The document discusses methods for identifying devices on a local area network (LAN). It explains that traditional intrusion detection and prevention systems assumed all LAN devices were PCs, but with the rise of IoT, devices now include appliances, sensors, and more. The document then outlines several passive methods for detecting LAN devices, including checking: (1) the device MAC address' organizationally unique identifier to determine brand, (2) DHCP options like client identifier for fingerprints, (3) HTTP user-agent strings for clues, and (4) common applications used. Identifying LAN devices provides benefits for monitoring, access control, and generating threat intelligence.
Related topics: