Crowdsourced Device Labeling for IoT Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As the Internet of Things (IoT) grows, networks face challenges in automatically configuring access control and security policies for unknown IoT devices, as the device type is often not initially known, leading to potential security risks and inefficiencies in network operations.

Innovation Solution

A labeling service that clusters endpoint devices based on telemetry data, uses machine learning to identify unknown device types, and validates labels through a crowdsourcing mechanism by selecting user interfaces from similar network environments to ensure accurate device type classification and policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the network automatically configures access control policies for known device types, then network security and operational efficiency are improved, but the ability to handle unknown IoT devices deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidhandling unknown devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system enables unknown devices to self-identify their types through automated machine learning classification. The device classification service automatically analyzes telemetry data from unknown devices and assigns device type labels without manual intervention, allowing the network to adapt to new devices while maintaining security policies.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the state of device type classification from static (pre-defined known types only) to dynamic (continuous learning from telemetry data). By using machine learning models that process varying telemetry parameters, the system can identify and classify unknown device types, thereby improving adaptability while maintaining reliable security through automated policy configuration.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If manual labeling of unknown devices is performed, then device type accuracy is improved, but time consumption and operational complexity increase

Engineering Contradiction:
Improvedevice type accuracyVSAvoidlabeling time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The device classification service automatically performs device type labeling by analyzing telemetry data using machine learning models. This self-service approach eliminates the need for manual labeling operations, significantly reducing time consumption while maintaining high accuracy through automated classification algorithms that continuously learn from network data.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual mechanical labeling operations with automated machine learning-based classification. The machine learning model processes telemetry data and automatically assigns device type labels, substituting human operators with an automated intelligent system that achieves both high accuracy and efficiency without time-consuming manual intervention.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If device type classification is performed without validation, then processing speed is improved, but classification accuracy deteriorates

Engineering Contradiction:
Improveclassification speedVSAvoidclassification accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system implements a feedback mechanism where device type labels generated by the machine learning model are validated against ground truth data or expert-labeled samples. This feedback loop allows the system to verify classification accuracy while maintaining processing speed, as the validation occurs efficiently through automated comparison and correction mechanisms that refine the classification results without requiring slow manual review of each device.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11528231B2Active labeling of unknown devices in a network
Publication Date: 2022.12.13 CISCO TECHNOLOGY INC
  • US11528231B2 patent drawing
  • US11528231B2 patent drawing
  • US11528231B2 patent drawing

AI summary

In one embodiment, a labeling service receives telemetry data for a cluster of endpoint devices in a first network environment. The endpoint devices in the cluster are clustered by a device classification service based on their telemetry data and labeled by a device type classifier of the device classification service as being of an unknown device type. The labeling service obtains a first device type label for the cluster of endpoint devices via a first user interface. The labeling service identifies one or more other network environments in which endpoint devices are located that have similar telemetry data as that of the cluster of endpoint devices. The labeling service obtains device type labels for the cluster of endpoint devices via a selected set of user interfaces from the identified one or more other network environments. The labeling service validates the first device type label for the cluster using the device type labels obtained via the selected set of user interfaces from the identified one or more other network environments.