Identifying devices on a remote network
Abstract
The device identification module identifies devices on a remote network, where the remote network can use network address translation technology. The device identification module can receive a list of devices on the remote network. The device classification module can be based at least in part on the device classification used for the remote network and one or more dynamic host configuration protocol (DHCP) information, the port sequence used in the network address translation on the remote network, and the real-time uniform resources executed on the remote network Locator (URL) checks to identify devices on the remote network.

Term
12.2 yearsto projected expiry
Projected expiry 30 November 2038, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
20 claims: 3 independent, 17 dependent
- 1一种用于标识设备的方法,所述方法包括: 通过连接到广域网的设备标识模块,接收网络设备列表,其中,所述网络设备列表包括 用于在远程专用地址空间上连接的一个或多个设备中的每个设备的条目; 通过所述设备标识模块,观察所述广域网中的至少一个网络分组,所述至少一个网络 分组源自在所述远程专用地址空间网络上连接的、并且在所述网络设备列表中具有条目的 所述一个或多个设备中的第一设备; 通过所述设备标识模块,至少部分基于由以下内容组成的组中的至少一项,标识对应 于所观察到的网络分组所源自的、所述远程专用地址空间网络上的所述第一设备的所述网 络设备列表上的条目: 用于所述远程专用地址空间网络的动态主机配置协议(DHCP)信息; 在所述远程专用地址空间网络上的网络地址转换(NAT)中使用的端口序列;以及 在所述远程专用地址空间网络上执行的实时统一资源定位符(URL)检查。
- 2根据权利要求1所述的方法,其中,所述用于所述远程专用地址空间网络的DHCP信息 包括一个或多个DHCP客户端标识符,并且其中,所述方法进一步包括: 通过所述远程专用地址空间网络上的第二设备,监视源自所述远程专用地址空间网络 的DHCP请求;以及 通过所述第二设备,将来自所述DHCP请求的一个或多个DHCP客户端标识符转发给所述 设备标识模块, 其中,所述标识对应于所观察到的网络分组所源自的、所述远程专用地址空间网络上 的所述第一设备的所述网络设备列表上的条目进一步至少部分地基于所述一个或多个 DHCP客户端标识符。
- 3根据权利要求1所述的方法,进一步包括: 聚类由所述远程专用地址空间网络上连接的所述一个或多个设备使用的端口序列, 其中,所述标识对应于所观察到的网络分组所源自的、所述远程专用地址空间网络上 的所述第一设备的所述网络设备列表上的条目进一步至少部分地基于聚类的端口序列。
- 4根据权利要求1所述的方法,进一步包括: 确定在所述远程专用地址空间网络上多个设备未被标识;以及 响应于确定多个未标识设备中的一个或多个未标识设备正在与域通信,向所述远程专 用地址空间网络上的第二设备发出请求,以发起在所述远程专用地址空间网络上的监听, 其中,所述标识对应于所观察到的网络分组所源自的、所述远程专用地址空间网络上 的所述第一设备的所述网络设备列表上的条目包括:从所述第二设备接收指示正在与所述 域通信的所述一个或多个未标识设备中的未标识设备的标识信息。
- 5根据权利要求1所述的方法,其中,所述远程专用地址空间网络上的路由器利用网络 地址转换。
- 6根据权利要求1所述的方法,其中,连接在所述远程专用地址空间网络上的所述一个 或多个设备包括至少一个物联网(IoT)设备。
- 7根据权利要求1所述的方法,其中,所述设备标识模块从连接在所述远程专用地址空 间网络上的网络监控器加密狗接收所述网络设备列表。
- 8根据权利要求1所述的方法,进一步包括:通过至少部分地连续地分析源自所述第一 标识设备的所述广域网中的网络分组,为对应于所述网络设备列表上所标识的条目的所述 远程专用地址空间网络上的所述第一设备提供一个或多个远程安全服务。
- 9一种系统,包括: 网络接口设备,被配置为将所述系统通信地连接到广域网; 至少一个处理器,通过总线连接到所述网络接口设备; 至少一个非暂时性计算机可读存储介质,通过总线连接到所述网络接口设备和所述至 少一个处理器,并存储一个或多个处理器可执行指令,所述处理器可执行指令包括以下指 令:当由所述至少一个处理器执行时提供设备标识模块,所述设备标识模块被配置为: 接收网络设备列表,其中,所述网络设备列表包括用于在远程专用地址空间上连接的 一个或多个设备中的每个设备的条目; 观察所述广域网中的至少一个网络分组,所述至少一个网络分组源自在所述远程专用 地址空间网络上连接的、并且在所述网络设备列表中具有条目的所述一个或多个设备中的 第一设备; 至少部分基于由以下内容组成的组中的至少一项,标识对应于所观察到的网络分组所 源自的、所述远程专用地址空间网络上的所述第一设备的所述网络设备列表上的条目: 用于所述远程专用地址空间网络的动态主机配置协议(DHCP)信息; 在所述远程专用地址空间网络上的网络地址转换(NAT)中使用的端口序列;以及 在所述远程专用地址空间网络上执行的实时统一资源定位符(URL)检查。
- 10根据权利要求9所述的系统,其中,所述用于所述远程专用地址空间网络的DHCP信 息包括一个或多个DHCP客户端标识符,并且其中,所述设备标识模块进一步被配置为: 从所述远程专用地址空间网络上的第二设备,从到所述设备标识模块的源自所述远程 专用地址空间网络的DHCP请求接收所述一个或多个DHCP客户端标识符;以及 进一步基于所述一个或多个DHCP客户端标识符,标识对应于所观察到的网络分组所源 自的、所述远程专用地址空间网络上的所述第一设备的所述网络设备列表上的条目。
- 11根据权利要求9所述的系统,其中,所述设备标识模块进一步被配置为: 聚类由所述远程专用地址空间网络上连接的所述一个或多个设备使用的端口序列;以 及 进一步基于聚类的端口序列,标识对应于所观察到的网络分组所源自的、所述远程专 用地址空间网络上的所述第一设备的所述网络设备列表上的条目。
- 12根据权利要求9所述的系统,其中,所述设备标识模块进一步被配置为: 确定在所述远程专用地址空间网络上多个设备未被标识;以及 响应于确定多个未标识设备中的一个或多个未标识设备正在与域通信,向所述远程专 用地址空间网络上的第二设备发出请求,以发起在所述远程专用地址空间网络上的监听, 其中,所述标识对应于所观察到的网络分组所源自的、所述远程专用地址空间网络上 的所述第一设备的所述网络设备列表上的条目包括:从所述第二设备接收指示正在与所述 域通信的所述一个或多个未标识设备中的未标识设备的标识信息。
- 13根据权利要求9所述的系统,其中,所述远程专用地址空间网络上的路由器利用网 络地址转换。
- 14根据权利要求9所述的系统,其中,连接在所述远程专用地址空间网络上的所述一 个或多个设备包括至少一个物联网(IoT)设备。
- 15根据权利要求9所述的系统,其中,所述设备标识模块被配置为从连接在所述远程 专用地址空间网络上的网络监控器加密狗接收所述网络设备列表。
- 16根据权利要求9所述的系统,所述处理器可执行指令包括以下指令,在由所述至少 一个处理器执行时提供平台,所述平台被配置为连续地分析所述广域网中源自所述第一标 识设备的网络分组,以为所述第一标识设备提供一个或多个远程安全服务。
- 17一种非暂时性计算机可读存储介质,包括一组可由计算机执行的指令,所述非暂时 性计算机可读存储介质包括: 通过连接到广域网的设备标识模块接收网络设备列表的指令,其中,所述网络设备列 表包括用于在远程专用地址空间上连接的一个或多个设备中的每个设备的条目; 通过所述设备标识模块,观察所述广域网中的至少一个网络分组的指令,所述至少一 个网络分组源自在所述远程专用地址空间网络上连接的、并且在所述网络设备列表中具有 条目的所述一个或多个设备中的第一设备; 通过所述设备标识模块,至少部分基于由以下内容组成的组中的至少一项,标识对应 于所观察到的网络分组所源自的、所述远程专用地址空间网络上的所述第一设备的所述网 络设备列表上的条目的指令: 用于所述远程专用地址空间网络的动态主机配置协议(DHCP)信息; 在所述远程专用地址空间网络上的网络地址转换(NAT)中使用的端口序列;以及 在所述远程专用地址空间网络上执行的实时统一资源定位符(URL)检查。
- 18根据权利要求17所述的非暂时性计算机可读存储介质,其中,用于所述远程专用地 址空间网络的DHCP信息包括一个或多个DHCP客户端标识符,并且进一步包括: 通过所述远程专用地址空间网络上的第二设备,监视源自所述远程专用地址空间网络 的DHCP请求的指令;以及 通过所述第二设备,将来自所述DHCP请求的一个或多个DHCP客户端标识符转发给所述 设备标识模块的指令, 其中,所述标识对应于所观察到的网络分组所源自的、所述远程专用地址空间网络上 的所述第一设备的所述网络设备列表上的条目进一步至少部分地基于所述一个或多个 DHCP客户端标识符。
- 19根据权利要求17所述的非暂时性计算机可读存储介质,进一步包括: 聚类由所述远程专用地址空间网络上连接的所述一个或多个设备使用的端口序列的 指令, 其中,所述标识对应于所观察到的网络分组所源自的、所述远程专用地址空间网络上 的所述第一设备的所述网络设备列表上的条目进一步至少部分地基于聚类的端口序列。
- 20根据权利要求17所述的非暂时性计算机可读存储介质,进一步包括: 确定在所述远程专用地址空间网络上多个设备未被标识的指令;以及 响应于确定多个未标识设备中的一个或多个未标识设备正在与域通信,向所述远程专 用地址空间网络上的第二设备发出请求,以发起在所述远程专用地址空间网络上的监听的 指令, 其中,所述标识对应于所观察到的网络分组所源自的、所述远程专用地址空间网络上 的所述第一设备的所述网络设备列表上的条目包括:从所述第二设备接收指示正在与所述 域通信的所述一个或多个未标识设备中的未标识设备的标识信息。
Independent claims20
81 paragraphs, as filed
Identify the technical field of the device on the remote network
[0001] The present disclosure generally relates to network systems, and more specifically relates to identifying network devices on remote networks that utilize a private address space such as a home network.
Background technique
[0002] "Internet of Things" (IoT) is a term used to describe a network that includes many different types of devices (traditional computers and devices that could not communicate on the network in the past). The "thing" in IoT can be any type of device that can collect data and communicate data via a network. Examples of such devices include smart home appliances, sensors, biochips, implantable medical devices, and vehicle-based devices. IoT devices can provide control and automation for devices in smart homes, smart grids, smart factories, smart cities, and smart transportation systems.
[0003] Providing security and/or control for IoT devices and other devices on remote networks can be difficult. One reason for the difficulty is that identifying devices can be challenging when monitoring business flows from outside the remote network (for example, through remote security, control, or network intelligence platforms).
Summary of the invention
[0004] The system and method implement (i) receive a list of network devices through a device identification module connected to a wide area network, wherein the list of network devices includes each of one or more devices connected to a remote dedicated address space. (Ii) Observe at least one network packet in the wide area network through the device identification module, the at least one network packet originating from the remote private address space network connected and in the The first device of the one or more devices having an entry in the network device list, and (iii) through the device identification module, based at least in part on at least one item in the group consisting of: Entry on the network device list of the first device on the remote private address space network from which the observed network packet originated: (a) Dynamic host configuration for the remote private address space network Protocol (DHCP) information, (b) the port sequence used in network address translation (NAT) on the remote private address space network, and (c) real-time uniform resource positioning performed on the remote private address space network Character (URL) check.
Description of the drawings
[0005] In order to better understand the subject of the present invention, you can refer to the accompanying drawings, in which:
[0006] FIG. 1 is a block diagram illustrating an example system for identifying devices on a remote network according to one embodiment of the present invention.
[0007] FIG. 2 is a flowchart showing the operation of a method for identifying a device on a remote network according to an embodiment of the present invention.
[0008] FIG. 3 is a block diagram of an example embodiment of a computer system on which an embodiment of the inventive subject matter may be executed.
Detailed ways
[0009] In the following detailed description of an exemplary embodiment of the present invention, reference is made to the accompanying drawings forming a part thereof, and in which
By way of illustration, specific example embodiments in which the present invention can be practiced are shown. These embodiments are described in sufficient detail to enable those skilled in the art to practice the subject of the present invention, and it should be understood that other embodiments can be utilized, and logical, mechanical, and electrical operations can be performed without departing from the scope of the subject of the present invention. And other changes.
[0010] Some parts of the following detailed description are presented based on algorithms and symbolic representations of operations on data bits in computer memory. These algorithm descriptions and representations are the most effective way for those skilled in the data processing field to convey the essence of their work to others in the field. The algorithm here is generally considered to be a self-consistent sequence of steps leading to the desired result. Steps are steps that require physical manipulation of physical quantities. Usually, though not required, these quantities take the form of electrical or magnetic signals that can be stored, transferred, combined, compared, and otherwise manipulated. Sometimes, mainly for general reasons, it has proven convenient to call these signals bits, values, elements, symbols, characters, items, numbers, etc. However, it should be remembered that all of these and similar terms should be associated with the appropriate physical quantities and are merely convenient labels applied to these quantities. Unless explicitly stated otherwise from the following discussion, terms such as "processing" or "calculation" or "operation" or "determination" or "display" refer to the actions and processes of a computer system or similar computing device, which will be expressed as Data of physical (eg, electronic) quantities in computer system registers and memories is manipulated and transformed into other data similarly expressed as physical quantities in computer system memories or registers or other such information storage, transmission, or display devices.
[0011] In the figures, the same reference numerals are used throughout to refer to the same components that appear in multiple figures. The same reference numerals or labels may be used to refer to signals and connections, and the actual meaning will be clear from its use in the context. Generally, for a given item or part of the invention, the first digit of the reference number should correspond to the number of the figure where the item or part was first found.
[0012] The description of the various embodiments is only to be interpreted as an example, and does not describe every possible example of the subject matter of the present invention. Many alternatives can be realized using a combination of current or future technologies, which still fall within the scope of the claims. Therefore, the following detailed description should not be considered as having a limiting meaning, and the scope of the subject matter of the present invention is limited only by the appended claims.
[0013] Embodiments of the present invention include a device identification module that can use network flow statistics and optionally network monitoring from a remote private address space (eg, "local") network such as a home network The data of the device dongle is used to classify the devices on the private address space network so that they can be identified as specific devices, such as specific household devices. The device identification module may be part of a system that provides remote security and/or control services for a private address space network. In order to provide such services in an effective manner, network flow statistics and classifications determined using flow statistics can be used to identify devices on a private address space network. After the device is identified, the service flow associated with the specific device can be analyzed. As used herein, identification can include mapping an unknown device to a specific single device in the network. Classification can include applying machine learning algorithms that allow unknown devices to be classified into a set of known device categories or device types.
[0014] One factor that makes this identification more difficult is the use of network address translation (NAT). The Internet Protocol address space is limited, so each private address space network (for example, in a home) usually uses a local address space, for example, 192.168.1.x and NAT. Routers or other devices acting as gateway routers use NAT to allow any device in the home to communicate with the wider Internet. NAT rewrites the Internet Protocol (IP) address of each local device in the IP header of the network packet sent from/to the local device with the IP address of the gateway device (such as a router, etc.), and uses the TCP port number This is achieved by demultiplexing the business when it returns. Table 1 below illustrates an example NAT table.
[0015] Table 1
[0016]
<td>equipment</td><td>Private address space C local") IP address</td><td>Local port</td><td></td><td>Destination address</td><td>NAT IP address</td><td>NAT port</td>
<td>Jon's IPad</td><td>192.168.1.21</td><td>750</td><td></td><td>fhcebook.com</td><td>35.42.105.19</td><td>21750</td>
<td>Jon's iPad</td><td>192.168.1.21</td><td>751</td><td></td><td>cnn.com</td><td>35.42.105.19</td><td>21751</td>
<td>Bill's iPad</td><td>192.168.1.27</td><td>1546</td><td></td><td>cnni com</td><td>35.42.105.19</td><td>1546</td>
<td>TV</td><td>192.168.1.40</td><td>550</td><td></td><td>samsung.com</td><td>35.42.105.19</td><td>550</td>
<td>PC</td><td>192.168.1.5</td><td>660</td><td></td><td>cnn.com</td><td>35.42.105.19</td><td>660</td>
[0017] When a network packet is to be relayed from a private address space network to a remote network, the gateway device uses NAT to convert the private address space IP address to the gateway device IP address (for example, 35.42.105.19), and maps the port of the packet to NAT port. For example, suppose Jon's iPad is communicating with cnn.com via local port 751. The source IP address of the outgoing packet has been mapped to the gateway IP address (NAT IP address in Table 1). The port of the outgoing packet is mapped to a unique port number, which can be associated with Jon's iPad via the NAT table. When the business returns (for example, from cnn.com), the router will check the port number (for example, 21751) to route it to Jon's iPad on port 751.
[0018] As can be seen from the above, it may be difficult to use specific devices on the private address space network to remotely (for example, from outside the private address space network, such as through the Internet) identify network devices on the private address space network and associate network services ( Observed on a wider network with a public address space (such as the Internet), because all network devices on a private address space network seem to have the same IP address as the gateway device on the private address space network.
[0019] A remote system can use the systems and methods of the embodiments described herein to identify devices on a private address space network.
[0020] FIG. 1 is a block diagram illustrating an example system 100 for identifying devices on a remote network according to an embodiment. In some embodiments, system 100 may include a dedicated address space (eg, "local") network 102 configured to communicatively connect router 104, JOT device 110T12, smartphones 108 and 116, computer 118, and network monitor dongle 120. The network monitor dongle 120 may include a network service monitor 132 and a network device list 134. The system 100 may further include a public address space (eg, "broad") network 122, a device identification module 124, and a classification database 126. The public address space network 122 may include a flow statistics information collector 114, and may be communicatively connected to a router 104, and the router 104 may interface with the private address space network 102 and the public address space network 122. The public address space network 122 can also be communicatively connected to the device identification module 124 and the classification database 126. The classification database 126 can store the network flow statistics 106 and the classified device list 128. In some embodiments, the device identification module 124 and the classification database 126 may include a platform 136.
[0021] The dedicated address space network 102 can facilitate the exchange of data (for example, network packets, etc.) between the router 104, the smart phones 108 and 116, the IOT devices 110-112, the computer 118, and the network monitor dongle 120. The dedicated address space network 102 may be a wired network, a wireless network, or a combination of both. In some embodiments, the private address space network 102 may be a home network. In an alternative embodiment, the network 102 may be a network in a small business or a corporate network. Private address is empty
The inter-network 102 includes a network that utilizes a dedicated IP address space. Although the geographic scale/spatial scope of the private address space network 102 is not limited, examples of networks that may include the private address space network 102 include, but are not limited to, nanoscale networks, near-field networks, body area netwok (BAN), personal Local area network (PAN), short-range local area network (NAN), local area network (LAN), wireless local area network (WLAN), home area network (HAN), storage area network (SAN) and campus area network (CAN). In another embodiment, the dedicated address space network 102 is any medium that allows data to be physically transmitted through serial or parallel communication channels (eg, copper wires, optical fibers, computer buses, wireless communication channels, etc.).
[0022] The public address space network 122 can facilitate the exchange of data (eg, network packets, etc.) between the router 104, the device identification module 124, and the classification database 126. The public address space network 122 may be any collection of one or more wired networks, wireless networks, or a combination of the two, and they cover a larger range than the private address space network 102. In some aspects, the public address space network 122 may be one or more networks that make up the Internet. The public address space network 122 includes a network that utilizes a public IP address space. Although the geographic scale/spatial scope of the public address space network 122 is not limited, examples of networks that can include the public address space network 122 include, but are not limited to, backbone networks, metropolitan area networks (MAN), wide area networks (WAN), and global area networks. (GAN), Public Switched Cellular Network (PSTN) and Internet Area Network (IAN). In another embodiment, the public address space network 122 is any medium that allows data to be physically transmitted through serial or parallel communication channels (eg, copper wires, optical fibers, computer buses, wireless communication channels, etc.).
[0023] An IoT device (eg, IoT devices 110, 112) may be any type of device that includes a processor and a network interface to transmit data via the private address space network 102 and/or the public address space network 122. Examples of such devices include, but are not limited to, smart TVs, smart home appliances, sensors, biochips, office equipment, implantable medical devices, and vehicle-based devices.
[0024] The computer 118 may be a server computer, a laptop computer, a tablet computer, a set-top box, a video game console, or any other device with a processor and memory that enables the device to execute programs.
[0025] The smart phones 108 and 116 may be any type of smart phones. Examples of smart phones include Android-based smart phones, iPhones, and Windows phones. The embodiments are not limited to any particular type of smartphone. The smart phone 108 may be the same type of mobile phone as the smart phone 116, or may be a different type of mobile phone.
[0026] The router 104 can forward network data (eg, packets) between the private address space network 102 and the public address space network 122. The router 104 may be a standalone router, a wireless router or access point, a modem/router, or any other device that forwards data between two networks. In some embodiments, the router 104 can use a first addressing scheme (such as a private IP address space) in a first network (e.g., private address space network 102) or a second addressing scheme (such as a public address space). ) To forward packets between the second network (for example, the public address space network 122) or sub-networks. For example, as described further herein, the router 104 can remap one IP address space to another IP address space to perform NAT by modifying the network address information in the IP header of the packet when the packet is transmitted through the router 104. .
[0027] The network monitor dongle 120 may be a computing device 112 similar to the IoT device 110. The network monitor dongle 120 includes one or more processors, one or more storage devices, and a network interface device. The network monitor dongle 120 may be coupled to the network 102 via a network interface device and a communication connection (wireless, wired, or a combination of wired and wireless). The processor of the network monitor dongle 120 can execute the network service monitor 132, which can monitor (also known as snooping or sniffing) packets on the network 102 and use the data obtained from the monitoring The data is used to construct the network device list 134 and store the network device list 134 on the storage device of the network monitor dongle 120. The network service monitor 132 can also scan the IP address range of the private address space network 102 and detect packets (also known as "ping").
(Pinging)" or "port scanning") is sent to each device IP address on the private address space network 102 to construct a network device list. In some embodiments, the network service monitor 132 is provided as a storage device The processor executable instructions include the functions, routines, methods and/or subprograms of the network monitor dongle 120. The network device list 134 may be a list of device names of the devices discovered by the network monitor dongle 120 on the network 102 And their associated media access control (MAC) addresses. In some embodiments, the network monitor dongle 120 can respond to commands received from a remote source such as the device identification module 124, which will be described further below. The network device list 134 will generally include the IP and MAC addresses of devices identified or discovered on the private address space network 102, as well as any open ports, and may also include other identification information observed on the private address space network 102 (such as browsing Server proxy string, dynamic host configuration protocol (DHCP) request, etc.). These can be used to identify devices in the private address space network 102.
[0028] The device identification module 124 observes the network flow statistics 106 based on the network traffic received from the private address space network 102, as seen in the wider public address space network 122. Even when the actual network address of the device is hidden due to the use of NAT, network flow statistics can be used with other techniques described below to identify devices in a remote network (for example, private address space network 102). For example, the device identification module 124 can use the network flow statistics 106 together with other data (such as the network device list 134 of the private address space network 102) to identify and classify devices on the private address space network 102 without needing to know The actual IP address or MAC address of the device in the private address space network 102. For example, a machine learning algorithm can be applied to the network flow statistics 106 to classify unknown devices in a set of known device categories or device types. The classification equipment may be maintained in the classified equipment list 128 stored in the classification database 126. The device identification module 124 may be an independent module or a component of another system or platform 136. For example, the device identification module 124 may be a component of a network security system, a network control system, a network intelligence platform, and the like. The platform 136 can provide additional services, such as malware detection, denial of service attack detection, Corpse network membership testing, etc. Such services may use the device identification provided by the device identification module 124 in order to provide such additional services. In some embodiments, the device identification module 124 is provided as processor-executable instructions stored on a storage device, which include functions, routines, methods, and/or subroutines of the computing device and/or platform 136.
[0029] In some embodiments, the network flow statistics 106 may be collected by the flow statistics collector 114. For example, an Internet Service Provider (ISP) that provides a connection to the wider public address space network 122 may include a flow statistics collector 114 as part of the ISP router for transferring packets received via the router 104 from the private The address space network 102 is routed to the broader public address space network 122 managed by the ISP. For example, a router located at the edge of an ISP network may include a flow statistics collector 114. Alternatively, the flow statistics collector 114 may be separate from the ISP router.
[0030] In an alternative embodiment, the functions described as provided by the network monitor dongle 120 may be distributed to the other components shown in FIG. 1. For example, the computer 118 or the router 104 may perform some or all of the functions of the network monitor dongle 120.
[0031] It should be noted that although only one private address space network 102 is shown in FIG. 1, the device identification module
124 can receive data from many different private address space networks 102.
[0032] Take the number and types of devices shown in FIG. 1 as an example. Those skilled in the art with the benefit of the present disclosure will understand that the network 102 may include more or fewer devices and device types than those shown in FIG. 1.
[0033] FIG. 2 is a flowchart 200 showing the operation of a method for identifying a device on a remote network according to an embodiment.
[0034] At block 202, the device identification module 124 may receive a network device list 134 for the private address space network 102. As described above, the network device list 134 may include a list of devices on the private address space network 102 and device information.
MAC address. In some embodiments, block 202 may be referred to as receiving the network device list 134 from a remote network because the private address space network 102 is remote from the device identification module 124.
[0035] In block 204, the device identification module 124 may optionally determine the network flow statistics of the private address space network 102. For example, the flow statistics can be collected from a gateway device such as the router 104 or the router of an ISP that provides network services to the private address space network 102. For example, the ISP may include the flow statistics collector 114 in the router or as a separate device. Flow statistics can be used to classify and/or identify devices, as described herein.
[0036] At block 206, a check may be made to determine whether there are any unidentified devices on the private address space network 102. For example, the device identification module 124 may check to determine whether any devices in the network device list 134 are still unidentified after performing the operations of blocks 202-204.
[0037] When the check at block 206 determines that no device is unidentified (ie, all devices in the network device list 134 are identified), then the method ends. When the check at block 206 determines that there are one or more unidentified devices on the private address space network 102 (ie, at least one device in the network device list 134 is not identified), then the method proceeds to block 208 .
[0038] At block 208, the device identification module 124 attempts to use DHCP data to identify the device. In some embodiments, software on a computer on the private address space network 102 or on the network monitor dongle 120 (eg, the network traffic monitor 132) can listen for DHCP requests. Because the DHCP request is a broadcast packet, all workstations on the network can see the DHCP request. The DHCP request may contain optional parameters called DHCP client identifiers. The DHCP client identifier is usually set in a systematic manner by different types of equipment. For example, the DHCP client identifier ANDROID-XXXXYYYY" can indicate the Android device "Jon's iPhone" can indicate the iPhone, etc. Therefore, the DHCP client identifier can include information that can be used, as well as usage network flow statistics and Device fingerprint data determined by the network device list to remotely identify and/or classify network devices on the private address space network. DHCP data can be forwarded from the computer 118 on the private address space network 102 or the network monitor dongle 120 to the device identification The module 124 is used to identify devices on the private address space network 102.
[0039] At block 210, a check may be made to determine whether there are any unidentified devices on the private address space network 102. For example, the device identification module 124 may check to determine whether any devices in the network device list 134 are still unidentified after performing the operations of blocks 202-208.
[0040] When the check at block 210 determines that no device is still unidentified (ie, all devices in the network device list 134 are identified), then the method ends. When the check at block 210 determines that there are one or more unidentified devices on the private address space network 102 (ie, at least one device in the network device list 134 is not identified), then the method proceeds to block 212 .
[0041] At block 212, the device identification module 124 may use the port number sequence in the network service to try to identify the device. This technique is based on the fact that devices usually use sequential port numbers as their source ports, and routers (for example, router 104) usually try to assign the same source port during NAT. Therefore, in the example described in Table 1, Jon's iPad can be located on ports 750, 751, 752, etc., and Bill's iPad can be located on ports 1546, 1547, 1548, etc. The cluster of port numbers can be used to identify a specific device on the private address space network 102 and the network service associated with the device.
[0042] At block 214, a check may be made to determine whether there are any unidentified devices on the private address space network. For example, the device identification module 124 may check to see whether any devices in the network device list 134 are still unidentified after performing the operations of blocks 202-212.
[0043] When the check at block 214 determines that no device is still unidentified (ie, all devices in the network device list 134 are identified), then the method ends. When the check at block 214 determines that there are one or more unidentified devices on the private address space network 102 (ie, at least one device in the network device list 134 is not identified), then the method proceeds to block 216 .
[0044] At block 216, the device identification module 124 may use a real-time URL (Uniform Resource Locator) check to identify the device. As an example, after block 212, when the device identification module 124 attempts to classify a network flow and/or identify a device based on the network flow, two or three device choices may be left. As an example, the device identification module 124 may determine that there is a network flow from one of the three devices (referred to as these P, Q, and R) on the private address space network 102 to the domain "samsung.com". Then, the device identification module 124 may send a request to the network monitor dongle 120 to temporarily monitor the packets on the private address space network 102 belonging to the three devices P, Q, and R. Alternatively, the device identification module 124 may send a request to the network monitor dongle 120 to briefly monitor all packets on the private address space network 102. In response to this request, the network monitor dongle 120 can check which of the three devices P, Q, R is currently connected to the domain "samsung.com, and report the identification details associated with the device to the device identification module 124. In After the operation is completed in block 216, the method ends. In an embodiment, any unidentified device is classified as "unknown".
[0045] In some embodiments, after the method described herein ends, the analysis of the traffic flow associated with the specific device identified by the method can continue. For example, the platform 136 may utilize the identified devices on the network device list 134 to provide services, such as malware detection, denial of service attack detection, botnet membership detection, and the like.
[0046] Those skilled in the art with the benefit of the present disclosure will understand that the sequence of operations shown in FIG. 2 may be different from the sequence shown. For example, based on difficulty, resource cost, and benefits associated with the sequence, various embodiments may use a different sequence than that shown in FIG. 2.
[0047] The above operations can be used in combination with other device classification and/or identification methods. For example, device fingerprinting or packet inspection can be used to classify and/or identify devices on the private address space network 102. The above operations can be used instead of or in addition to this device fingerprint or packet inspection. For example, the device identification module 124 may use network flow statistics to determine the device fingerprint of each device on the private address space network 102. The device fingerprint and the network device list 134 can be used to identify specific devices. In addition, the device identification module 124 may perform packet inspection to try to identify the device. For example, if the grouping includes a browser string identifying the browser used on the device, the browser string can be used to classify the device into a certain type. However, there may be more than one device of the same type on the network, so as mentioned above, other methods can be used to distinguish two devices of the same type.
[0048] FIG. 3 is a block diagram of an example embodiment of a computer system 300 on which embodiments of the subject of the present invention may run. The description of FIG. 3 is intended to provide a brief general description of suitable computer hardware and a suitable computing environment that can be combined to implement the present invention. In some embodiments, the subject matter of the invention is described in the general context of computer-executable instructions, such as program modules, executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types.
[0049] As described above, the system as disclosed herein can be distributed on many physical hosts. Therefore, many of the systems and subsystems of FIG. 3 may be involved in implementing the inventive subject matter disclosed herein.
[0050] In addition, those skilled in the art will understand that the present invention can be practiced with other computer system configurations, including handheld devices, multi-processor systems, microprocessor-based or programmable consumer electronics, smart phones, and network PCs. , Minicomputers, mainframe computers, etc. The embodiments of the present invention can also be practiced in a distributed computer environment, where tasks are performed by I/O remote processing devices linked through a communication network. In a distributed computing environment, program modules can be located locally and
Remote memory storage device.
[0051] With reference to FIG. 3, the example embodiment is extended to a machine in the example form of a computer system 300 within which instructions for causing the machine to perform any one or more of the methods discussed herein can be executed. In alternative example embodiments, the machine operates as a standalone device or can be connected (eg, networked) to other machines. In a networked deployment, a machine can operate in the capacity of a server or a client machine in a server-client network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. Further, although only a single machine is shown, the term "machine" should also be considered to include any machine that operates one or more sets of instructions individually or in combination to perform any one or more of the methods discussed herein set.
[0052] The example computer system 300 may include a processor 302 (eg, a central processing unit (CPU), a graphics processing unit (GPU), or both), a main memory 304 and a static memory 306, which communicate with each other via a bus 308. The computer system 300 may also include a video display unit 310 (for example, a liquid crystal display (LCD) or a cathode ray tube (CRT)). In an exemplary embodiment, the computer system 300 further includes an alpha-numeric input device 312 (for example, a keyboard), a user interface (UI) navigation device or a cursor control device 314 (for example, a mouse), a disk drive unit 316, and a signal generating device 318 (For example, a speaker) and one or more of the network interface device 320.
[0053] The disk drive unit 316 includes a machine-readable medium 322 on which one or more sets of instructions 324 and data structures (for example, software instructions) implemented or used by any one or more of the methods or functions described herein are stored. ). The instructions 324 may also completely or at least partially reside in the main memory 304 or the processor 302 during execution by the computer system 300, and the main memory 304 and the processor 302 also constitute machine-readable media.
[0054] Although the machine-readable medium 322 is shown as a single medium in the example embodiment, the term "machine-readable medium" may include a single medium or multiple media (eg, centralized or distributed Database, or associated cache and server). The term "machine-readable medium" shall also be regarded as including instructions capable of storing, encoding, or carrying instructions for being executed by a machine and causing the machine to perform any one or more of the methods of the embodiments of the present invention, or capable of storing, encoding Or any tangible medium that carries data structures used by or associated with these instructions. Therefore, the term "machine-readable storage medium" should be regarded as including, but not limited to, solid-state memory and optical and magnetic media that can store information in a non-transitory manner, that is, media that can store information. Specific examples of machine-readable media include non-volatile memory, including, for example, semiconductor memory devices (eg, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), and flash memory devices) ; Magnetic disks, such as internal hard disks and removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks.
[0055] Using a signal transmission medium via the network interface device 320, and using any of many well-known transmission protocols (for example, FTP, HTTP), it is also possible to send or receive instructions 324 through the communication network 326. Examples of communication networks include local area networks (LAN), wide area networks (WAN), the Internet, mobile phone networks, plain old cell phone (POTS) networks, and wireless data networks (for example, WiFi and WiMax networks). The term "machine-readable signal medium" shall be regarded as including any temporary intangible medium capable of storing, encoding or carrying instructions for execution by a machine, and including digital or analog communication signals or other intangible media to facilitate the execution of such software Communication.
[0056] In an embodiment, the method for identifying devices (eg, IoT devices 110-112, smartphones 108 and 116, computer 118, etc.) includes connecting to a wide area network that receives a list of network devices (eg, network device list 134) (For example, the public address space network 122) device identification module (for example, the device identification module 124). The list of network devices may include one or more devices (for example, IoT devices 110-112, smartphones 108 and 116, computers 118, etc.) connected to a remote private address space network (for example, private address space network 102) Entries for each device. The method includes
A device identification module that observes network services (for example, at least one network packet) on the wide area network, the network services originating from the first device of one or more devices connected to the remote private address space network, and There is an entry on the network device list. The device identification module identifies in the network device list an entry corresponding to the first device (ie, the identified device) on the remote private address space network from which the observed network packet originated. The device identification module performs identification based at least in part on at least one of the following groups: DHCP information of the remote private address space network, the port sequence used in NAT on the remote private address space network, and the remote private address space network Real-time URL checks performed and their combinations.
[0057] The DHCP information for the remote private address space network may include one or more DHCP client identifiers, and the method may further include a second device (for example, a network monitor dongle on the remote private address space network) 120 etc.), the second device monitors the request originating from the remote dedicated address space network, and forwards one or more DHCP client identifiers from the DHCP request to the device identification module. In addition, the identification of the entry on the network device list corresponding to the first device on the remote private address space network from which the observed packet originated may also be based at least in part on one or more DHCP client identifiers. The method may further include: clustering the port sequence used by one or more devices connected to the remote private address space network, and clustering the remote private address space network on the network device from which the observed packet originated The identification of the entry corresponding to the first device on the above may be further based at least in part on the clustered port sequence. In addition, the method may include: determining that a plurality of devices are not identified on the remote dedicated address space network, and in response to determining that one or more of the plurality of unidentified devices are communicating with the domain, sending a remote dedicated address The second device on the address space network issues a request to initiate monitoring on the remote dedicated address space network. In addition, the remote private address space network from which the observed packet originated on the network device list The identification of the entry corresponding to the first device on the network includes: receiving from the second device identification information indicating an unidentified device among the one or more unidentified devices communicating with the domain. In some embodiments, the method further includes providing for the first device on the remote private address space network by continuously analyzing network packets in the wide area network originating from the first identification device at least in part One or more remote security services corresponding to the entries identified on the network device list.
[0058] In another embodiment, the system includes a network interface device (eg, network interface device 320), at least one processor (eg, processor 302), and at least one non-transitory computer-readable storage medium (eg, main Memory 304, Wait). The network interface device is configured to communicatively connect the system to a wide area network (eg, public address space network 122). At least one processor and at least one memory are connected to each other through a bus (for example, the bus 308) and to a network interface device. At least one non-transitory computer-readable storage medium stores one or more processor-executable instructions (for example, instruction 324), and the processor-executable instructions, when executed by at least one processor, provide a device identification module (for example, a device identification module). 124). The identification module is configured to receive a list of network devices (for example, network device list 134), which includes one or more devices (for example, IoT) for connecting on a remote private address space network (for example, private address space network 102). An entry for each of the devices 110-112, smart phones 108 and 116, computer 118, etc.). The device identification module is further configured to observe network services (for example, at least one network packet) on the wide area network, the network services originating from the first device of one or more devices connected on the remote private address space network, and There are entries in the list of network devices. The device identification module is configured to identify the first device (ie, the identified device) corresponding to the first device (ie, the identified device) on the remote private address space network from which the observed network packet originated on the network device list Article Item. The device identification module is configured to perform identification based at least in part on at least one item in the group consisting of: DHCP information for the remote private address space network, use in NAT on the remote private address space network
The port sequence of, real-time URL checking performed on the remote dedicated address space network, and combinations thereof.
[0059] In yet another embodiment, a non-transitory computer-readable storage medium (eg, machine-readable medium 322, etc.) includes a set of instructions that can be executed by a computer (eg, instructions 324, etc.). The non-transitory computer-readable storage medium includes an instruction to receive a network device list (eg, network device list 134) through a device identification module (eg, device identification module 124) connected to a wide area network (eg, public address space network 122). The list of network devices includes each of one or more devices (for example, IoT devices 110112, smartphones 108 and 116, computers 118, etc.) used to connect on a remote private address space network (for example, private address space network 102) The entry of the device. The non-volatile computer-readable storage medium also includes instructions for observing at least one network service in the wide area network through the device identification module and having an entry in the network device list, the network service originating from the remote The first device among the one or more devices connected on the private address space network. In addition, the non-transitory computer-readable storage medium includes identifying the first device on the remote private address space network from which the observed network packet originated on the network device list through the device identification module (Ie, the identified device) the instruction of the corresponding entry. Device identification module at least The identification is performed based in part on at least one item in the group consisting of: the DHCP information for the remote private address space network, the port sequence used in the NAT on the remote private address space network, the Real-time URL checking and its combination performed on the remote private address space network.
[0060] Although an overview of the subject matter of the present invention has been described with reference to specific example embodiments, various modifications and changes can be made to these embodiments without departing from the broader spirit and scope of the embodiments of the present invention. If in fact more than one invention or inventive concept is disclosed, it is only for convenience without the intention to voluntarily limit the scope of the application to any single invention or inventive concept. These embodiments of the subject matter of the invention may be used herein. Individually or collectively referred to as "invention".
[0061] It is apparent from the foregoing description that certain aspects of the subject matter of the present invention are not limited by the specific details of the examples shown herein, and therefore it is expected that other modifications and applications or equivalents thereof will occur for those skilled in the art. Therefore, the claims should be intended to cover all such modifications and applications without departing from the spirit and scope of the subject matter of the present invention. Therefore, it is obvious that the subject matter of the present invention is limited only by the appended claims and their equivalents.
[0062] An abstract is provided to comply with 37 C.FR §1.72(b) to allow readers to quickly determine the nature and main points of the technical disclosure. The abstract is submitted with the understanding that it will not be used to limit the scope of the claims.
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| CN115277434A | Cited by | China | – | Search report | – |
| CN115883509A | Cited by | China | – | Search report | – |
| US12170645B2 | Cited by | United States of America | – | Applicant | – |
| CN101127631A | Cites | China | A | Search report | 1-20 |
| CN101243647A | Cites | China | A | Search report | 1-20 |
| CN1582560A | Cites | China | A | Search report | 1-20 |
| US2007055753A1 | Cites | United States of America | A | Search report | 1-20 |
| US2010169446A1 | Cites | United States of America | A | Search report | 1-20 |
| US2017054594A1 | Cites | United States of America | A | Search report | 1-20 |
6 members in 3 offices
Priority claims14
| Document | Office | Kind | Date |
|---|---|---|---|
| 201762592980 | United States of America | P | |
| 201762592980 | United States of America | P | |
| 62592980 | United States of America | – | |
| 16205074 | United States of America | – | |
| 201816205074 | United States of America | A | |
| 201816205074 | United States of America | A | |
| 2018063243 | United States of America | W | |
| 2018063243 | United States of America | W | |
| 16205074 | – | – | – |
| 62592980 | – | – | – |
| PCTUS2018063243 | – | – | – |
| US201762592980P | – | – | – |
| US201816205074 | – | – | – |
| WO2018US63243 | – | – | – |
Members6
| Document | Office | Kind | |
|---|---|---|---|
| US2019166091A1 | United States of America | A1 | |
| WO2019108892A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN112020862AThis record | China | A | |
| US10862862B2 | United States of America | B2 | |
| CN112020862B | China | B | |
| CN112020862B | China | B |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Patent grantGrantedGR01 | GR01 | |
| Entry into force of request for substantive examinationSE01 | SE01 | |
| PublicationPB01 | PB01 |
Numbers
- Publication
- 112020862
- Publication, DOCDB
- 112020862
- Publication, EPODOC
- CN112020862
- Application
- 800773699
- Application, DOCDB
- 201880077369
- Application, EPODOC
- CN201880077369
Titles2
- Chinese
- 在远程网络上标识设备
- English
- Identify the device on the remote network
Classification
- CPC, 5
- H04L61/2591
- H04L61/2514
- H04L67/12
- Y04S40/18
- H04L61/5014
- IPC, 2
- H04N21 41
- H04L12 28