IoT Firewall Policies from Passive Profiling of Unmanaged Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security measures are inadequate for protecting networks from malicious activities targeting Internet of Things (IoT) devices, particularly due to their unmanaged nature and lack of support for protocols like RADIUS, leading to potential compromise and catastrophic consequences.
Innovation Solution
A data appliance with an IoT server and module is used to passively monitor and identify IoT devices, providing AAA support and generating security policies based on device profiles, enabling effective management and protection within enterprise networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing security measures are used to protect networks, then general security coverage is provided, but IoT devices remain vulnerable due to their unmanaged nature and lack of protocol support
Solution Approach 1:
The patent introduces an intermediary system that sits between the network and IoT devices, translating between standard network protocols and device-specific communication patterns. This intermediary enables security policies to be enforced without requiring direct protocol support from the IoT devices themselves, thus resolving the contradiction between maintaining security reliability and accommodating diverse device adaptability.
Solution Approach 2:
The system implements a universal security framework that can handle multiple device types and protocols through a common architecture. By creating a multi-functional security layer that adapts to different IoT device characteristics while enforcing consistent security policies, the system achieves both broad security coverage and device-specific compatibility.
2Reliability
If granular policy enforcement is implemented for IoT devices, then security is improved, but device complexity and management overhead increase
Solution Approach 1:
The patent segments security policies into hierarchical levels, separating device identification, policy assignment, and enforcement functions. This segmentation allows granular security control to be implemented without requiring complex manual configuration, as the system automatically divides and distributes policy management across multiple manageable components.
Solution Approach 2:
The system implements self-service capabilities where IoT devices automatically register themselves, receive appropriate security policies, and enforce them without manual intervention. This self-service approach reduces management overhead while maintaining granular security enforcement, as devices autonomously navigate the policy assignment process.
3Ease of operation
If passive monitoring and identification of IoT devices is performed, then security policy generation is enabled, but system complexity increases
Solution Approach 1:
The system performs preliminary passive monitoring and device identification before security policies are needed. By pre-characterizing devices and their behaviors during an initial observation period, the system builds a knowledge base that enables automatic policy generation without requiring complex real-time analysis, thus reducing operational complexity.
Solution Approach 2:
The monitoring system implements feedback loops where observed device behaviors continuously inform and refine security policy generation. This feedback mechanism automates the policy creation process by using actual device performance data, reducing the need for manual configuration while maintaining simplicity through data-driven decision making.
Data Source
AI summary
Techniques for enforcing policies on Internet of Things (IoT) device communications are disclosed. Information associated with a network communication of an IoT device is received. The received information is used to determine a device profile, including a device type, to associate with the IoT device. A recommended security policy to be applied to the IoT device by a security appliance is generated.


