets between the user device and network resources. Instead of relying on event logs maintained on the user's device (which can be hacked), the system passively monitors authentication packets (such as Kerberos tickets) transmitted over the network. This intermediary approach separates the monitoring function from the user device, preventing direct manipulation of monitoring data while maintaining accurate presence detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If software agent is loaded on user's device for monitoring, then user activity can be monitored, but monitoring is not performed passively and security is compromised

Engineering Contradiction:
Improveuser activity monitoring accuracyVSAvoidsecurity risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the monitoring function from the user's device by removing the need for software agents. Instead of installing monitoring software on user devices, the system extracts authentication information from network traffic packets that naturally occur during normal device operation. This extraction approach allows passive monitoring without modifying or compromising the user device, eliminating security risks associated with installing agents while maintaining accurate activity tracking.

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If network traffic is monitored to identify user, then user presence can be determined, but it is not possible to determine with certainty when user logged on and logged off

Engineering Contradiction:
Improveuser presence detection accuracyVSAvoidlogin/logout timing precision
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by capturing and timestamping authentication packets at the moment of login and logout events. The system is positioned to intercept authentication requests and responses before users can manipulate local logs. By recording the exact timestamps of authentication packets (such as ticket granting service requests and service requests) as they traverse the network, the system establishes an authoritative record of login/logout times that cannot be altered by users, thereby preventing time loss and ensuring precise presence tracking.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11818228B2Establishing user's presence on internal on-premises network over time using network signals
Publication Date: 2023.11.14 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11818228B2 patent drawing
  • US11818228B2 patent drawing
  • US11818228B2 patent drawing

AI summary

Systems and methods for determining a user's presence on a network of an enterprise are provided. Traffic is collected to a network from devices and, over a period of time, login and logoff information from a user is determined from the collected network traffic. Network sessions are determined from a user's login and logoff information and timetable is generated specific to the user that contains the network sessions. The time table identifies when the user was active and when the user was not active based on the login and logoff information and, therefore, present at a particular location over a period of time.