IoT Network Flow Control via Device Fingerprinting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The management of Internet of Things (IoT) devices is complicated by their diverse network characteristics and protocols, leading to unwieldy multi-level management systems that struggle to adapt to new devices and effectively detect and prevent anomalous behavior.
Innovation Solution
Assigning risk values to IoT device network characteristics, generating a 'fingerprint' of normal behavior, and converting it into flow control rules that are instantiated in a network boundary control system to monitor and enforce normal behavior, triggering alerts or actions for deviations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multi-level management systems are used to manage diverse IoT devices, then device coverage is improved, but system complexity increases and adaptability to new devices deteriorates
Solution Approach 1:
The patent implements a universal management system that handles diverse IoT devices through a single platform. The system uses device fingerprints and flow rules to manage different device types uniformly, eliminating the need for multiple specialized management systems while maintaining adaptability to new devices through automated learning and rule generation.
2Reliability
If traditional management systems are used, then existing devices are managed, but detection of anomalous behavior is ineffective
Solution Approach 1:
The system continuously monitors network traffic and compares actual device behavior against established flow rules. When deviations are detected, the system generates alerts and can automatically respond to anomalies. This feedback mechanism enables effective detection of anomalous behavior while maintaining manageable system complexity through automated rule-based enforcement.
Solution Approach 2:
The system pre-establishes flow rules based on device fingerprints before anomalies occur. These rules define expected normal behavior patterns, allowing the system to proactively detect and respond to deviations. This preliminary action approach improves detection reliability without requiring complex real-time analysis of every traffic pattern.
3Extent of automation
If manual management approaches are used, then control over devices is achieved, but automation and dynamic response to threats are lost
Solution Approach 1:
The system automatically generates device fingerprints and flow rules without requiring manual configuration for each device. The automated rule generation and enforcement mechanisms enable dynamic threat detection and response while keeping the control system manageable through standardized processes and algorithms.
Data Source
AI summary
A method, apparatus and computer program product for use in monitoring and controlling network behavior of Internet of Things (IoT) devices connected to a network. According to this approach, a set of network characteristics of an IoT device (e.g., as published by the device manufacturer) are assigned various risk values and then monitored over an initial time period to generate a “fingerprint” of the device's network flow. This flow is then transformed into one or more flow control rules representing “normal” or abnormal behavior of the IoT device. Preferably, the rules are instantiated into a network boundary control system (NBCS), such as an enterprise router, gateway, or the like, and then enforced, e.g., to generate alerts or others actions when the rules are triggered. The approach enables dynamic and automated threat detection and prevention based on anomalous and/or known-bad behavior.


