Passive User Presence Detection via Network Traffic Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current enterprise security systems face challenges in accurately determining user login and logout times due to potential hacking of event logs and manipulation of data packets, necessitating a passive monitoring method to ensure accurate HR and accounting functions.
Innovation Solution
A method and system that collect network traffic from devices to determine login and logoff information over time, generating a timetable to identify user presence and activity, using a gateway, domain controller, and monitor to authenticate and aggregate connection information without requiring software agents on user devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If event logs are maintained on user's device for monitoring, then user activity can be tracked, but the event log is subject to being hacked and manipulated
Solution Approach 1:
The patent introduces an intermediary monitoring system that captures network traffic packets between the user device and network resources. Instead of relying on event logs maintained on the user's device (which can be hacked), the system passively monitors authentication packets (such as Kerberos tickets) transmitted over the network. This intermediary approach separates the monitoring function from the user device, preventing direct manipulation of monitoring data while maintaining accurate presence detection.
2Measurement precision
If software agent is loaded on user's device for monitoring, then user activity can be monitored, but monitoring is not performed passively and security is compromised
Solution Approach 1:
The patent extracts the monitoring function from the user's device by removing the need for software agents. Instead of installing monitoring software on user devices, the system extracts authentication information from network traffic packets that naturally occur during normal device operation. This extraction approach allows passive monitoring without modifying or compromising the user device, eliminating security risks associated with installing agents while maintaining accurate activity tracking.
3Measurement precision
If network traffic is monitored to identify user, then user presence can be determined, but it is not possible to determine with certainty when user logged on and logged off
Solution Approach 1:
The patent applies preliminary action by capturing and timestamping authentication packets at the moment of login and logout events. The system is positioned to intercept authentication requests and responses before users can manipulate local logs. By recording the exact timestamps of authentication packets (such as ticket granting service requests and service requests) as they traverse the network, the system establishes an authoritative record of login/logout times that cannot be altered by users, thereby preventing time loss and ensuring precise presence tracking.
Data Source
AI summary
Systems and methods for determining a user's presence on a network of an enterprise are provided. Traffic is collected to a network from devices and, over a period of time, login and logoff information from a user is determined from the collected network traffic. Network sessions are determined from a user's login and logoff information and timetable is generated specific to the user that contains the network sessions. The time table identifies when the user was active and when the user was not active based on the login and logoff information and, therefore, present at a particular location over a period of time.


