Unauthorized Device Location Tracing via Selective FDB Queries
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large-scale networks, identifying the connection location of unauthorized devices is inefficient due to the large amount of data in forwarding databases (FDBs) and the need for high processing power and memory capacity, which simple devices cannot handle effectively.
Innovation Solution
A location identification apparatus that uses a processing unit to acquire and process connection port information through a series of steps, reducing the need to acquire all FDB information from each network device, even with low processing power and memory capacity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If the SNMP manager requests and acquires all FDB information from each SNMP agent to identify unauthorized device locations, then the identification accuracy is improved, but the time required and processing resources increase significantly
Solution Approach 1:
The patent extracts only the necessary FDB information related to unauthorized devices rather than acquiring all FDB data. The SNMP manager selectively requests FDB entries containing specific unauthorized device MAC addresses, thereby maintaining identification accuracy while significantly reducing the time and processing resources required.
Solution Approach 2:
Instead of performing complete FDB acquisition from all network devices, the patent applies partial action by requesting only specific FDB entries that contain the unauthorized device information. This selective approach achieves sufficient identification accuracy without the excessive time cost of complete data collection.
2Productivity
If a management device with high processing power and memory capacity is used to handle all FDB data, then the identification capability is improved, but the device complexity and cost increase
Solution Approach 1:
The patent extracts only the essential FDB information needed for unauthorized device identification, allowing simple management devices with limited processing power and memory to effectively perform identification tasks without requiring complex hardware configurations.
Solution Approach 2:
By implementing partial action through selective FDB information requests, the patent enables simple management devices to achieve adequate identification capability without needing high processing power and large memory capacity, thereby reducing device complexity and cost.
3Loss of information
If all FDB information is acquired and stored for analysis, then the completeness of information is improved, but the memory capacity requirements and processing overhead increase
Solution Approach 1:
The patent extracts only the specific FDB information containing unauthorized device MAC addresses from the network devices, storing and processing only this essential subset. This approach maintains sufficient information completeness for identification purposes while dramatically reducing memory capacity requirements and processing overhead compared to storing all FDB data.
Data Source
AI summary
The efficient identification of the connection location of an unauthorized device is enabled in a large-scale network. Upon receiving a notification of a physical address sent from an unauthorized device connected to a network, a first connection port corresponding to the physical address of the unauthorized device is acquired. From a first network device, a second connection port corresponding to a physical address of a network device connected to the first network device is acquired. First processing is executed to identify the network devices having the second connection port number that is the same as the first connection port number. Second processing is executed to acquire, from a second network device identified by the first processing, a third connection port corresponding to a physical address of network devices connected to the second network device. A connection location of the unauthorized device is identified by repeating the first and second processing.


