IoT Firewall Policies from Passive Profiling of Unmanaged Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security measures are inadequate for protecting networks from malicious activities targeting Internet of Things (IoT) devices, particularly due to their unmanaged nature and lack of support for protocols like RADIUS, leading to potential compromise and catastrophic consequences.

Innovation Solution

A data appliance with an IoT server and module is used to passively monitor and identify IoT devices, providing AAA support and generating security policies based on device profiles, enabling effective management and protection within enterprise networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security measures are used to protect networks, then general security coverage is provided, but IoT devices remain vulnerable due to their unmanaged nature and lack of protocol support

Engineering Contradiction:
Improvenetwork securityVSAvoidIoT device compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary system that sits between the network and IoT devices, translating between standard network protocols and device-specific communication patterns. This intermediary enables security policies to be enforced without requiring direct protocol support from the IoT devices themselves, thus resolving the contradiction between maintaining security reliability and accommodating diverse device adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a universal security framework that can handle multiple device types and protocols through a common architecture. By creating a multi-functional security layer that adapts to different IoT device characteristics while enforcing consistent security policies, the system achieves both broad security coverage and device-specific compatibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If granular policy enforcement is implemented for IoT devices, then security is improved, but device complexity and management overhead increase

Engineering Contradiction:
Improvedevice securityVSAvoidsecurity policy management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security policies into hierarchical levels, separating device identification, policy assignment, and enforcement functions. This segmentation allows granular security control to be implemented without requiring complex manual configuration, as the system automatically divides and distributes policy management across multiple manageable components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements self-service capabilities where IoT devices automatically register themselves, receive appropriate security policies, and enforce them without manual intervention. This self-service approach reduces management overhead while maintaining granular security enforcement, as devices autonomously navigate the policy assignment process.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If passive monitoring and identification of IoT devices is performed, then security policy generation is enabled, but system complexity increases

Engineering Contradiction:
Improveautomated policy generationVSAvoidmonitoring system architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system performs preliminary passive monitoring and device identification before security policies are needed. By pre-characterizing devices and their behaviors during an initial observation period, the system builds a knowledge base that enables automatic policy generation without requiring complex real-time analysis, thus reducing operational complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The monitoring system implements feedback loops where observed device behaviors continuously inform and refine security policy generation. This feedback mechanism automates the policy creation process by using actual device performance data, reducing the need for manual configuration while maintaining simplicity through data-driven decision making.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250247684A1IoT security policy on a firewall
Publication Date: 2025.07.31 PALO ALTO NETWORKS INC
  • US20250247684A1 patent drawing
  • US20250247684A1 patent drawing
  • US20250247684A1 patent drawing

AI summary

Techniques for enforcing policies on Internet of Things (IoT) device communications are disclosed. Information associated with a network communication of an IoT device is received. The received information is used to determine a device profile, including a device type, to associate with the IoT device. A recommended security policy to be applied to the IoT device by a security appliance is generated.