IP Library › Granted Patent US 11,605,009
Granted Patent B2
US 11,605,009 · App. 16/994,952 · Granted Mar 14, 2023

Network device identification

Inventors: Evaldas Kazlauskis (Siauliai, LT); Jovaldas Januskevicius (Kaunas, LT)
Assignee: Cujo LLC
G06N5/025G06F18/22H04L41/12H04L41/16H04L43/065
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,605,009
App. No.
16/994,952
Granted
Mar 14, 2023
Kind
B2
Abstract

Network device identification. A method includes extracting, from network traffic data of a plurality of user devices in a computer network, one or more data fragments relating to a device model of each user device, associating the one or more data fragments with device identification data assigned to each user device, determining a device model for a specific data fragment based on analyzing one or more data fields associated with the specific data fragment, and generating one or more device model identification rules based on the specific data fragment.

Claims (118)

1. A method comprising:

extracting, from network traffic data of a plurality of user devices in a computer network, one or more data fragments relating to a device model of each user device;

associating the one or more data fragments with device identification data assigned to each user device;

determining a device model for a specific data fragment of the one or more data fragments based on analyzing one or more data fields associated with the specific data fragment; and

generating one or more device model identification rules based on the specific data fragment.

2. The method according to claim 1 , further comprising extracting the one or more data fragments relating to the device model by analysis using one or more of:

static rules, data extraction algorithms, and artificial intelligence applications.

3. The method according to claim 1 , wherein determining the device model for the specific data fragment based on analyzing the one or more data fields associated with the specific data fragment further comprises analyzing historical device model data and applying one or more of:

statistical analysis, encoded decision rules, and one or more artificial intelligence techniques.

4. The method according to claim 3 , wherein determining the device model for the specific data fragment further comprises analyzing one or more of:

a brand of the user device, a type of the user device, a name of the user device, an operating system of the user device, and concreteness of a keyword formed based on a data source type and the one or more data fragments.

5. The method according to claim 1 , wherein generating the one or more device model identification rules further comprises:

selecting one or more further data fragments as one or more device model identification rule candidates based on comparing the one or more further data fragments with the specific data fragment, wherein the one or more further data fragments that are determined to have the highest matching levels with the specific data fragment are selected;

constructing a rule graph for each device model identification rule candidate;

splitting each part of the device model identification rule candidate into separate nodes in the rule graph;

generating a comparison by comparing each node with the specific data fragment;

calculating a matching level for each node based on the comparison; and

accepting or rejecting each device model identification rule candidate based on the matching level.

6. The method according to claim 5 , further comprising:

in response to determining that all parts of the specific data fragment are matched with at least one node in the rule graph, calculating a reverse identification rule by replacing the matched parts of the device model identification rule candidate with the parts of the specific data fragment having the highest matching levels; and

in response to determining that one or more nodes are not matched or that the one or more nodes have a lower matching level, dropping the nodes from the one or more device model identification rules.

7. The method according to claim 5 , further comprising:

determining whether the device model identification rule candidate matches the specific data fragment;

in response to determining that the device model identification rule candidate matches the specific data fragment, marking the device model identification rule candidate as successfully generated device model identification rule; and

in response to determining that the device model identification rule candidate does not match the specific data fragment, selecting the specific data fragment as a device model identification rule.

8. The method according to claim 1 , further comprising:

extracting metadata related to determining the device model and to generating the one or more device model identification rules; and

assigning a device model identification accuracy score to the device model and to each device model identification rule based on the extracted metadata, wherein the device model identification accuracy score is determined by using one or more of:

decision rules, statistical analysis and artificial intelligence techniques.

9. The method according to claim 8 , wherein the metadata comprises one or more of:

a ratio of most common brand, device type, device identification level and/or operating system among user devices transmitting the specific data fragment, acceptance/rejection of the one or more device model identification rules, complexity of the one or more device model identification rules, and similarity of the one or more device model identification rules when compared with the specific data fragment.

10. The method according to claim 8 , further comprising:

in response to determining that the device model identification accuracy score is above a predetermined threshold, accepting the device model; and

in response to determining that the device model identification accuracy score is below the predetermined threshold, rejecting the device model.

11. An apparatus in a computer network system comprising:

one or more processors; and

a non-transitory computer-readable medium comprising stored program code, the program code comprising computer-executable instructions that, when executed by the one or more processors, causes the one or more processors to:

extract, from network traffic data of a plurality of user devices in a computer network, one or more data fragments relating to a device model of each user device;

associate the one or more data fragments with device identification data assigned to each user device;

determine a device model for a specific data fragment of the one or more data fragments based on analyzing one or more data fields associated with the specific data fragment;

generate one or more device model identification rules based on the specific data fragment;

extract metadata related to determining the device model and to generating the one or more device model identification rules; and

assign a device model identification accuracy score to the device model and to each device model identification rule based on the extracted metadata.

12. The apparatus according to claim 11 , wherein the instructions further cause the one or more processors to determine the device model for the specific data fragment based on analyzing one or more data fields associated with the specific data fragment by analyzing historical device model data and applying one or more of:

statistical analysis, encoded decision rules, and one or more artificial intelligence techniques.

13. The apparatus according to claim 12 , wherein, to determine the device model for the specific data fragment, the instructions further cause the one or more processors to analyze one or more of:

a brand of the user device, a type of the user device, a name of the user device, an operating system of the user device, and concreteness of a keyword formed based on a data source type and the one or more data fragments.

14. The apparatus according to claim 11 , wherein, to generate the one or more device model identification rules, the instructions further cause the one or more processors to:

select one or more further data fragments as one or more device model identification rule candidates based on comparing the one or more further data fragments with the specific data fragment, wherein the one or more further data fragments that are determined to have the highest matching levels with the specific data fragment are selected;

construct a rule graph for each device model identification rule candidate;

split each part of the device model identification rule candidate into separate nodes in the rule graph;

generate a comparison by comparing each node with the specific data fragment;

calculate a matching level for each node based on the comparison; and

accept or reject each device model identification rule candidate based on the matching level.

15. The apparatus according to claim 14 , wherein the instructions further cause the one or more processors to:

calculate a reverse identification rule by replacing the matched parts of the device model identification rule candidate with the parts of the specific data fragment having the highest matching levels in response to determining that all parts of the specific data fragment are matched with at least one node in the rule graph; and

drop the nodes from the one or more device identification rules in response to determining that one or more nodes are not matched or that the one or more nodes have a lower matching level.

16. The apparatus according to claim 14 , wherein the instructions further cause the one or more processors to:

determine whether the device model identification rule candidate matches the specific data fragment;

mark the device model identification rule candidate as successfully generated device model identification rule in response to determining that the device model identification rule candidate matches the specific data fragment; and

select the specific data fragment as a device model identification rule in response to determining that the device model identification rule candidate does not match the specific data fragment.

17. The apparatus according to claim 11 , wherein:

the device model identification accuracy score is determined by using one or more of:

decision rules, statistical analysis and artificial intelligence techniques.

18. The apparatus according to claim 11 , wherein the metadata comprises one or more of:

a ratio of most common brand, device type, device identification level and/or operating system among user devices transmitting the specific data fragment, acceptance/rejection of the one or more device model identification rules, complexity of the one or more device model identification rules, and similarity of the one or more device identification rules when compared with the specific data fragment.

19. The apparatus according to claim 11 , wherein the instructions further cause the one or more processors to:

accept the device model in response to determining that the device model identification accuracy score is above a predetermined threshold; and

reject the device model in response to determining that the device model identification accuracy score is below the predetermined threshold.

20. A non-transitory computer-readable medium comprising stored program code, the program code comprising computer-executable instructions that, when executed by a processor, causes the processor to:

extract, from network traffic data of a plurality of user devices in a computer network, one or more data fragments relating to a device model of each user device;

associate the one or more data fragments with device identification data assigned to each user device;

determine a device model for a specific data fragment of the one or more data fragments based on analyzing one or more data fields associated with the specific data fragment;

select one or more further data fragments as one or more device model identification rule candidates based on comparing the one or more further data fragments with the specific data fragment, wherein the one or more further data fragments that are determined to have the highest matching levels with the specific data fragment are selected;

construct a rule graph for each device model identification rule candidate to generate one or more rule graphs; and

generate one or more device model identification rules based on the specific data fragment and the one or more rule graphs.

21. An apparatus in a computer network system comprising:

one or more processors; and

a non-transitory computer-readable medium comprising stored program code, the program code comprising computer-executable instructions that, when executed by the one or more processors, causes the one or more processors to:

extract, from network traffic data of a plurality of user devices in a computer network, one or more data fragments relating to a device model of each user device;

associate the one or more data fragments with device identification data assigned to each user device;

determine a device model for a specific data fragment of the one or more data fragments based on analyzing one or more data fields associated with the specific data fragment; and

generate one or more device model identification rules based on the specific data fragment.

22. A non-transitory computer-readable medium comprising stored program code, the program code comprising computer-executable instructions that, when executed by a processor, causes the processor to:

extract, from network traffic data of a plurality of user devices in a computer network, one or more data fragments relating to a device model of each user device;

associate the one or more data fragments with device identification data assigned to each user device;

determine a device model for a specific data fragment of the one or more data fragments based on analyzing one or more data fields associated with the specific data fragment; and

generate one or more device model identification rules based on the specific data fragment.

23. A method comprising:

extracting, from network traffic data of a plurality of user devices in a computer network, one or more data fragments relating to a device model of each user device;

associating the one or more data fragments with device identification data assigned to each user device;

determining a device model for a specific data fragment of the one or more data fragments based on analyzing one or more data fields associated with the specific data fragment;

generating one or more device model identification rules based on the specific data fragment;

extracting metadata related to determining the device model and to generating the one or more device model identification rules; and

assigning a device model identification accuracy score to the device model and to each device model identification rule based on the extracted metadata.

24. A non-transitory computer-readable medium comprising stored program code, the program code comprising computer-executable instructions that, when executed by a processor, causes the processor to:

extract, from network traffic data of a plurality of user devices in a computer network, one or more data fragments relating to a device model of each user device;

associate the one or more data fragments with device identification data assigned to each user device;

determine a device model for a specific data fragment of the one or more data fragments based on analyzing one or more data fields associated with the specific data fragment;

generate one or more device model identification rules based on the specific data fragment;

extract metadata related to determining the device model and to generating the one or more device model identification rules; and

assign a device model identification accuracy score to the device model and to each device model identification rule based on the extracted metadata.

25. A method comprising:

extracting, from network traffic data of a plurality of user devices in a computer network, one or more data fragments relating to a device model of each user device;

associating the one or more data fragments with device identification data assigned to each user device;

determining a device model for a specific data fragment of the one or more data fragments based on analyzing one or more data fields associated with the specific data fragment;

selecting one or more further data fragments as one or more device model identification rule candidates based on comparing the one or more further data fragments with the specific data fragment, wherein the one or more further data fragments that are determined to have the highest matching levels with the specific data fragment are selected;

constructing a rule graph for each device model identification rule candidate to generate one or more rule graphs; and

generating one or more device model identification rules based on the specific data fragment and the one or more rule graphs.

26. An apparatus in a computer network system comprising:

one or more processors; and

a non-transitory computer-readable medium comprising stored program code, the program code comprising computer-executable instructions that, when executed by the one or more processors, causes the one or more processors to:

extract, from network traffic data of a plurality of user devices in a computer network, one or more data fragments relating to a device model of each user device;

associate the one or more data fragments with device identification data assigned to each user device;

determine a device model for a specific data fragment of the one or more data fragments based on analyzing one or more data fields associated with the specific data fragment;

select one or more further data fragments as one or more device model identification rule candidates based on comparing the one or more further data fragments with the specific data fragment, wherein the one or more further data fragments that are determined to have the highest matching levels with the specific data fragment are selected;

construct a rule graph for each device model identification rule candidate to generate one or more rule graphs; and

generate one or more device model identification rules based on the specific data fragment and the one or more rule graphs.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2020
From: KAZLAUSKIS, EVALDAS; JANUSKEVICIUS, JOVALDAS
To: CUJO LLC
Reel/Frame 053640/0350 →
Continuity (1)
Related Publication 20220051113A1 · Feb 17, 2022
Cited By (2)
US 12,341,778 US 12,641,084