Security Appliance Fingerprinting for Application Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In a computing environment, identifying and associating security entities becomes challenging as the number of entities and transactions increases, making it difficult to maintain network integrity.
Innovation Solution
A security appliance monitors communication between user computers and destination computers, extracts selective information, generates a primary fingerprint, and matches it with an application ID database to assign corresponding application IDs, enabling the identification of security entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If comprehensive monitoring of all security entities and transactions is implemented, then network integrity is maintained, but system complexity and processing overhead increase significantly
Solution Approach 1:
The patent segments the identification process into distinct phases: extracting selective information from communications, generating fingerprints from that information, and matching fingerprints against stored templates. This segmentation allows the system to handle large volumes of traffic by processing only relevant features rather than analyzing complete communication data, thereby maintaining network integrity while reducing system complexity.
Solution Approach 2:
The patent extracts selective information from communications between security entities, isolating only the necessary identifying features. By taking out and analyzing only the relevant fingerprint data rather than processing entire communication streams, the system maintains comprehensive monitoring capability while significantly reducing processing overhead and system complexity.
2Measurement precision
If selective information extraction and fingerprinting is implemented, then identification accuracy is improved, but information loss occurs
Solution Approach 1:
The patent applies local quality by making different parts of the communication data serve different functions: selective information is extracted for identification purposes while other parts are discarded. The fingerprinting process focuses on specific local features that are sufficient for accurate entity identification, achieving high measurement precision without requiring complete information retention.
Solution Approach 2:
The patent creates simplified copies of security entities in the form of fingerprints and templates. These fingerprint copies contain only the essential identifying characteristics needed for accurate identification, allowing the system to maintain high identification accuracy while working with reduced data representations that minimize information loss.
Data Source
AI summary
System and method to identify a security entity in a computing environment is disclosed. Communication between a user computer and at least one destination computer by a security appliance is monitored by a security appliance. Selective information from the communication is extracted. A primary fingerprint is generated using a subset of the selective information. The generated primary fingerprint is evaluated for a match in an application ID database. When there is a match, corresponding application ID is assigned to the communication, wherein the application ID is associated with an application that generated the communication.


