Cloud Security for IoT and ZeroConf Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Internet of Things (IoT) devices and ZeroConf devices pose significant security risks due to poor configuration and lack of monitoring capabilities, making them vulnerable to malware and data theft, as traditional security solutions fail to detect malicious activity within the network.

Innovation Solution

A cloud-based security system that monitors and controls IoT and ZeroConf devices by receiving fingerprints and operation data, determining security risks, and performing policy-based actions such as blocking compromised services or ports, using a promiscuous mode application to detect and communicate with a cloud-based system for real-time threat detection and mitigation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If ZeroConf protocols are used for automatic device discovery and configuration, then ease of operation is improved, but security is worsened due to lack of user awareness and monitoring capabilities

Engineering Contradiction:
Improveautomatic device configurationVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a cloud-based security system as an intermediary that monitors and controls IoT and ZeroConf devices. The system receives fingerprints and operation data from devices, determines security risks, and performs policy-based actions without requiring manual user configuration, thus maintaining ease of operation while improving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If traditional point security solutions are used to monitor traffic, then security monitoring is simplified, but detection capability is worsened as they fail to detect malicious activity within the network

Engineering Contradiction:
Improvesecurity solution architectureVSAvoidmalicious activity detection
Core Design Contradiction:
Device complexityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent moves security monitoring from a traditional point-based approach to a cloud-based distributed architecture. Multiple user devices collect and report device fingerprints and operation data to the cloud security system, which analyzes security risks across the entire network. This dimensional shift enables comprehensive detection of malicious activities that traditional solutions miss.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of manufacture

If IOT devices run with default configurations, then ease of manufacture and deployment is improved, but security is worsened due to vulnerability to attacks

Engineering Contradiction:
Improvedevice deploymentVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The cloud-based security system performs preliminary security assessments by receiving device fingerprints and configuration data before devices are fully deployed. The system determines security risks based on default configurations and performs policy-based actions to mitigate vulnerabilities proactively, rather than reacting to attacks after they occur.

Inventive Principle:
Principle #10Preliminary action

4Difficulty of detecting and measuring

If cloud-based monitoring is implemented for all IOT devices, then security detection capability is improved, but device complexity and data processing requirements increase

Engineering Contradiction:
Improvesecurity risk detectionVSAvoidmonitoring system architecture
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent segments the security monitoring system into distributed components on user devices and a centralized cloud-based security system. Each user device executes an application that collects local device fingerprints and operation data, then reports to the cloud system for centralized analysis. This segmentation distributes the complexity burden while maintaining comprehensive detection capability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11388177B2Systems and methods for security and control of internet of things and ZeroConf devices using cloud services
Publication Date: 2022.07.12 ZSCALER INC
  • US11388177B2 patent drawing
  • US11388177B2 patent drawing
  • US11388177B2 patent drawing

AI summary

Systems and methods for security and control of Internet of Things (IOT) and ZeroConf devices using cloud services. The present disclosure uses an application that runs on a user device in a promiscuous mode to look for potentially vulnerable and compromised machines on the local network. Specifically, the user device can fingerprint ZeroConf and IOT networks based on their static and dynamic behavior. The application discovers all hosts on the network and uses a cloud service such as via a cloud-based system to detect potentially malicious IOTs with known vulnerabilities. Based on an enterprise policy or user's preferences, the solution can alert if any IOT device tries to communicate with the user's device or if the user's device itself broadcasts services running on the device such as screen sharing/file sharing.