Persistent Host Identification via MAC Address Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network security systems face challenges in maintaining an accurate snapshot of a dynamic network, leading to degraded performance and inadequate protection, as devices with dynamic IP addresses change, making it difficult to track vulnerabilities and self-identification unreliable.
Innovation Solution
A security manager system with a host profiling module that generates snapshots of network characteristics, including IP addresses, NetBIOS names, and MAC addresses, and a host matching module that uses weighted rules to correlate host instances, ensuring persistent identification and security policy enforcement even with IP address changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If dynamic IP addresses are used to reduce address pool requirements, then fewer IP addresses are needed, but the network security system cannot track devices through address changes
Solution Approach 1:
The patent introduces MAC addresses as an intermediary identifier that remains constant even when IP addresses change. The security system uses MAC addresses to maintain persistent device identification and tracking, while IP addresses are allowed to dynamically change for resource efficiency.
Solution Approach 2:
The system changes the identification parameter from IP address (which changes dynamically) to MAC address (which remains stable). This parameter substitution allows the system to maintain reliable device tracking while still benefiting from dynamic IP address allocation.
2Ease of operation
If service banners are used for device self-identification, then device identification is simplified, but hackers can compromise banners and information is insufficient
Solution Approach 1:
The patent uses MAC addresses as a more reliable intermediary identifier instead of service banners. MAC addresses provide hardware-level identification that cannot be easily compromised or falsified, replacing the vulnerable software-based banner system.
Solution Approach 2:
The system creates a persistent device profile that copies and stores essential device characteristics (MAC address, device type, security posture) independently of transient information like service banners. This profile serves as a reliable reference for device identification.
3Loss of information
If the network security system tracks devices using IP addresses, then security information can be associated with devices, but performance degrades when IP addresses change dynamically
Solution Approach 1:
The patent uses MAC addresses as a stable intermediary to link security information to devices. Instead of re-querying or re-associating security data when IP addresses change, the system maintains continuous linkage through the immutable MAC address, preserving security information without performance degradation.
Data Source
AI summary
A system comprises a security manager to scan a network for host instances representing hosts on the network at that time, and record characteristics of the host instances in a host record. The security manager subsequently scans the network for host instances in order to identify persistent hosts. A host profiling module takes snapshots of the network to generate host instances based on characteristics such as an IP address, a NetBIOS name, a DNS name, a MAC address. A host matching module correlates host instances from different snapshots using weighted rules (predetermined or customized) to discriminate between multiple potential matching host instances. Also, security logic makes security decisions based on data including persistent host information.


