ML-Based IoT Device Classification for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing prevalence of IoT devices in networks poses a security risk due to their generally lower security standards and lack of oversight, making them vulnerable targets for cyber threats, which existing technologies fail to effectively classify and manage.

Innovation Solution

A method and system utilizing machine learning models to classify network devices as IoT or non-IoT devices based on network activity data, featuring extraction, and feature engineering, allowing for enhanced monitoring and security measures for identified IoT devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IoT devices are deployed in networks, then network functionality and connectivity are enhanced, but network security and vulnerability to cyber threats deteriorate

Engineering Contradiction:
Improvenetwork functionalityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary classification of devices as IoT or non-IoT before security threats can exploit vulnerabilities. By identifying IoT devices early through machine learning analysis of network activity patterns, the system enables proactive security measures to be applied before attacks occur, resolving the contradiction between deploying IoT devices for functionality and protecting network security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a machine learning-based classification system as an intermediary layer between IoT devices and the network. This intermediary analyzes network activity data, extracts features, and classifies devices without requiring direct access to device internals, thereby enabling security monitoring while maintaining device functionality and connectivity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If machine learning classification systems are implemented, then IoT device identification accuracy is improved, but system complexity and computational requirements increase

Engineering Contradiction:
Improvedevice classification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts specific relevant features from network activity data such as connection patterns, packet sizes, and protocol usage. By taking out only the most discriminative features rather than analyzing all raw data, the system achieves high classification accuracy while reducing computational complexity and making the system more manageable

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The machine learning model automatically trains and classifies devices without requiring manual configuration or expert intervention. The system self-adjusts to new device types through continuous learning from network activity patterns, reducing operational complexity while maintaining high classification precision

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11706236B2Autonomous application of security measures to IoT devices
Publication Date: 2023.07.18 RAPID7 INC
  • US11706236B2 patent drawing
  • US11706236B2 patent drawing
  • US11706236B2 patent drawing

AI summary

Methods and systems for classifying a device on a network. The systems and methods may receive network activity data associated with an unknown device. A classifier executing one or more machine learning models may then classify the device as an internet of things (IoT) device or a non-IoT device.