IP Library › Granted Patent US 12,261,818
Granted Patent B2
US 12,261,818 · App. 18/346,803 · Granted Mar 25, 2025

System and method of discovering a network asset from a network sample

Inventors: Aviv Yehezkel (Ramat-Gan, IL); Eyal Elyashiv (Ramat Hasharon, IL)
Assignee: TWEENZNET LTD.
H04L61/4541H04L61/4511
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,261,818
App. No.
18/346,803
Granted
Mar 25, 2025
Kind
B2
Abstract

Systems and methods of discovering computer network assets, including: identifying, by a processor, in sampled traffic over at least one computer network, an internet protocol (IP) address of a node communicating over at least one port, wherein the at least one port is associated with an asset type, determining, by the processor, a volume of traffic associated with the IP address of the node communicating over the at least one port, discovering, by the processor, the IP address of the node as belonging to an asset of the asset type, based on the volume of traffic exceeding a dynamic threshold, and adding the asset, by the processor, to a list of discovered assets.

Claims (34)

1. A method of discovering computer network assets, the method comprising:

identifying, by a processor, in sampled traffic over at least one computer network, an internet protocol (IP) address of a node communicating over at least one port, wherein the at least one port is associated with an asset type;

determining, by the processor, a volume of traffic associated with the IP address of the node communicating over the at least one port;

discovering, by the processor, the IP address of the node as belonging to an asset of the asset type, based on the volume of traffic exceeding a dynamic threshold and based on volume of internal communication over the at least one port associated with the asset type that exceeds a port threshold; and

adding the asset, by the processor, to a list of discovered assets,

wherein the dynamic threshold is determined, by the processor, based on a ratio between the port threshold and a number of nodes with internal IP addresses communicating over the at least one port.

2. The method of claim 1 , wherein the port threshold is determined, by the processor, based on a ratio between volume of traffic through the port and total volume of traffic through other ports.

3. The method of claim 1 , wherein the dynamic threshold is determined, by the processor, based on total volume of traffic over the computer network and based on the asset type.

4. The method of claim 1 , comprising detecting, by the processor, an anomaly based on detecting an asset communicating over at least one port not associated with the asset type of the asset.

5. The method of claim 1 , comprising detecting, by the processor, an anomaly based on detecting an internal IP address of a node using an asset configured for external communication.

6. The method of claim 1 , comprising detecting, by the processor, an anomaly based on detecting an external IP address of a node using an asset configured for internal communication.

7. The method of claim 1 , comprising detecting, by the processor, an anomaly based on detecting an internal IP address of a node communicating over at least one port configured for external communication.

8. The method of claim 1 , comprising detecting, by the processor, an anomaly based on detecting an external IP address of a node communicating over at least one port configured for internal communication.

9. The method of claim 1 , wherein adding the asset, byte processor, to the list of discovered assets comprises: adding the IP address of the asset and the asset type to the list of discovered assets.

10. The method of claim 9 , wherein adding an asset, byte processor, tithe list of discovered assets comprises: adding the IP address of the asset and a list of at least one server port, wherein the volume of traffic of the asset over the at least one server port exceeds the dynamic threshold.

11. The method of claim 10 , comprising adding, by the processor, to the list of discovered assets, an IP address of at least one subnetwork in communication with at least one server over the at least one server port, a volume of outbound traffic over the at least one server port, a volume of inbound traffic over the at least one server port and a volume of internal traffic over the at least one server port, wherein the volume of traffic between the server and the at least one subnetwork exceeds the dynamic threshold.

12. A system for discovering computer network assets comprising:

a processor configured to:

identify in sampled traffic over at least one computer network, an internet protocol (IP) address of a node communicating over at least one port, wherein the at least one port is associated with an asset type;

determine a volume of traffic associated with the IP address of the node communicating over the at least one port;

discover the IP address of the node as belonging to an asset of the asset type, based on the volume of traffic exceeding a dynamic threshold and based on volume of internal communication over the at least one port associated with the asset type that exceeds a port threshold; and

add the asset to a list of discovered assets,

wherein the dynamic threshold is determined, by the processor, based on a ratio between the port threshold and a number of nodes with internal IP addresses communicating over the at least one port.

13. The system of claim 12 , wherein the processor is configured to determine the port threshold, based on a ratio between volume of traffic through the port and total volume of traffic through other ports.

14. The system of claim 12 , wherein the processor is configured to determine the dynamic threshold, based on total volume of traffic over the computer network and based on the asset type.

15. The system of claim 12 , wherein the processor is configured to detect an anomaly based on detecting at least one of: an asset communicating over at least one port not associated with the asset type of the asset, an internal IP address of a node using an asset configured for external communication, an external IP address of a node using an asset configured for internal communication.

16. The system of claim 12 , wherein the processor is configured to detect an anomaly based on detecting at least one of: an internal [P address of a node communicating over at least one port configured for external communication, and an external IP address of a node communicating over at least one port configured for internal communication.

17. The system of claim 16 , wherein the processor is configured to add an asset to the list of discovered assets, comprising: adding the IP address of the asset and a list of at least one server port, wherein the volume of traffic of the asset over the at least one server port exceeds the dynamic threshold.

18. A method of determining computer network assets, the method comprising:

sampling, by a processor, traffic over a computer network;

determining, by the processor, an internet protocol (IP) address of a node communicating over a port in the sampled traffic, wherein the at least one port is associated with an asset type;

checking, by the processor, if a volume of traffic associated with the IP address of the node communicating over the at least one port is exceeding a dynamic threshold; and

adding the asset, by the processor, to a list of discovered assets based on determination of the IP address of the node as belonging to an asset of the asset type when the volume of traffic is exceeding the dynamic threshold and based on volume of internal communication over the at least one port associated with the asset type that exceeds a port threshold,

wherein the dynamic threshold is determined, by the processor, based on a ratio between the port threshold and a number of nodes with internal IP addresses communicating over the at least one port.

Assignments (2)
SECURITY INTEREST Recorded Dec 18, 2024
From: TWEENZNET LTD.
To: HOFFMAN, CARL W
Reel/Frame 069621/0942 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2024
From: YEHEZKEL, AVIV; ELYASHIV, EYAL
To: TWEENZNET LTD.
Reel/Frame 066398/0696 →
Continuity (2)
Provisional Application 63358552 · Jul 6, 2022
Related Publication 20240015134A1 · Jan 11, 2024
References Cited (16)
US 9489154B1 · Haapanen · 2016 [cited by examiner]
US 9847965B2 · Hugard, IV · 2017 [cited by examiner]
US 10171318B2 · Pon · 2019 [cited by examiner]
US 10320619B2 · Seddigh · 2019 [cited by examiner]
US 11115799B1 · Du · 2021 [cited by examiner]
US 11212183B1 · Hankins · 2021 [cited by examiner]
US 11216889B1 · Gray · 2022 [cited by examiner]
US 11616793B2 · Fry · 2023 [cited by examiner]
US 20120226807A1 · Panella · 2012 [cited by examiner]
US 20170317899A1 · Taylor · 2017 [cited by examiner]
US 20190281072A1 · Al Khater · 2019 [cited by examiner]
US 20210105304A1 · Kraning · 2021 [cited by examiner]
US 20220255805A1 · Hausermann · 2022 [cited by examiner]
N. Msadek, R. Soua and T. Engel, “IoT Device Fingerprinting: Machine Learning based Encrypted Traffic Analysis,” 2019 IEEE Wireless Communications and Networking Conference (WCNC), Marrakesh, Morocco, 2019, pp. 1-8, doi… [cited by examiner]
J. Thom, N. Thom, S. Sengupta and E. Hand, “Smart Recon: Network Traffic Fingerprinting for IoT Device Identification,” 2022 IEEE 12th Annual Computing and Communication Workshop and Conference (CCWC), Las Vegas, NV, US… [cited by examiner]
Dong, Shuaike, et al. ‘Your Smart Home Can't Keep a Secret: Towards Automated Fingerprinting of IoT Traffic with Neural Networks’. arXiv [Cs.CR], 2019, http://arxiv.org/abs/1909.00104. arXiv. (Year: 2019). [cited by examiner]