Network Device Identification via Weighted Inventory Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for identifying devices in computer networks, such as network scanning and passive analysis of network traffic, are inefficient and often disrupt operational processes or fail to accurately determine device attributes, particularly in cyber-physical systems with obsolete software and complex network architectures.

Innovation Solution

The use of inventory rules with weighting factor values to identify network devices by intercepting and analyzing data traffic, where each rule has conditions and priorities based on previously identified devices, allowing for efficient and accurate identification of device parameters like MAC addresses and software versions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network scanning is used to identify devices, then device identification capability is improved, but operational processes are disrupted

Engineering Contradiction:
Improvedevice identification capabilityVSAvoidoperational disruption
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

Instead of actively scanning the network to discover devices (traditional approach), the system inverts the approach by having devices self-announce their presence through inventory rules. The PLCs and other network devices automatically publish their inventory data to the network, allowing the gateway to passively collect this information without disrupting device operations.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces an intermediary mechanism (inventory rules with weighting factors) that mediates between device identification needs and operational continuity. The weighting factor system acts as a filter that prioritizes which device attributes to collect, reducing the burden on network devices while maintaining identification accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If passive analysis of network traffic is used, then operational disruptions are avoided, but device attribute determination accuracy is reduced

Engineering Contradiction:
Improveoperational disruptionVSAvoiddevice attribute determination accuracy
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The patent changes the parameters of passive analysis by introducing weighting factors that prioritize certain device attributes over others. Instead of attempting to extract all possible device information equally (which would be resource-intensive and less accurate), the system selectively focuses on high-priority attributes based on pre-defined weighting factors, improving both accuracy and efficiency.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system performs preliminary action by pre-defining inventory rules and weighting factors before network analysis begins. This allows the passive analysis to focus only on relevant device attributes that have been predetermined as important, rather than attempting to discover all possible attributes during the analysis phase.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive device inventory is created, then security assessment is improved, but time and resources required increase

Engineering Contradiction:
Improvesecurity assessmentVSAvoidinventory creation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by creating a prioritized inventory that focuses on the most critical device attributes for security assessment. Rather than exhaustively collecting every possible device parameter, the system uses weighting factors to identify and collect only the essential attributes needed for effective security evaluation, reducing time and resource requirements while maintaining security assessment quality.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11683336B2System and method for using weighting factor values of inventory rules to efficiently identify devices of a computer network
Publication Date: 2023.06.20 AO KASPERSKY LAB
  • US11683336B2 patent drawing
  • US11683336B2 patent drawing
  • US11683336B2 patent drawing

AI summary

A method for using inventory rules to identify devices of a computer network includes intercepting data traffic across one or more communication links of the computer network. The intercepted data traffic is analyzed to determine whether one or more of a plurality of inventory rules is satisfied by the intercepted data traffic. Each of the plurality of inventory rules comprises one or more conditions indicating the presence of a particular computer network device having a set of parameters. Each one of the plurality of inventory rules has a weighting factor value indicative of a priority of the application of a corresponding rule. The weighting factor value depends on previously identified devices. One or more devices of the computer network are identified using the weighting factor value of the one or more satisfied inventory rules.