IP Library Granted Patent US 11,526,392
Granted Patent B2
US 11,526,392 · App. 16/868,914 · Granted Dec 13, 2022

System and method for inferring device model based on media access control address

Inventors: Ron Shoham (Tel Aviv, IL); Tom Hanetz (Tel Aviv, IL); Yuval Friedlander (Petah-Tiqwa, IL); Gil Ben Zvi (Hod Hasharon, IL)
Assignee: Armis Security Ltd.
G06F11/079G06F11/0709G06F11/0751G06N7/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,526,392
App. No.
16/868,914
Granted
Dec 13, 2022
Kind
B2
Abstract

A system and method for inferring device models. The method includes determining block statistics for each block of a plurality of blocks of a plurality of media access control (MAC) addresses, the plurality of blocks having a plurality of respective prefixes, wherein the plurality of blocks are grouped based on commonalities among the plurality of respective prefixes; generating an aggregated statistical model for the plurality of blocks based on the plurality of MAC addresses and the block statistics, wherein each block is a string of digits included in one of the plurality of MAC addresses; and applying the aggregated statistical model to the block statistics of at least one block of the plurality of blocks in order to determine at least one inferred device model, wherein each of the at least one block is grouped into the same group.

Claims (43)

1. A method for inferring device models, comprising:

determining block statistics for each block of a plurality of blocks of a plurality of media access control (MAC) addresses, the plurality of blocks having a plurality of respective prefixes, wherein the plurality of blocks is grouped based on commonalities among the plurality of respective prefixes, wherein the block statistics include a ratio of a number of occurrences of each block to the total number of occurrences of the plurality of blocks;

generating an aggregated statistical model for the plurality of blocks based on the plurality of MAC addresses and the block statistics, wherein each block is a prefix included in one of the plurality of MAC addresses; and

applying the aggregated statistical model to the block statistics of at least one block of the plurality of blocks in order to determine at least one inferred device model, wherein each of the at least one block is grouped into the same group.

2. The method of claim 1 , wherein applying the aggregated statistical model to the block statistics further comprises:

determining a potential device model and a corresponding confidence level for each block, wherein each inferred device model is a potential device model having a corresponding confidence level above a threshold.

3. The method of claim 1 , further comprising:

adding a first inferred device model of the at least one inferred device model to a device profile.

4. The method of claim 3 , further comprising:

monitoring behavior of a networking device based on the device profile to detect abnormal behavior of the first networking device, wherein the abnormal behavior is a deviation from a predetermined normal behavior associated with the first inferred device model device model.

5. The method of claim 1 , wherein the plurality of MAC addresses is included in networking model device data, further comprising:

preprocessing the networking device model data, wherein preprocessing the networking device model data further comprises unifying a plurality of device model names among the networking device model data based on an ontology, wherein the ontology defines synonymous device model names.

6. The method of claim 1 , wherein the plurality of MAC addresses is included in networking model device data, further comprising:

preprocessing the networking device model data, wherein preprocessing the networking device model data further comprises normalizing a plurality of device model names among the networking device model data such that like device model names of the plurality of device model names have the same resolution.

7. The method of claim 1 , wherein the plurality of MAC addresses is included in networking model device data, further comprising:

preprocessing the networking device model data, wherein preprocessing the networking device model data further comprises excluding at least one MAC address of the plurality of MAC addresses from subsequent processing based on at least one blacklist.

8. The method of claim 1 , further comprising:

grouping the plurality of MAC addresses based on the plurality of blocks, wherein each block is a portion of a prefix of the respective MAC address, wherein the aggregated statistical model is generated based further on the grouping.

9. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

determining block statistics for each block of a plurality of blocks of a plurality of media access control (MAC) addresses, the plurality of blocks having a plurality of respective prefixes, wherein the plurality of blocks is grouped based on commonalities among the plurality of respective prefixes, wherein the block statistics include a ratio of a number of occurrences of each block to the total number of occurrences of the plurality of blocks;

generating an aggregated statistical model for the plurality of blocks based on the plurality of MAC addresses and the block statistics, wherein each block is a prefix included in one of the plurality of MAC addresses; and

applying the aggregated statistical model to the block statistics of at least one block of the plurality of blocks in order to determine at least one inferred device model, wherein each of the at least one block is grouped into the same group.

10. A system for inferring device models, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

determine block statistics for each block of a plurality of blocks of a plurality of media access control (MAC) addresses, the plurality of blocks having a plurality of respective prefixes, wherein the plurality of blocks is grouped based on commonalities among the plurality of respective prefixes, wherein the block statistics include a ratio of a number of occurrences of each block to the total number of occurrences of the plurality of blocks;

generate an aggregated statistical model for the plurality of blocks based on the plurality of MAC addresses and the block statistics, wherein each block is a prefix included in one of the plurality of MAC addresses; and

apply the aggregated statistical model to the block statistics of at least one block of the plurality of blocks in order to determine at least one inferred device model, wherein each of the at least one block is grouped into the same group.

11. The system of claim 10 , wherein the system is further configured to:

determine a potential device model and corresponding confidence level for each block, wherein each inferred device model is a potential device model having a corresponding confidence level above a threshold.

12. The system of claim 10 , wherein the system is further configured to:

add a first inferred device model of the at least one inferred device model to a device profile.

13. The system of claim 12 , wherein the system is further configured to:

monitor behavior of a networking device based on the device profile to detect abnormal behavior of the first networking device, wherein the abnormal behavior is a deviation from a predetermined normal behavior associated with the first inferred device model device model.

14. The system of claim 10 , wherein the plurality of MAC addresses is included in networking model device data, wherein the system is further configured to:

preprocess the networking device model data, wherein preprocessing the networking device model data further comprises unifying a plurality of device model names among the networking device model data based on an ontology, wherein the ontology defines synonymous device model names.

15. The system of claim 10 , wherein the plurality of MAC addresses is included in networking model device data, wherein the system is further configured to:

preprocess the networking device model data, wherein preprocessing the networking device model data further comprises normalizing a plurality of device model names among the networking device model data such that like device model names of the plurality of device model names have the same resolution.

16. The system of claim 10 , wherein the plurality of MAC addresses is included in networking model device data, wherein the system is further configured to:

preprocess the networking device model data, wherein preprocessing the networking device model data further comprises excluding at least one MAC address of the plurality of MAC addresses from subsequent processing based on at least one blacklist.

17. The system of claim 10 , wherein the system is further configured to:

group the plurality of MAC addresses based on the plurality of blocks, wherein each block is a portion of a prefix of the respective MAC address, wherein the aggregated statistical model is generated based further on the grouping.

18. The system of claim 10 , wherein the at least one blacklist includes any of: a blacklist of device models, a blacklist of categories of device models, and a blacklist of manufacturers.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Apr 21, 2026
From: HERCULES CAPITAL, INC.
To: ARMIS SECURITY LTD; ARMIS INC.
Reel/Frame 075477/0965 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 5, 2024
From: ARMIS SECURITY LTD.
To: HERCULES CAPITAL, INC., AS ADMINISTRATIVE AND COLLATERAL AGENT
Reel/Frame 066740/0499 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2020
From: SHOHAM, RON; HANETZ, TOM; FRIEDLANDER, YUVAL; BEN ZVI, GIL
To: ARMIS SECURITY LTD.
Reel/Frame 052600/0974 →
Continuity (1)
Related Publication 20210349774A1 · Nov 11, 2021
Cited By (4)
US 12,470,593 US 12,572,846 US 12,574,399 US 12,695,752