Agentless Security Services for IoT Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing endpoint security solutions are inadequate for Internet of Things (IoT) devices and other 'stripped-down' devices with limited processing, memory, and storage capabilities, as they often require traditional endpoint agents that are not feasible for installation, and updating security software on home gateways is challenging due to their low compute and memory capacities and large installed base.

Innovation Solution

Implementing cloud-based security services that work without any agent on the home gateway or router, using protocols like TR69 to configure routing rules from the cloud, and employing a DNS forwarder/recursive resolver to uniquely identify devices and apply network policies, allowing for agentless security without software or hardware changes on existing gateways.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional endpoint security agents are installed on devices, then security protection is improved, but device compatibility and ease of deployment worsen for IoT and stripped-down devices

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a home gateway as an intermediary device that provides security services to all endpoints in the network. Instead of installing agents on each endpoint device, the gateway acts as a central mediator that inspects, filters, and controls traffic from all devices including IoT devices, traditional computers, and mobile devices. This resolves the contradiction by providing universal security protection without requiring agent installation on any specific device type.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent inverts the traditional security architecture by moving the security function from the endpoint (where agents are installed) to the network gateway. Instead of endpoints initiating security protection through local agents, the gateway proactively provides security services to endpoints. This inversion allows IoT and stripped-down devices to receive security protection without needing to run any security software locally.

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If security software is updated on home gateways, then security effectiveness is improved, but deployment complexity and time increase due to large installed base and limited gateway capacities

Engineering Contradiction:
Improvesecurity effectivenessVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements automated update mechanisms where the home gateway autonomously receives, validates, and installs security software updates without requiring manual user intervention or complex deployment processes. The gateway service automatically manages the update lifecycle including downloading updates from the cloud, verifying their integrity, and applying them to the security functions. This self-service capability dramatically reduces deployment time and simplifies the process for managing large installed bases of gateways.

Inventive Principle:
Principle #25Self-service

3Productivity

If home gateways are equipped with more compute and memory capacity, then security service performance is improved, but device cost and complexity increase

Engineering Contradiction:
Improvesecurity service performanceVSAvoidgateway complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the security service functions into modular components that can be independently managed and optimized. Instead of requiring the gateway to handle all security functions with high computational demand, the security services are divided into distinct modules (e.g., threat intelligence, malware detection, policy enforcement) that can be distributed across the gateway's processing resources or even offloaded to cloud services. This segmentation allows the gateway to provide robust security services without requiring a single high-performance hardware configuration, thereby reducing overall device complexity and cost.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11824645B2Agentless security services
Publication Date: 2023.11.21 MCAFEE LLC
  • US11824645B2 patent drawing
  • US11824645B2 patent drawing
  • US11824645B2 patent drawing

AI summary

There is disclosed in one example a computing apparatus, including: a hardware platform including a processor, a memory, and a network interface; and instructions encoded within the memory to instruct the processor to: receive an incoming packet via the network interface; extract from the incoming packet a source port and a source internet protocol (IP) address; correlate the source port and source IP to a device identifier (ID); receive a network policy for the device ID; and apply the network policy to the incoming packet.