IoT Network Flow Control via Device Fingerprinting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The management of Internet of Things (IoT) devices is complicated by their diverse network characteristics and protocols, leading to unwieldy multi-level management systems that struggle to adapt to new devices and effectively detect and prevent anomalous behavior.

Innovation Solution

Assigning risk values to IoT device network characteristics, generating a 'fingerprint' of normal behavior, and converting it into flow control rules that are instantiated in a network boundary control system to monitor and enforce normal behavior, triggering alerts or actions for deviations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multi-level management systems are used to manage diverse IoT devices, then device coverage is improved, but system complexity increases and adaptability to new devices deteriorates

Engineering Contradiction:
Improvedevice coverageVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal management system that handles diverse IoT devices through a single platform. The system uses device fingerprints and flow rules to manage different device types uniformly, eliminating the need for multiple specialized management systems while maintaining adaptability to new devices through automated learning and rule generation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If traditional management systems are used, then existing devices are managed, but detection of anomalous behavior is ineffective

Engineering Contradiction:
Improvebehavior detection accuracyVSAvoidmanagement system capability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system continuously monitors network traffic and compares actual device behavior against established flow rules. When deviations are detected, the system generates alerts and can automatically respond to anomalies. This feedback mechanism enables effective detection of anomalous behavior while maintaining manageable system complexity through automated rule-based enforcement.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system pre-establishes flow rules based on device fingerprints before anomalies occur. These rules define expected normal behavior patterns, allowing the system to proactively detect and respond to deviations. This preliminary action approach improves detection reliability without requiring complex real-time analysis of every traffic pattern.

Inventive Principle:
Principle #10Preliminary action

3Extent of automation

If manual management approaches are used, then control over devices is achieved, but automation and dynamic response to threats are lost

Engineering Contradiction:
Improvethreat detection automationVSAvoidcontrol system complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The system automatically generates device fingerprints and flow rules without requiring manual configuration for each device. The automated rule generation and enforcement mechanisms enable dynamic threat detection and response while keeping the control system manageable through standardized processes and algorithms.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10673882B2Network flow control of internet of things (IoT) devices
Publication Date: 2020.06.02 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10673882B2 patent drawing
  • US10673882B2 patent drawing
  • US10673882B2 patent drawing

AI summary

A method, apparatus and computer program product for use in monitoring and controlling network behavior of Internet of Things (IoT) devices connected to a network. According to this approach, a set of network characteristics of an IoT device (e.g., as published by the device manufacturer) are assigned various risk values and then monitored over an initial time period to generate a “fingerprint” of the device's network flow. This flow is then transformed into one or more flow control rules representing “normal” or abnormal behavior of the IoT device. Preferably, the rules are instantiated into a network boundary control system (NBCS), such as an enterprise router, gateway, or the like, and then enforced, e.g., to generate alerts or others actions when the rules are triggered. The approach enables dynamic and automated threat detection and prevention based on anomalous and/or known-bad behavior.