Security Appliance Fingerprinting for Application Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a computing environment, identifying and associating security entities becomes challenging as the number of entities and transactions increases, making it difficult to maintain network integrity.

Innovation Solution

A security appliance monitors communication between user computers and destination computers, extracts selective information, generates a primary fingerprint, and matches it with an application ID database to assign corresponding application IDs, enabling the identification of security entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive monitoring of all security entities and transactions is implemented, then network integrity is maintained, but system complexity and processing overhead increase significantly

Engineering Contradiction:
Improvenetwork integrityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the identification process into distinct phases: extracting selective information from communications, generating fingerprints from that information, and matching fingerprints against stored templates. This segmentation allows the system to handle large volumes of traffic by processing only relevant features rather than analyzing complete communication data, thereby maintaining network integrity while reducing system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts selective information from communications between security entities, isolating only the necessary identifying features. By taking out and analyzing only the relevant fingerprint data rather than processing entire communication streams, the system maintains comprehensive monitoring capability while significantly reducing processing overhead and system complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If selective information extraction and fingerprinting is implemented, then identification accuracy is improved, but information loss occurs

Engineering Contradiction:
Improveidentification accuracyVSAvoidinformation loss
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent applies local quality by making different parts of the communication data serve different functions: selective information is extracted for identification purposes while other parts are discarded. The fingerprinting process focuses on specific local features that are sufficient for accurate entity identification, achieving high measurement precision without requiring complete information retention.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent creates simplified copies of security entities in the form of fingerprints and templates. These fingerprint copies contain only the essential identifying characteristics needed for accurate identification, allowing the system to maintain high identification accuracy while working with reduced data representations that minimize information loss.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250023870A1System and method for identifying an application initiating a communication in a computing environment
Publication Date: 2025.01.16 ARISTA NETWORKS INC
  • US20250023870A1 patent drawing
  • US20250023870A1 patent drawing
  • US20250023870A1 patent drawing

AI summary

System and method to identify a security entity in a computing environment is disclosed. Communication between a user computer and at least one destination computer by a security appliance is monitored by a security appliance. Selective information from the communication is extracted. A primary fingerprint is generated using a subset of the selective information. The generated primary fingerprint is evaluated for a match in an application ID database. When there is a match, corresponding application ID is assigned to the communication, wherein the application ID is associated with an application that generated the communication.