Rogue Device Detection Through Network Interface Attestation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing environments are vulnerable to unauthorized electronic devices that can passively monitor or actively inject malicious traffic, compromising security by gaining access to sensitive information or attacking weak points, which are not effectively detected in a timely manner.
Innovation Solution
A cross-comparison method is employed to verify the connectivity and trustworthiness of interfaces between computing devices and network devices using attestation and cross-comparison of network addresses, identifying any unauthorized devices by checking for mismatches or unattested connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network monitoring methods are used, then device connectivity can be monitored, but unauthorized devices cannot be effectively detected in a timely manner
Solution Approach 1:
The system performs preliminary attestation of devices before they are fully integrated into the network. Attestation keys are pre-distributed to authorized devices, and the attestation mechanism is established in advance, enabling immediate detection of unauthorized devices as soon as they attempt to connect, rather than detecting them after they have already compromised the network.
Solution Approach 2:
The system implements continuous feedback loops where attestation information is constantly verified and updated. The attestation status of devices is monitored in real-time, and any changes in device identity or authorization status are immediately detected and reported, enabling timely response to unauthorized device connections.
2Reliability
If comprehensive device verification is implemented, then security is improved, but system complexity increases
Solution Approach 1:
The patent introduces an intermediary attestation mechanism that mediates between devices and the network verification system. Instead of requiring direct complex verification between all network components, the attestation key system acts as an intermediary that simplifies the verification process while maintaining high security standards.
Solution Approach 2:
The system changes the verification parameter from complex continuous monitoring to simplified discrete attestation key verification. By transforming the security verification into checking whether specific attestation keys are present and valid, the system maintains high security while significantly reducing computational and operational complexity.
3Reliability
If all device connections are monitored and verified, then unauthorized access is prevented, but processing overhead and resource consumption increase
Solution Approach 1:
Attestation keys are distributed to devices in advance before they need to be verified on the network. This preliminary action allows devices to self-verify their authorization status without requiring intensive real-time processing, reducing the processing overhead during actual network operations while maintaining strict access control.
Solution Approach 2:
Instead of verifying device identities through complex real-time analysis, the system uses simplified attestation key copies that devices present for verification. This copying approach allows rapid verification of device authorization without the need for resource-intensive continuous monitoring and analysis of device behaviors.
Data Source
AI summary
In some examples, a system receives information from electronic devices comprising network devices and computing devices in a computing environment that are subject to attestations of interfaces of the network devices and the computing devices. For each interface of a given computing device being attested, the system verifies that the interface of the given computing device is connected to an interface of a corresponding network device that is being attested. For each interface of a given network device being attested, the system verifies that the interface of the given network device is connected to an interface of a corresponding computing device that is being attested or an interface of another network device that is being attested. The system detects a presence of an unauthorized electronic device in the computing environment in response to determining that an interface of a computing device being attested or an interface of a network device being attested is not connected to a corresponding interface of an electronic device being attested.


