Persistent Host Identification via MAC Address Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security systems face challenges in maintaining an accurate snapshot of a dynamic network, leading to degraded performance and inadequate protection, as devices with dynamic IP addresses change, making it difficult to track vulnerabilities and self-identification unreliable.

Innovation Solution

A security manager system with a host profiling module that generates snapshots of network characteristics, including IP addresses, NetBIOS names, and MAC addresses, and a host matching module that uses weighted rules to correlate host instances, ensuring persistent identification and security policy enforcement even with IP address changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If dynamic IP addresses are used to reduce address pool requirements, then fewer IP addresses are needed, but the network security system cannot track devices through address changes

Engineering Contradiction:
Improvenumber of IP addressesVSAvoiddevice tracking accuracy
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent introduces MAC addresses as an intermediary identifier that remains constant even when IP addresses change. The security system uses MAC addresses to maintain persistent device identification and tracking, while IP addresses are allowed to dynamically change for resource efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the identification parameter from IP address (which changes dynamically) to MAC address (which remains stable). This parameter substitution allows the system to maintain reliable device tracking while still benefiting from dynamic IP address allocation.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If service banners are used for device self-identification, then device identification is simplified, but hackers can compromise banners and information is insufficient

Engineering Contradiction:
Improvedevice self-identificationVSAvoididentification accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent uses MAC addresses as a more reliable intermediary identifier instead of service banners. MAC addresses provide hardware-level identification that cannot be easily compromised or falsified, replacing the vulnerable software-based banner system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a persistent device profile that copies and stores essential device characteristics (MAC address, device type, security posture) independently of transient information like service banners. This profile serves as a reliable reference for device identification.

Inventive Principle:
Principle #26Copying

3Loss of information

If the network security system tracks devices using IP addresses, then security information can be associated with devices, but performance degrades when IP addresses change dynamically

Engineering Contradiction:
Improvesecurity information retentionVSAvoidsecurity system performance
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent uses MAC addresses as a stable intermediary to link security information to devices. Instead of re-querying or re-associating security data when IP addresses change, the system maintains continuous linkage through the immutable MAC address, preserving security information without performance degradation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9280667B1Persistent host determination
Publication Date: 2016.03.08 TRIPWIRE INC
  • US9280667B1 patent drawing
  • US9280667B1 patent drawing
  • US9280667B1 patent drawing

AI summary

A system comprises a security manager to scan a network for host instances representing hosts on the network at that time, and record characteristics of the host instances in a host record. The security manager subsequently scans the network for host instances in order to identify persistent hosts. A host profiling module takes snapshots of the network to generate host instances based on characteristics such as an IP address, a NetBIOS name, a DNS name, a MAC address. A host matching module correlates host instances from different snapshots using weighted rules (predetermined or customized) to discriminate between multiple potential matching host instances. Also, security logic makes security decisions based on data including persistent host information.