IoT Device Detection via Passive Packet Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of connected IoT devices poses challenges in securing them against malware and managing networks, as existing systems lack efficient automatic device discovery and configuration methods, particularly for non-technical users.

Innovation Solution

A device detection appliance that automatically discovers and categorizes connected devices by analyzing packet data and collaborating with remote servers to provide security services, manage configurations, and redirect traffic for threat detection and secure communication, facilitating secure network management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual device configuration and management is performed, then device security and network management can be achieved, but the complexity and burden increase significantly for users managing large numbers of devices

Engineering Contradiction:
Improvedevice securityVSAvoiddevice management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables devices to automatically register and configure themselves with the gateway device without human intervention. Each device performs self-discovery and self-registration by transmitting device information packets that contain unique identifiers and capability data, allowing the gateway to automatically provision security policies and network configurations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The gateway device maintains a pre-configured device information database containing security policies, network parameters, and management rules before devices connect. When a device registers, the gateway retrieves and applies the appropriate pre-prepared configuration data, eliminating the need for manual setup and reducing operational complexity while maintaining security standards.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If automatic device discovery systems are implemented, then device detection speed improves, but the system complexity and resource requirements increase

Engineering Contradiction:
Improvedevice detection speedVSAvoiddetection system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent replaces complex active scanning and probing mechanisms with a passive packet interception approach. The gateway device captures device information packets that devices automatically transmit during their normal connection establishment process, substituting mechanical detection actions with event-driven observation that reduces system complexity while maintaining detection speed.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The gateway device performs multiple functions simultaneously: it acts as a network router, a device discovery system, a security policy enforcement point, and a configuration management server. By consolidating these functions into a single multi-functional device, the system avoids the complexity of multiple specialized components while achieving high detection productivity through centralized packet analysis.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3437260B1System and methods for automatic device detection
Publication Date: 2021.09.29 BITDEFENDER IPR MANAGEMENT
  • EP3437260B1 patent drawingFigure 1-A
  • EP3437260B1 patent drawingFigure 1-B
  • EP3437260B1 patent drawingFigure 2

AI summary

Described systems and methods enable an automatic device detection/discovery, particularly of 'Internet of Things' client devices such as wearables, mobile communication devices, and smart home appliances, among others. Device detection comprises assigning a target device to a device category, such as "tablet computer from an unknown manufacturer, running Android®". Some embodiments determine multiple preliminary category assignments according to distinct inputs such as HTTP user agent data, DHCP data, mDNS data, and MAC data. Each preliminary category assignment may come with an associated score. A definitive category assignment may be made according to an aggregate score. Applications include computer security, software provisioning, and remote device management, among others.