Method and system for tracing missing network devices using hardware fingerprints
First Claim
1. A method for determining a position of an electronic device within a wide area network including the electronic device and additionally including first and second network elements, said method comprising:
- distributing a tracing tool to the first network element within said wide area network;
detecting a physical separation of said electronic device and an associated user;
determining identifying indicia of said electronic device, wherein said identifying indicia are automatically transmifted by said electronic device during communication on the wide area network between said electronic device and the second network element;
the first network element monitoring traffic on said wide area network utilizing said tracing tool, wherein said monitoring includes;
in response to detecting said physical separation, the first network element intercepting data of said communication on the wide area network between said electronic device and said second network element, said data including said identifying indicia; and
determining a physical position of said electronic device within said wide area network in response to an interception of said identifying indicia.
3 Assignments
0 Petitions
Accused Products
Abstract
When a piece of network equipment is determined to be stolen or missing, a hardware tracing tool mounted within the network detects the distinctive hardware fingerprints of the missing hardware within Internet traffic and extracts the device'"'"'s IP address to trace the location of the missing equipment. As Internet messages or data packets cross through servers containing the tracing tool, the data packets are decompiled to retrieve unique identifier indicia (hardware fingerprints), such as a computer'"'"'s MAC address, for example. The extracted fingerprints are then compared with fingerprints stored in a database of missing hardware using a hashing or mapping function, and the server system is alerted to a match. The IP address of the device transmitting the matching indicia is then extracted to determine the location of the missing or stolen network hardware. In this way, a method of tracing missing network hardware is provided that does not increase the cost of network equipment or unnecessarily effect network bandwidth.
70 Citations
18 Claims
-
1. A method for determining a position of an electronic device within a wide area network including the electronic device and additionally including first and second network elements, said method comprising:
-
distributing a tracing tool to the first network element within said wide area network; detecting a physical separation of said electronic device and an associated user; determining identifying indicia of said electronic device, wherein said identifying indicia are automatically transmifted by said electronic device during communication on the wide area network between said electronic device and the second network element; the first network element monitoring traffic on said wide area network utilizing said tracing tool, wherein said monitoring includes; in response to detecting said physical separation, the first network element intercepting data of said communication on the wide area network between said electronic device and said second network element, said data including said identifying indicia; and determining a physical position of said electronic device within said wide area network in response to an interception of said identifying indicia. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
-
10. A system for determining a position of an electronic device within a wide area network including the electronic device and at least an additional second network element, said system comprising:
-
a hardware fingerprint server to determine identifying indicia of said electronic device, wherein said identifying indicia are automatically transmitted by said electronic device during communication on the wide area network between said electronic device and the second network element; a monitoring server to detect a physical separation of said electronic device and an associated user and further to monitor traffic on said wide area network, wherein said monitoring server includes; an intercept module, responsive to a detection of said physical separation, to intercept data of said communication on said wide area network between said electronic device and said second network element, said data including said identifying indicia; and a tracing server to determine a physical position of said electronic device within said wide area network in response to an interception of said identifying indicia at said intercept module. - View Dependent Claims (11, 12, 13)
-
-
14. A machine-readable medium having embodied therein program code executable by a machine, wherein said program code causes said machine to perform a method for determining a position of an electronic device within a wide area network including the electronic device and additionally including first and second network elements, said method comprising:
-
detecting a physical separation of said electronic device and an associated user; determining identifying indicia of said electronic device, wherein said identifying indicia are automatically transmitted by said electronic device during communication on the wide area network between said electronic device and the second network element; the first network element monitoring traffic on said wide area network at said first network element utilizing a tracing tool, wherein said monitoring comprises; in response to detecting said physical separation, the first network element intercepting data of said communication on the wide area network between said electronic device and said second network element, said data including said identifying indicia; and determining a physical position of said electronic device within said wide area network in response to an interception of said identifying indicia. - View Dependent Claims (15, 16, 17, 18)
-
Specification