IoT Device Isolation via Virtual Overlay Network Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of IoT devices in network attacks, particularly in DDoS attacks, poses a significant security threat due to their vulnerabilities and lack of proper security measures, leading to potential exposure of private data and compromised networks.

Innovation Solution

The formation of an isolation network that redirects traffic from IoT devices to a server for analysis, allowing for the determination of node profiles and configuration based on machine learning models, thereby isolating and securing the devices within a virtual overlay network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IoT devices are connected directly to the network, then network functionality and ease of operation are improved, but security vulnerability and exposure to attacks increase

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a broker device as an intermediary between IoT devices and the network. The broker establishes isolated communication channels, allowing IoT devices to access network resources without direct exposure. The broker mediates all communications, filtering and controlling traffic to prevent unauthorized access while maintaining device functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network into isolated communication channels for each IoT device through the broker. Each device operates in its own virtualized communication space, separated from other devices and the external network. This segmentation contains potential security breaches within individual channels, preventing lateral movement of attacks across the network.

Inventive Principle:
Principle #1Segmentation

2Reliability

If IoT devices are isolated in a virtual network, then security is improved, but network communication capability may be restricted

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork communication
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic communication channels that can be flexibly configured and modified based on security requirements and communication needs. The broker dynamically establishes, modifies, and terminates communication paths between IoT devices and network resources, allowing security policies to change without physically reconfiguring the network infrastructure.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The broker device provides universal access capabilities for multiple IoT devices through a single platform. It handles diverse communication protocols and traffic types, providing unified security management while maintaining compatibility with various network resources and devices through standardized interfaces.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If traffic from IoT devices is redirected to a server for analysis, then device profiling and security monitoring are improved, but network complexity and infrastructure requirements increase

Engineering Contradiction:
Improvedevice profiling accuracyVSAvoidnetwork infrastructure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges multiple security functions including traffic analysis, device profiling, threat detection, and communication mediation into a single broker device. This consolidation reduces overall network complexity compared to having separate systems for each function, while maintaining comprehensive security monitoring and device characterization capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10212182B2Device profiling for isolation networks
Publication Date: 2019.02.19 CISCO TECHNOLOGY INC
  • US10212182B2 patent drawing
  • US10212182B2 patent drawing
  • US10212182B2 patent drawing

AI summary

In one embodiment, a server instructs one or more networking devices in a local area network (LAN) to form virtual network overlay in the LAN that redirects traffic associated with a particular node in the LAN to the server. The server receives the redirected traffic associated with the particular node. The server determines a node profile for the particular node based in part on an analysis of the redirected traffic. The server configures the particular node based on the determined node profile for the particular node.