Data obfuscation method

By generating and transmitting decoy data packets that mimic genuine IoT traffic patterns, the method obscures network traffic, preventing eavesdroppers from learning about user behavior and enhancing security in IoT environments.

WO2025172282A1PCT designated stage Publication Date: 2025-08-21BRITISH TELECOM PLC

Patent Information

Application Number
PCT/EP2025/053563
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-16
Filing Date
2025-02-11
Publication Date
2025-08-21

AI Technical Summary

Technical Problem

IoT devices in computing environments transmit network traffic with distinctive signals that can be intercepted by eavesdroppers, revealing information about user behavior and making the environment vulnerable to physical attacks.

Method used

A computer-implemented method involving monitoring network traffic, generating an obfuscation schedule based on this traffic, and transmitting decoy data packets with parameters that mimic genuine traffic to obscure the real data packets, using a smart replicator to enhance realism and prevent eavesdroppers from distinguishing between decoys and genuine traffic.

Benefits of technology

The method effectively obfuscates network traffic, making it difficult for eavesdroppers to learn about the environment's occupancy, thereby enhancing security and reducing vulnerability to physical attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025053563_21082025_PF_FP_ABST
    Figure EP2025053563_21082025_PF_FP_ABST
Patent Text Reader

Abstract

An example computer-implemented method of data obfuscation is defined. The computer- implemented method comprises monitoring network traffic from one or more IoT devices in a computing environment; generating an obfuscation schedule based on the monitored network traffic, the obfuscation schedule specifying a transmission time and one or more parameters for each of a plurality of decoy data packets to be transmitted according to the obfuscation schedule transmission times and parameters for a plurality of decoy data packets; and transmitting the decoy data packets according to the obfuscation schedule.
Need to check novelty before this filing date? Find Prior Art

Description

DATA OBFUSCATION METHOD

[0001] The present disclosure relates to data obfuscation in a computing environment containing one or more loT or smart devices.BACKGROUND

[0002] The use of loT (internet of things) or smart devices in a home, business or office environment is becoming increasingly common. These loT devices often form part of a computing environment within a home, business or office environment. In order to ensure security and user privacy, these loT devices generally communicate with each other, computing devices within the computing environment, and servers outside the computing using encrypted communications. However, the network traffic from these loT devices comprise data packets that have distinctive signals. Thus, based on information such as the size and timing of data packets, an eavesdropper into the computing environment may be able to learn about the behaviour of the users within the computing environment. For example, an eavesdropper may be able to establish when a smart lock is being locked and unlocked. This enables the eavesdropper to determine information about the building containing the computing environment. For example, the eavesdropper may be able to establish the occupancy of the building. This can leave the building containing the computing environment vulnerable to physical real-world attacks such as break ins.

[0003] The examples described herein are not limited to examples which solve problems mentioned in this background section.SUMMARY

[0004] Examples of preferred aspects and embodiments of the invention are as set out in the accompanying independent and dependent claims.

[0005] This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.

[0006] In one embodiment a computer-implemented method of data obfuscation is defined. The computer-implemented method comprises monitoring network traffic from one or more loT devices in a computing environment; generating an obfuscation schedule based on the monitored network traffic, the obfuscation schedule specifying a transmission time and one or more parameters for each of a plurality of decoy data packets to be transmitted according to the obfuscation schedule; and transmitting the decoy data packets according to the obfuscation schedule. Generating the obfuscation schedule based on network traffic in the computing environment ensures the obfuscation schedule is reflective of normal network traffic in the computing environment. Hence, when decoy data packets are sent in accordance with the obfuscation schedule, an eavesdropper is unable to distinguish between the decoy data packet and genuine network traffic. This increases the effectiveness of the obfuscation schedule anddecoy data packets as it makes it harder for the eavesdropper to identify the genuine network traffic.

[0007] In some examples, the one or more parameters for each decoy data packet comprise: a purported source MAC address for the decoy data packet, wherein the purported source MAC address corresponds to a MAC address of one of the one or more loT devices. In these examples, the method may further comprise receiving the decoy data packets at a wireless router; determining, by the wireless router, that the decoy data packets are decoy data packets; and sending, by the wireless router, the decoy data packets to a smart replicator. Having the router distinguish between the decoy data packets and genuine data packets prevents the decoy data packets causing problems if they are passed onto other devices which may try and process the decoy data packets.

[0008] In some cases, the above example may further comprise receiving, by the smart replicator, the decoy data packets; and sending, by the smart replicator and via the wireless router, a response to each of at least some of the decoy data packets. Having a smart replicator, send responses, such as acknowledgements, to the decoy data packets further increases the realism of the decoy network traffic and prevents, for example, an eavesdropper determining decoy data packets as being decoys based on the way they are subsequently treated in the computing environment. The smart replicator may be at the wireless router; and sending the decoy data packets to the smart replicator may comprise sending the decoy data packets between internal modules of the wireless router. Alternatively, the smart replicator may be remote from the wireless router; and sending the decoy data packets to the smart replicator may comprise transmitting, by the wireless router, the decoy data packets to the smart replicator. Hence, the smart replicator can form part of the wireless router enabling full integration with the wireless router or may be separate from the wireless router enabling easier retro-fitting of the smart replicator.

[0009] In some examples, the one or more parameters for each decoy packet comprises a purported source MAC address for the decoy data packet, wherein the purported source MAC address corresponds to a MAC address of one of the one or more loT devices; and receiving the decoy data packets at a wireless router; determining, by the wireless router, that the decoy data packets are decoy data packets; and discarding, by the wireless router, the decoy data. Having the wireless router discard the decoy data packets provides an alternative way of ensuring the decoy data packets do not disrupt operation of any of the one or more loT devices or severs that operate with the one or more loT devices.

[0010] In examples where the wireless router determines that the decoy data packets are decoy data packets then in some cases the decoy data packets are encrypted; and determining, by the wireless router, that the decoy data packets are decoy data packets comprises: decrypting the encrypted decoy data packets; and determining that the decoy data packets are decoy data packets from either a header or a content of the decrypted decoy data packets. This enables thewireless router to accurately determine which data packets are decoy data packets. In some examples, all data packets including decoy data packets are encrypted at a link / MAC level so this encryption will be expected. In these cases, the decoy data packets can have, for example, a genuine source IP address, a genuine destination IP address or an indication in the content of the decoy data packet that the data packet is a decoy. This allows the wireless router to detect all decoy data packets and reduces false positives for example when a decoy data packet and genuine data packet are sent at similar times or a genuine data packet is sent in accordance with the obfuscation schedule.

[0011] As an alternative or in addition to the above, in examples where the wireless router determines that the decoy data packets are decoy data packets then, in some cases the wireless router comprises a memory storing a copy of the obfuscation schedule; and determining, by the wireless router, that the decoy data packets are decoy data packets comprises determining that the decoy data packets are decoy data packets based on the obfuscation schedule. This enables the wireless router to determine decoy data packets even if it does not have access to the content of the data packet and / or the data packet is not encrypted at a link / MAC level so the source and destination IP address of the decoy data packet are purported address that are to be ignored.

[0012] In some examples, the monitoring the network traffic comprises determining traffic information associated with the one or more loT devices, wherein the traffic information comprises a size of data packets associated with the one or more loT devices, and the one or more parameters for each of the plurality of decoy data packets comprises a size for the decoy data packet, wherein the size of the decoy data packet is specified to be substantially similar to the size of data packets associated with an loT device from the one or more loT devices. In some examples the size of the decoy data packet being substantially similar to the size of data packets associated with the loT devices comprises the decoy data packet being the same size as the data packets associated with the loT devices. Having the decoy data packets being a same or substantially similar size to genuine data packets makes it harder for an eavesdropper to distinguish the genuine data packets from the decoy data packets.

[0013] In some examples, the monitoring the network traffic comprises determining a monitored time interval between a first data packet associated with the one or more loT devices and a second data packet associated with the one or more loT devices; and a decoy time interval between a transmission time for a first decoy data packet and a transmission time for a second decoy data packet in the obfuscation schedule is substantially similar to the monitored time interval. The first data packet and the second data packet may be from the same loT device of the one or more loT devices or different loT devices of the one or more loT devices. The first and second decoy data packets may have purported source MAC addresses corresponding to the MAC address of the loT device from which the first and second data packet were received respectively. In a computing environment whether automated or with human users, loT devices are often used in pairs or groups or a single loT device sends signals in known patterns.Replicating any time intervals between commonly paired / grouped data packet signals from the one or more loT devices in the obfuscation schedule makes it harder for an eavesdropper to identify decoy data packets which may otherwise be distinguishable by virtue of not following the standard pattern of network traffic in the computing environment.

[0014] In some examples, the monitoring the network traffic comprises monitoring the network traffic using a machine learning model to identify network traffic associated with the one or more loT devices and to associate the network traffic with the one or more loT devices. The use of machine learning models allows data to be extracted from the network traffic that may otherwise be unexpected. Thus, the use of a machine learning model can lead to an improved obfuscation schedule that is harder to distinguish from genuine network traffic.

[0015] In some examples, generating an obfuscation schedule based on the monitored network traffic comprises replicating the network traffic associated with at least one of the one or more loT devices at random times. Replicating at random times means that the obfuscation schedule does not follow a predictable pattern which could then be used by an eavesdropper to identify which parts of the network traffic correspond to decoy data packets sent according to the obfuscation schedule.

[0016] In some examples, transmitting the decoy data packets according to the obfuscation schedule comprises transmitting the decoy data packets by a decoy device in the computing environment, wherein the decoy device is separate from the one or more loT devices. The use of a decoy device to transmit the decoy data packets ensures the decoy data packets are being transmitted in the computing environment while avoiding the need to retrofit or adjust the one or more loT devices to provide decoy data packets. This also ensures that the one or more loT devices can be unaware of the decoy data packets and obfuscation schedules meaning that if one of the one or more loT devices is insecure, it does not compromise the effectiveness of the obfuscation schedule.

[0017] A second embodiment defines a computer-implemented method performed at a network router. The computer implemented method comprises receiving a data packet, wherein a purported source MAC address of the data packet indicates the data packet was received from a first loT device; determining whether the data packet is a decoy data packet or a genuine data packet from the first loT device; and in response to determining the data packet is a decoy data packet forwarding the data packet to a smart replicator; else in response to determining the data packet is a genuine data packet from the first loT device forwarding the data packet to device indicated in a header of the genuine data packet. Thus, in a second embodiment, the application relates to a router that distinguishes between decoy data packets and genuine data packets and / or network traffic and ensures the data packets are correctly processed. This prevents decoy data packets accidentally being actioned which may disrupt or compromise the security of a building in which the computing environment is situated.

[0018] In some examples, the method above further comprises receiving, by the smart replicator, the data packet; and sending, by the smart replicator and via the wireless router, a response to the data packet, wherein a destination address of the response is the purported source MAC address of the data packet. Having a smart replicator, which may or may not be situated at the wireless router, send responses or acknowledgements further improves the realism of the decoy network traffic sent according to the obfuscation schedule and makes it harder for an eavesdropper to distinguish between genuine and decoy data packets.

[0019] It will also be apparent to anyone of ordinary skill in the art, that some of the preferred features indicated above as preferable in the context of one of the aspects of the disclosed technology indicated may replace one or more preferred features of other ones of the preferred aspects of the disclosed technology. Such apparent combinations are not explicitly listed above under each such possible additional aspect for the sake of conciseness.

[0020] Other examples will become apparent from the following detailed description, which, when taken in conjunction with the drawings, illustrate by way of example the principles of the disclosed technology.BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 shows a computing environment comprising loT devices in which the methods of the present application may be implemented.

[0022] Figure 2 is a flowchart describing a method of data obfuscation in accordance with the present application.

[0023] Figure 3 is a flowchart describing a method of how a wireless router processes decoy data packets in accordance with the present application.

[0024] Figure 4 is a flowchart describing a method of acknowledging decoy data packets in accordance with the present application.

[0025] Figure 5 is a flowchart describing an alternative method of data obfuscation in accordance with the present application.

[0026] Figure 6 shows a computing device that can be used to implement the smart replicator and / or decoy device of the present application.

[0027] The accompanying drawings illustrate various examples. The skilled person will appreciate that the illustrated element boundaries (e.g., boxes, groups of boxes, or other shapes) in the drawings represent one example of the boundaries. It may be that in some examples, one element may be designed as multiple elements or that multiple elements may be designed as one element. Common reference numerals are used throughout the figures, where appropriate, to indicate similar features.DETAILED DESCRIPTION

[0028] The following description is made for the purpose of illustrating the general principles of the present technology and is not meant to limit the inventive concepts claimed herein. As will be apparent to anyone of ordinary skill in the art, one or more or all of the particularfeatures described herein in the context of one embodiment are also present in some other embodiment(s) and / or can be used in combination with other described features in various possible combinations and permutations in some other embodiment(s).

[0029] The present application is directed to a computer-implemented method of data obfuscation in a smart home / business environment or computing environment that comprises one or more loT or smart devices. The method comprises monitoring and / or analysing network traffic in the computing or smart environment. The method further comprises generating an obfuscation schedule based on the monitored or analysed network traffic. The obfuscation schedule comprises a schedule upon which decoy data packets should be transmitted in the smart or computing environment and comprises timings for each of the decoy data packets to be transmitted and properties and / or parameters for the decoy data packets. The method then comprises transmitting the decoy data packets in accordance with the obfuscation schedule. In some examples, the method can also comprise forwarding by a wireless router data packets identified as decoy data packets to a smart replicator which can then provide appropriate acknowledgements or responses to increase the realism of decoy network traffic and make it harder for an eavesdropper to distinguish genuine and decoy data packets.

[0030] Figure 1 shows a computing environment 100 comprising a plurality of loT (internet of things) devices 101 a, 101 b, 101 c and 101 d that communicate with each other and the internet via a router 102. While Figure 1 shows four loT devices, a smart thermostat 101 a, a smart lock 101 b, a smart light 101 c and a smart TV 101 d, the skilled person would understand this is purely exemplary and the computing environment 100 can contain any number and any form of suitable loT devices. The plurality of loT devices can also be referred to as smart devices. In the example shown in Figure 1 , computing environment 100 comprises a home environment, such as a single home which may have one or more occupants that share the home. However, in other examples, computing environment could comprise a work environment, such as an office or a multi-home environment such as a halls of residence or a care home. In addition, while computing environment 100 comprises a plurality of loT devices 101 a-101 d, in some examples, the computing environment 100 may comprise only one loT device. The skilled person would understand the computing environment may contain any suitable number of loT devices. Thus, the computing environment comprises one or more loT devices. As will be discussed later, computing environment 100 also includes a decoy device 104 and a smart replicator 107.

[0031] The one or more loT devices 101 a-101 d in the computing environment 100 communicate with each other and with the internet, typically, via a router 102. In some examples the router 102 can be a wireless router and the loT devices can communicate via Wi-Fi. However, in other examples, the router 102 may communicate with the one or more loT devices 101 a-101 d in any other suitable way including Bluetooth or wired connections. The data packets sent by the loT devices 101 a-101d to each other and the internet via the router 102 may be encrypted, for example, using the WPA2 (Wi-Fi Protected Access 2) protocol or any other suitable encryptionprotocol. This means an eavesdropping on the network traffic in the computing environment 100 is unable to read the data packets sent by the one or more loT devices 101 a-101d. However, in many cases, the loT devices 101 a-101 d send distinctive signals in terms of packet size and timing that would allow an eavesdropper to determine information concerning the data packet even if the content of the data packet cannot be decrypted. For example, smart lock device 101 b may send paired signals indicating an unlock and a lock event that occur within a short time frame of each other. In addition, data packets may be sent from a smart lock 101 b at specific times of the day which likely coincide with when someone leaves or arrives at a house. For example, signals may be received at 8am and again at 6:30pm. In another example, smart thermostat 101 a may communicate with a boiler 103 within time intervals which reflect a typical time for the building in which the computing environment 100 is contained to reach a desired temperature. In terms of a home environment, such signals may only be received when an occupant is at home, while in terms of a work environment, such signals may only be received during a standard work day e.g. 9am to 5pm. Thus, despite being unable to decrypt the encrypted data packets, an eavesdropper may be able to learn a lot about the occupancy of the building containing the computing environment from the network traffic within the computing environment 100. Using machine learning models may enable even more information to be extracted. Thus, even without being able to decrypt network traffic, an eavesdropper in a computing environment 100 can learn about the occupancy of a building containing the computing environment 100 enabling the eavesdropper to know when the building is empty and thus vulnerable or, potentially, when only vulnerable occupants are in the building.

[0032] In the present application, decoy data packets are added to the network traffic in the computing environment 100. These decoy data packets obfuscate the actual signals from the one or more loT 101 a-101d devices by adding in additional signals. The decoy data packets added to the network traffic in the present application are transmitted according to an obfuscation schedule determined by monitoring the network traffic in the computing environment 100. Thus, the decoy data packets follow patterns of behaviour typical of the loT devices 101 a-101d in the computing environment 100 and thus an eavesdropper will be unable to distinguish the decoy data packets from genuine network traffic. Thus, an eavesdropper is unable to learn about, e.g. the occupancy of a building containing the computing environment 100.

[0033] Figure 2 shows an example method 200 performed in accordance with the present application in order to determine an obfuscation schedule and transmit decoy data packets in a computing environment 100.

[0034] At step 210 the method comprises monitoring network traffic from one or more loT devices 101 a-101d in a computing environment 100. In some examples, the monitoring the network traffic can be performed by a smart replicator 107 which may be positioned at a router such as wireless router 102 or which can be separate device in the computing environment 100. In other examples, the monitoring network traffic can be performed by the router, such as wirelessrouter 102 itself, either at a specific smart replicator module 107 or as part of other network traffic processing. The monitoring network traffic comprises determining properties of the network traffic from the one or more loT devices 101 a-101d. For example, the monitoring network traffic can comprise determining an loT device 101 a-101d of the one or more loT devices 101 a-101d associated with each data packet in the network traffic, a size of each data packet in the network traffic, a time of transmission of each data packet in the network traffic, a time interval between successive data packets associated with an loT device of the one or more loT devices 101 a-101d and / or a time interval between data packets from different loT devices of the one or more loT devices 101 a-10d.

[0035] As mentioned above, the data packets forming the network traffic are often encrypted. In some example, the monitoring network traffic from the one or more loT devices can be performed on the encrypted network traffic without performing any decryption. This ensures the monitoring has access to the same but not more information as a potential eavesdropper. However, the skilled person would appreciate that since the step of monitoring the network traffic is performed by a trusted device, in other examples, the monitoring the network traffic can comprise decrypting the network traffic and performing the monitoring on the decrypted network traffic.

[0036] In some example, the step of monitoring the network traffic can be performed by a trained machine learning model. To this end, the network traffic may be segmented to divide the network traffic into small bursts of data packets. The segmented network traffic can then be used as an input into the trained machine learning model which outputs information about the one or more loT devices 101 a-101 d associated with the data packets in the network traffic and events (e.g. lock / unlock of a smart lock or turning on and changing channel of a smart TV) of the one or more loT devices 101 a-101d associated with the data packets in the network traffic. In some examples, the trained machine learning model can be trained to identify an loT device and an event of the loT device associated with a set of data packets in the network traffic. In other examples, the trained machine learning model can be trained to identify an loT device and a size and / or timing of data packets associated with the loT device. In some examples, the trained machine learning model can comprise a Random Forest machine learning model, a OneVsRest classifier or a SEQ2SEQ machine learning model. The machine learning model can be trained by collecting network traffic. This training can occur in a computing environment different from computing environment 100 discussed above. In some examples, the machine learning model may be trained using network traffic from multiple computing environments. Training the machine learning model may also comprise segmenting the network traffic to divide the network traffic into small bursts of data packets. Specific features can be determined for the data packets in the segmented network traffic. These specific features can comprise for example an loT device that is associated with a data packet in the network traffic (e.g. an loT device that provided the data packet) and an event associated with a data packet in the network traffic (e.g. an event beingreported / described / actioned in the data packet). These specific features can then be used to train the machine learning model to classify network traffic to identify corresponding features.

[0037] While as mentioned above, in some examples the step of monitoring the network traffic can be performed by a trained machine learning model, in other examples, other suitable ways of monitoring the network traffic may be used. For example, the monitoring the network traffic may comprise determining an loT device that is associated with or is the source of each data packet, a size of each data packet and a timing of each network packet and recording this information. The loT device that is the source of a data packet can be determined from a source MAC address for the data packet. In addition, the size and timing of the data packet can be determined by monitoring when data packets are received by the computing device performing the monitoring and analysing the data packets to determine their size. If the computing device performing the monitoring decrypts the data packets then additional information about the data packets such as destination and event information can also be determined for the network traffic even when a machine learning model is not used as part of the monitoring the network traffic.

[0038] At step 212, the method comprises generating an obfuscation schedule based on the monitored network traffic. The obfuscation schedule comprises a schedule at which decoy data packets should be transmitted in the computing environment 100 to prevent an eavesdropper from learning about the occupancy of a building containing the computing environment 100 if they intercept the network traffic of the computing environment. The obfuscation schedule comprises a transmission time and one or more parameters for each of a plurality of decoy data packets that are to be transmitted in accordance with the obfuscation schedule. In some examples, the obfuscation schedule can be generated by the smart replicator 107 which may form part of the wireless router 102 or may be separate from the wireless router 102. In other examples, the obfuscation schedule may be generated by the wireless router 102 itself. In further examples, another computing device or even an loT device in the system may generate the obfuscation schedule.

[0039] The monitoring the network traffic performed in step 210 can also comprise analysing the network traffic, for example as discussed above. Thus, the monitored network traffic can be considered analysed network traffic. As discussed above, the monitoring / analysing can comprise determining properties of the network traffic from the one or more loT devices 101 a- 101 d. The obfuscation schedule can comprise a schedule for the decoy data packets that replicates / simulates / approximates real behaviour of network packets from the one or more loT devices 101 a-101d only at different times. In other words, the obfuscation schedule can comprise a schedule for decoy data packets that provides false signals for the one or more loT devices 101 a-101d that have some of the same properties / parameters as the real data packets from the one or more loT devices wherein the real properties / parameters were established during the step of monitoring the network traffic 210. These decoy data packets can be transmitted either atrandom times or according to a regular and feasible time schedule. Different properties / parameters and time schedules will be discussed below.

[0040] As discussed above, in many examples, the data packets sent by the one or more loT devices 101 a-101d are encrypted. Hence, an eavesdropper is only able to learn a minimum information about the content of the data packets. However, the eavesdropper would potentially be able to determine a size of the data packet. Hence, if the transmitted decoy data packets are of substantially different size to the data packets transmitted as part of network traffic from the one or more loT devices 101 a-101d, an eavesdropper may be able to distinguish the decoy data packets from the genuine network traffic thus preventing the decoy data packets from fully obfuscating the network traffic.

[0041] Given the above, in some examples, the monitoring the network traffic 210 can comprise determining a size of the data packets associated with the one or more loT devices 101 a-101d. This can involve, for example, determining a size of data packets associated with each or the one or more loT devices 101 a-101d. Some loT devices may always send data packets of the same size. Thus those loT devices can always be associated with data packets of the corresponding size. Other loT devices may send data packets within a range of sizes and / or send different data packets of different sizes. Thus, these loT devices may be associated with more than one size of data packet or a range of sizes of data packet e.g. through an average and standard deviation.

[0042] The obfuscation schedule can associate each decoy data packet with an loT device from the one or more loT devices 101 a-101 d which acts as fictional or purported source of the decoy data packet. The properties / parameters of the decoy data packets in the obfuscation schedule can then comprise an appropriate size of the data packets for the loT devices to which they are associated. In other words, the parameters for each decoy data packet can comprise a size for the decoy data packet wherein the size of the decoy data packet is the same or substantially similar to the size of data packets for the associated loT device. In examples where an loT device is associated with only a single size of data packets, this can involve the decoy data packet having a substantially similar or same size as the size of data packet associated with the loT device. In examples where an loT device is associated with multiple sizes of data packet then the size of the data packet can be chosen at random from either the associated sizes for data packets for the loT device or the range of sizes for data packets for the loT device. Alternatively, if an loT device sends data packets in groups or pairs that always follow a pattern / rule in size of data packet throughout the group / pair, this pattern can be replicated when choosing the appropriate size for the decoy data packet. Having the decoy data packets have a similar or same size as genuine data packets associated with the one or more loT devices 101 a- 101 d ensures an eavesdropper is unable to distinguish the decoy data packets from the real data packets based on size.

[0043] It is noted for completeness that, as discussed above, in many computing environments 100, the data packets from the one or more loT devices 101 a-101 d may be encrypted. This, while as discussed above, the size of the decoy data packets may be selected to conform to the size of data packets in network traffic in the computing environment, the actual content of the decoy data packets can differ. In some examples, the decoy data packets may contain information that when decrypted indicates the decoy data packet is a decoy data packet. In addition or as an alternative, the main body of the decoy data packet may contain information about which loT device of the one or more loT devices 101 a-101d the decoy data packet is associated. As discussed later, this may enable further network traffic in the form of decoy responses to be generated based on the data packet. In addition or as an alternative, the main body of the decoy data packet can comprise randomness, ipsum text or other filler rather than the standard content of a data packet from the network traffic of the computing environment 100. This can allow decoy data packets to be easily distinguished and disregarded and also prevents decoy data packets from being accidentally actioned, something which could risk the safety or security of the building containing the computing environment 100.

[0044] As mentioned above, each of at least some of the decoy data packets from the obfuscation schedule may be associated with an loT device from the one or more loT devices 101 a-101d as a fictional or purported source of the decoy data packet. In some examples, the properties / parameters of each decoy data packets comprises a source MAC address for the data packet. In order to ensure the network traffic seems genuine, the source MAC address for each decoy data packet can be set to the associated loT device for the decoy data packet. Given this is not the genuine source MAC address of the decoy data packet, this source MAC address can be referred to as a purported source MAC address. The use of purported source MAC addresses ensures the decoy data packet appear to come from one of the one or more loT devices 101 a- 101 d in the computing environment 100 rather than an additional device. This avoids having an eavesdropper be able to distinguish the decoy data packets from data packets in the genuine network traffic based on a source of the data packets.

[0045] A user in a computing environment 100 containing one or more loT devices 101 a- 101 d may follow a regular pattern in their usage of the loT devices 101 a-101 d. For example, a user may use a smart lock 101 b to enter their house by unlocking the door and once they have entered the house locking the door. The user may then always switch on a smart TV 101 d once they return home to keep them company. Another user may unlock the smart lock 101 b, turn on a smart light 101 c, adjust the temperature on a smart thermostat 101 a and only then lock the smart lock 101 b. An eavesdropper monitoring a computing environment 100 may use these patterns to distinguish genuine network traffic from decoy data packets. For example, if a user always follows a particular schedule of using loT devices then if the decoy data packets from the obfuscation schedule do not follow that pattern, then an eavesdropper may be able to distinguish the decoy data packets from the genuine network traffic and thus learn about the occupancy of abuilding containing the computing environment 100 even in the presence of the decoy data packets.

[0046] To this end, the step of monitoring the network traffic can comprise determining a monitored time interval between a first and second data packet associated with or sent from / to the one or more loT devices 101 a-101 d in the computing environment 100. In some examples, the first and second data packets may be associated with the same loT device of the one or more loT devices 101 a-101 d. For example, based on use in the computing environment 100 an loT device may always send data packets in pairs or larger groups. For example, if a user always unlocks then locks a smart lock 101 b when entering or leaving a building, the network traffic from the smart lock 101 b may always consist of pairs of network packets separated by a similar time interval. In another example, a smart thermostat 101 a may send pairs of signals corresponding to a switch on heating and switch off heating separate by a time interval that reflects the time to bring a building up to temperature. Thus, in order to determine patterns in the network traffic, the monitoring the network traffic and determining a monitored time interval can comprise determining a time interval between pairs or groups of data packets sent by a single loT device. In other examples, the first and second data packets may be associated with different loT devices from the one or more loT devices 101 a-101 d. For example, based on use in the computing environment 100 a first loT device may always be used after or in combination with a second loT device. For example, a user may always unlock a smart lock 101 b then switch on a smart light 101 c or switch on a smart light 101c and then switch on a smart TV 101 d. Thus, in order to determine patterns in the network traffic, the monitoring the network traffic and determining a monitored time interval can comprise determining a time interval between data packets sent from different loT devices.

[0047] Once a monitored time interval has been determined, the step of generating an obfuscation schedule 212 can comprise generating an obfuscation schedule wherein a decoy time interval between a first and second decoy data packet in the obfuscation schedule is substantially similar to or the same as the monitored time interval. In some examples, the decoy time interval may be identical to the monitored time interval. In other examples, the decoy time interval may be similar to the monitored time interval but with added noise or randomness to reflect that if behaviour is being performed by a user, it is unlikely the time interval between two events associated with the one or more loT devices 101 a-101 d is identical. In some examples the monitored time interval may comprise an average and standard deviation of the time interval between the first and second data packet and the decoy time interval can be selected at random from this range.

[0048] As discussed above, each decoy data packet can be associated with a fictional or purported loT device from the one or more loT devices 101 a-101d. In order to make the decoy data packets appears as genuine network traffic, the first and second decoy data packets can be associated with the loT devices associated with the first and second data packet used todetermine the monitored time interval. As mentioned above, this can be a single loT device or two different loT devices. In some examples, as described above, the associating the decoy data packets with an loT device can comprise having a purported MAC address of the decoy data packet be a MAC address of the associated loT device.

[0049] As discussed above, the obfuscation schedule defines transmission times and one or more parameters / properties for decoy data packets that aim to reflect real world behaviour of the one or more loT devices 101 a-101 d in the computing environment 100 so an eavesdropper is unable to distinguish the decoy data packets from the genuine network traffic and thus is not able to learn about the schedule of occupants of the computing environment 100 from the network traffic. Above, several ways of generating decoy data packet properties for the obfuscation schedule have been discussed. In order to ensure the obfuscation schedule obfuscates the data packets from genuine network traffic, the monitoring network traffic can comprise determining parameters / properties of the data packets in the network traffic, for example as discussed above by determining sizes of data packets in the network traffic, monitored time intervals between data packets in the network traffic and source MAC addresses of one or more loT devices 101 a-101d that produced the data packets in the network traffic. The generating the obfuscation schedule can then comprise generating an obfuscation schedule that replicates the network traffic at random times by containing decoy data packets that replicate the parameters / properties of data packets of the monitored network traffic at random times. In some examples the random times may be throughout the day e.g. over 24 hours. In other examples, the random times may be only during daytime hours thus reflecting times a person is likely to be active in the computing environment 100. In further examples, whether the random times are over 24 hours or just during the day time differs between loT devices. As mentioned above decoy data packets can be associated with an loT device in the computing environment 100. Thus, decoy data packets associated with loT devices that may be used irrespective of occupancy or while occupants are asleep e.g. smart thermostats 101 a may be included in the obfuscation schedule on a 24 hour basis while decoy data packets associated with loT devices that are only likely to be used during waking hours may be included in the obfuscation schedule on a waking hours basis. The times at which the decoy data packets appear in the obfuscation schedule can be random in both cases within the relevant hours. In addition, while the times at which decoy data packets appear in the obfuscation schedule are random, the decoy data packets may be grouped or paired to ensure that any fixed time intervals between data packets remain in the decoy data packets even with the randomness.

[0050] In other examples, instead of replicating the data packets in the network traffic at random in the obfuscation schedule, the obfuscation schedule can replicate the data packets from the network traffic at specific time intervals. For example, the time intervals can be determined by replicating the data packets in the network traffic from one day on another day or by replicating schedules of use from other computing environments. The use of fixed time intervals of this formcan make the replicated data packets appear more realistic than random replication and thus make it harder for an eavesdropper to distinguish between real data packets and decoy data packets.

[0051] After the obfuscation schedule has been generated, the method 200 further comprises in step 214, transmitting the decoy data packets in accordance with the obfuscation schedule. In some examples, the decoy data packets can be transmitted by a device in the computing environment 100 that is separate from the wireless router 102. The device in the computing environment 100 can be specific device for transmitting the decoy data packets referred to as a decoy device 104. However, in other examples, an existing device in the computing environment 100 such as one of the one or more loT devices 101 a-101 d can be used as a decoy device as an alternative to or in addition to having the decoy device 104 be a separate device. In some examples where a smart replicator 107 is used the smart replicator 107 may be at the decoy device 104 instead of the wireless router 102. In other examples, the smart replicator 107 may be separate from the decoy device 104 either being at the wireless router 102 or elsewhere. In some examples, the decoy device 104 could form part of the wireless router by being a second wireless interface of the wireless router with a different MAC address from the first wireless interface of the wireless router that receives the network traffic and decoy data packets. In these examples the first wireless interface and the second wireless interface operate on the same frequency band to enable communication between the two wireless interfaces. In order to enable the decoy device 104 to transmit decoy data packets in accordance with the obfuscation schedule, the obfuscation schedule can be transmitted or otherwise passed to the decoy device 104 from the smart replicator 107, wireless router 102 or other device which generated the obfuscation schedule. The decoy device 104 then transmits data packets in accordance with the obfuscation schedule e.g. the decoy device 104 transmits data packets at the transmission times specified in the obfuscation schedule and with the properties / parameters specified in the obfuscation schedule. As discussed above, while the decoy data packets are transmitted by the decoy device 104, the purported source MAC address of each decoy data packet is an loT device of the one or more loT devices 101 a-101d in the computing environment 100. As the one or more loT devices 101 a-101 d communicate via the wireless router 102, the destination MAC address of the data packets is the wireless router 102.

[0052] The above method 200 provides a method of generating and transmitting decoy data packets in a computing environment 100 to help obfuscate genuine data packets and network traffic so that an eavesdropper cannot learn information about the occupancy or use of a building containing the computing environment 100. In some examples, as well as having a decoy device 104 provide the decoy data packets, it is useful to have the smart replicator 107 and / or the wireless router 102 provide acknowledgements or other responses to the decoy data packet. This prevents an eavesdropper being able to identify that decoy data packets are decoy data packets by noting they are not processed in the same way as genuine data packets.

[0053] Figure 3 shows a method performed by a wireless router 102 such as the wireless router in computing environment 100 in order to process and respond to decoy data packets. In step 310, the wireless router 102 receives the decoy data packets. In some examples, the wireless router 102 can receive the decoy data packets as part of other network traffic that includes genuine network traffic from the one or more loT devices 101 a-101d. When the wireless router 102 receives the decoy data packets, the decoy data packets have a source MAC address that indicates they are from the one or more loT devices 101 a-101d in the computing environment100 wherein different decoy data packets can have different purported source MAC addresses corresponding to different loT devices of the one or more loT devices 101 a-101 d. While the decoy data packets have purported source MAC addresses that indicate they come from loT devices101 a-101d in the computing environment 100, the decoy data packets can actually be received from a decoy device such as decoy device 104.

[0054] At step 312, the method comprises determining by the wireless router 102 that the decoy data packets are decoy data packets. When the network traffic also includes genuine data packets from the one or more loT devices 101 a-101d, this can comprise determining which data packets are decoy data packets and which data packets are genuine data packets. In some examples, after the smart replicator 107 or wireless router 102 generates the obfuscation schedule, the obfuscation schedule can be sent and / or stored at the wireless router 102. The wireless router 102 can then determine a decoy data packet is a decoy data packet based on the obfuscation schedule. In addition or as an alternative, data packets can be encrypted. Thus, both the decoy data packets and genuine data packets in the network traffic can be encrypted. For example the data packets can be encrypted at a link / MAC layer meaning that the content of the data packet and a source and destination IP address of the data packet will be encrypted. In such examples, the wireless router 102 will decrypt data packets when determining how to process the data packets. Hence, the wireless router 102 can determine decoy data packets are decoy data packets from the decrypted decoy data packets and can also determine genuine data packets are genuine data packets in the same way. In such a case, the wireless router may determine decoy data packets are decoy data packets based on the source or destination IP address in the decoy data packets. In addition or as an alternative, the wireless router 102 can determine data packets are decoy or genuine based on content in the body of the data packet. While in many cases link / MAC layer encryption will be used this may not be the case. In such examples, as well as having a purported source MAC address each decoy data packet will have a purported source IP address that corresponds to the loT device the data packet is associated with and a purported destination IP address. The purported destination IP address can be a property / parameter of the decoy data packet in the obfuscation schedule and determined based on the monitoring network traffic. When link / MAC layer encryption is not used, the wireless router 102 can determine whether data packets are decoy data packets either based on an obfuscation schedule or by decryptingthe data packet and determining the data packet is a decoy data packet from the contents of the body of the data packet.

[0055] At step 314, the wireless router 102, sends or forwards the decoy data packets to a smart replicator 107. As mentioned above, in some examples the smart replicator 107 can be positioned at or in the wireless router 102. In these examples, the wireless router 102 sending / forwarding the decoy data packets to the smart replicator 107 can comprise the wireless router 102 passing the decoy data packets between modules of the wireless router 102. In this case, since the decoy data packets are not being transmitted over the wireless network they may not be re-encrypted before being sent from the wireless router 102 to the smart replicator 107. In other examples, the smart replicator 107 may be separate from the wireless router 102. For example, the smart replicator 107 may be separate standalone device, form part of the decoy device 104 or be part of one of the one or more loT devices 101 a-101 d. In such cases, where link / MAC layer encryption is used, the wireless router 102 may re-encrypt the decoy data packets before sending them to the smart replicator 107.

[0056] In examples of step 314 where the network traffic also comprises genuine data packets from the one or more loT devices 101 a-101d, then, in response to determining a data packet is a genuine data packet, the wireless router 102 can forward the data packet to another device indicated in a header of the genuine data packet. For example, the genuine data packet can have a destination IP address and the wireless router 102 can forward the genuine data packet to that IP address.

[0057] Figure 4 shows a method 400 implemented by a smart replicator 107. At step 410, the smart replicator 107 receives the decoy data packets from the wireless router. In response to receiving the decoy data packet the smart replicator 107 can decrypt the decoy data packet. The decoy data packet can comprise information either in a header of the decoy data packet or in a body of the decoy data packet that identifies the loT device of the one or more loT devices 101 a- 101 d that is acting as a purported source of the data packet. This information could comprise a MAC address or IP address for the loT device that is present in the body of the data packet. In addition, this information could comprise a IP address present in the header of the decoy data packet. The decoy data packet may also contain additional information indicating it is a decoy data packet to enable the smart replicator 107 to confirm it is a decoy data packet.

[0058] At step 412, the method performed by the smart replicator 107 further comprises sending a response to at least some of the decoy data packets. The responses can comprise an acknowledgement of receipt of the decoy data packet and / or a data packet that replicates a further message in response to the decoy data packet. The responses can be sent from the smart replicator 107 and via the wireless router 102. Hence, the responses can mimic genuine response traffic. The responses can be directed to the loT device that was the purported source of the decoy data packet, for example by setting a destination IP address of the response to be the loT device that was the purported source of the decoy data packet. In examples where the smartreplicator 107 is at the router and is forming part of the router, the destination MAC address of the response can be the loT device that was the purported source of the decoy data packet. When the replicator is remote from the wireless router 102, an initial destination MAC address can be the wireless router 102 which can then forward the response to a destination MAC address of the loT devices that was the purported source of the decoy data packet.

[0059] In some examples, the responses can appear to come from the wireless router 102 itself to reflect the wireless router 102 acknowledging data packets. In other examples, a purported source MAC address of the response can comprise another loT device in the computing environment 100, a MAC address of a server or computer in the computing environment 100 or network details that indicate the response was received from outside the computing environment 100. Thus, an eavesdropper viewing the response messages will see them as genuine. Having the smart replicator 107 provide response data packets increases the realism of the decoy data packets and decoy network traffic and makes it harder for an eavesdropper to distinguish decoy and genuine data packets.

[0060] As the loT device that receives the response is not expecting a response, it can know to ignore and discard the response. In other examples the body or header of the response may contain information indicating the loT device which will receive the response to ignore and discard the response.

[0061] By having the smart replicator 107 send responses and acknowledgements, more realistic decoy network traffic can be generated. This is because if decoy data packets were simply ignored, an eavesdropper may be able to determine they are decoy data packets based on the lack of further processing.

[0062] Figure 5 shows an alternative method 500 performed by a wireless router 102. In this method, rather than forwarding the decoy data packets to a smart replicator 107, the wireless router 102 discards the decoy data packets.

[0063] In step 510, the wireless router 102 receives the decoy data packets as described above with respect to step 310. As above, in some examples the decoy data packets can be received as part of network traffic that also comprises genuine data packets.

[0064] In step 512, the wireless router 102 determines that the decoy data packets are decoy data packets. This can be done as described above with respect to step 312 of method 300.

[0065] In step 514, in response to determining a data packet is a decoy data packet, the wireless router 102 can discard the decoy data packet rather than forwarding it on to any other device or forwarding it outside the computing environment 100. In some examples, in addition to discarding the decoy data packet, the wireless router 102 can send a response to the decoy data packet. In these examples the wireless router 102 performs the functionality described as being performed by the smart replicator 107 in regards to method 400. As mentioned above, thisincreases the realism of the decoy network traffic and makes it harder to identify decoy data packets.

[0066] As discussed above, the present application defines a computer-implemented method of data obfuscation in a computing environment. In some examples, this method comprises collecting loT traffic, for example a smart replicator 107 can receive and extract information from loT devices about data packets sent from the loT devices. The smart replicator 107 can be at a wireless router or remote from the wireless router. The method can then comprise analysing loT traffic. In this regard, the smart replicator 107 can use machine learning to analyse loT traffic and create a schedule for traffic replica. The method may then further comprise programming a decoy agent. As mentioned above, a decoy device or decoy agent may send the decoy data packets. Thus, the method may comprise the smart replicator 107 sending the traffic replica schedule and traffic profile to the decoy agent. The method may then comprise sending the traffic replica. In this regard, the decoy agent or decoy device may generate and transmits loT traffic replica according to schedule.

[0067] Figure 6 illustrates various components of an example computing device 600 in which the smart replicator 107 or decoy device 104 may be implemented. The computing device is of any suitable form such as a desktop computer, a tablet computer, a wireless router, a laptop computer, or a standalone computing or computer processing device.

[0068] The computing device 600 comprises one or more processors 602 which are microprocessors, controllers or any other suitable type of processors for processing computer executable instructions to control the operation of the device in order to perform the methods of Figures 2 to 5. In some examples, for example where a system on a chip architecture is used, the processors 602 include one or more fixed function blocks (also referred to as accelerators) which implement a part of the method of Figures 2 to 5 in hardware (rather than software or firmware). That is, the methods described herein are implemented in any one or more of software, firmware, hardware. The computing device has a data store holding instructions to implement the methods of Figures 2 to 5 and / or any obfuscation schedule generated. In some examples the computing device can comprise a wireless router. Platform software comprising an operating system 604 or any other suitable platform software is provided at the computing-based device to enable application software 606 to be executed on the device. Although the computer storage media (memory 608) is shown within the computing-based device 600 it will be appreciated that the storage is, in some examples, distributed or located remotely and accessed via a network or other communication link (e.g. using communication interface 610).

[0069] The computing-based device 600 may also in some examples comprise an input / output controller 612 arranged to output display information to a display device 614 which may be separate from or integral to the computing-based device 600. The display information may provide a graphical user interface. The input / output controller 612 may also be arranged to receive and process input from one or more devices, such as a user input device 616 (e.g. amouse, keyboard, camera, microphone or other sensor). In some examples the user input device 616 detects voice input, user gestures or other user actions. In an example the display device 614 also acts as the user input device 616 if it is a touch sensitive display device. The input / output controller 612 outputs data to devices other than the display device in some examples. In other examples the computing-based device 600 may not be connected to a display device 614 or input device 616 and any management of the computing-based device 600 may be done via a remote computing device as is known for wireless routers or loT devices.

[0070] In some examples, the methods of Figures 2 to 5 may be implemented in a network system with steps of the method being performed by a smart replicator 107, a wireless router 102 and a decoy device 104. Each of the smart replicator 107, wireless router 102 and decoy device 104 may comprise a computing device comprising a processor and memory containing computer- readable instructions to implement the method of the device. In addition, each of the smart replicator 107, wireless router 102 and decoy device 104 may comprise a communications interface allowing wireless communication in the computing environment 100. In some examples, each of the smart replicator 107, wireless router 102, and / or decoy device 104 may comprise a computer-based device as described above with respect to Figure 6.

[0071] Any reference to 'an' item refers to one or more of those items. The term 'comprising' is used herein to mean including the method blocks or elements identified, but that such blocks or elements do not comprise an exclusive list and an apparatus may contain additional blocks or elements and a method may contain additional operations or elements. Furthermore, the blocks, elements and operations are themselves not impliedly closed.

[0072] The steps of the methods described herein may be carried out in any suitable order, or simultaneously where appropriate. The arrows between boxes in the figures show one example sequence of method steps but are not intended to exclude other sequences or the performance of multiple steps in parallel. Additionally, individual blocks may be deleted from any of the methods without departing from the scope of the claims. Aspects of any of the examples described above may be combined with aspects of any of the other examples described to form further examples without losing the effect sought. Where elements of the figures are shown connected by arrows, it will be appreciated that these arrows show just one example flow of communications (including data and control messages) between elements. The flow between elements may be in either direction or in both directions.

[0073] Where the description has explicitly disclosed in isolation some individual features, any apparent combination of two or more such features is considered also to be disclosed, to the extent that such features or combinations are apparent and capable of being carried out based on the present specification as a whole in the light of the common general knowledge of a person skilled in the art, irrespective of whether such features or combinations of features solve any problems disclosed herein. In view of the foregoing description it will be evident to a person skilled in the art that various modifications may be made within the scope of the invention.

Claims

CLAIMS1 . A computer-implemented method of data obfuscation, the computer-implemented method comprising: monitoring network traffic from one or more loT devices in a computing environment; generating an obfuscation schedule based on the monitored network traffic, the obfuscation schedule specifying a transmission time and one or more parameters for each of a plurality of decoy data packets to be transmitted according to the obfuscation schedule; and transmitting the decoy data packets according to the obfuscation schedule.

2. The computer-implemented method of any previous claim, wherein: the one or more parameters for each decoy data packet comprise: a purported source MAC address for the decoy data packet, wherein the purported source MAC address corresponds to a MAC address of one of the one or more loT devices; and the method further comprises: receiving the decoy data packets at a wireless router; determining, by the wireless router, that the decoy data packets are decoy data packets; and sending, by the wireless router, the decoy data packets to a smart replicator.

3. The computer-implemented method of claim 2, further comprising: receiving, by the smart replicator, the decoy data packets; and sending, by the smart replicator and via the wireless router, a response to each of at least some of the decoy data packets.

4. The computer-implemented method of claim 2 or claim 3, wherein: the smart replicator is at the wireless router; and sending the decoy data packets to the smart replicator comprises sending the decoy data packets between internal modules of the wireless router.

5. The computer-implemented method of claim 2 or claim 3, wherein: the smart replicator is remote from the wireless router; sending the decoy data packets to the smart replicator comprises transmitting, by the wireless router, the decoy data packets to the smart replicator.

6. The computer-implemented method of any of claim 1 , wherein:the one or more parameters for each decoy packet comprises a purported source MAC address for the decoy data packet, wherein the purported source MAC address corresponds to a MAC address of one of the one or more loT devices; and the method further comprises: receiving the decoy data packets at a wireless router; determining, by the wireless router, that the decoy data packets are decoy data packets; and discarding, by the wireless router, the decoy data.

7. The computer-implemented method of any of claims 2 to 6, wherein: the decoy data packets are encrypted; and determining, by the wireless router, that the decoy data packets are decoy data packets comprises: decrypting the encrypted decoy data packets; and determining that the decoy data packets are decoy data packets from either a header or a content of the decrypted decoy data packets.

8. The computer-implemented method of claims 2 to 6, wherein: the wireless router comprises a memory storing a copy of the obfuscation schedule; and determining, by the wireless router, that the decoy data packets are decoy data packets comprises determining that the decoy data packets are decoy data packets based on the obfuscation schedule.

9. The computer-implemented method of any previous claim, wherein: the monitoring the network traffic comprises determining traffic information associated with the one or more loT devices, wherein the traffic information comprises a size of data packets associated with the one or more loT devices, and the one or more parameters for each of the plurality of decoy data packets comprises a size for the decoy data packet, wherein the size of the decoy data packet is specified to be substantially similar to the size of data packets associated with an loT device from the one or more loT devices.

10. The computer-implemented method of any previous claim, wherein: the monitoring the network traffic comprises determining a monitored time interval between a first data packet associated with the one or more loT devices and a second data packet associated with the one or more loT devices; anda decoy time interval between a transmission time for a first decoy data packet and a transmission time for a second decoy data packet in the obfuscation schedule is substantially similar to the monitored time interval.1 1 . The computer-implemented method of any previous claim, wherein: the monitoring the network traffic comprises monitoring the network traffic using a machine learning model to identify network traffic associated with the one or more loT devices and to associate the network traffic with the one or more loT devices.

12. The computer-implemented method of claim 1 1 , wherein : generating an obfuscation schedule based on the monitored network traffic comprises replicating the network traffic associated with at least one of the one or more loT devices at random times.

13. The computer-implemented method any previous claim, wherein: transmitting the decoy data packets according to the obfuscation schedule comprises transmitting the decoy data packets by a decoy device in the computing environment, wherein the decoy device is separate from the one or more loT devices.

14. A computer-implemented method performed at a network router, the computer implemented method comprising: receiving a data packet, wherein a purported source MAC address of the data packet indicates the data packet was received from a first loT device; determining whether the data packet is a decoy data packet or a genuine data packet from the first loT device; and in response to determining the data packet is a decoy data packet forwarding the data packet to a smart replicator; else in response to determining the data packet is a genuine data packet from the first loT device forwarding the data packet to device indicated in a header of the genuine data packet.

15. The computer-implemented method of claim 14, further comprising: receiving, by the smart replicator, the data packet; and sending, by the smart replicator and via the wireless router, a response to the data packet, wherein a destination address of the response is the purported source MAC address of the data packet.

Citation Information

Patent Citations

  • Method for injecting advertisements based on Openwrt router

    CN105657046A

  • Detecting unsanctioned messages in electronic networks

    GB2568667A

  • Device obfuscation in electronic networks

    GB2568668A

  • System and method for protecting a communication device against identification outside a computer network by generating random and normalized non-iot traffic

    US20210152523A1

Cited By

  • Dynamic address hopping attack target depth interference adjustment method and system

    CN120811782A