×

Systems and methods for fingerprinting physical devices and device types based on network traffic

  • US 9,225,732 B2
  • Filed: 11/29/2012
  • Issued: 12/29/2015
  • Est. Priority Date: 11/29/2011
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • capturing, at a listening node in communication with a network, network traffic originating from a first device in communication with the network and routed to a destination node in communication with the network;

    measuring, independent of network traffic type, protocol or packet payload, one or more traffic properties of the captured network traffic;

    generating a feature vector based on at least a portion of the one or more measured traffic properties;

    analyzing one or more statistical properties of the feature vector; and

    generating a first device signature based on the analyzed one or more statistical properties, wherein the first device signature comprises encoded information about a hardware and software architecture of the first device;

    comparing the first device signature with one or more known signatures; and

    determining, based on the comparing, and without prior knowledge of the network traffic type, protocol or packet payload, a type of the first device and an identity of the first device.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×