IoT Network Profile Generation for Malware Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern networks face challenges in detecting and preventing malware attacks on IoT devices, as infected devices often mimic normal behavior, making it difficult to distinguish between legitimate and malicious communications.

Innovation Solution

A system that determines and shares network profiles for IoT devices, generating profiles based on detected communications and converting them into network policies to prevent unauthorized communications, using a server to identify and implement profiles that restrict communications to only acceptable protocols, sources, and destinations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network monitoring is performed to detect malware-infected IoT devices, then security detection capability is improved, but false positives increase because infected devices mimic normal behavior

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoiddetection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the detection approach by creating separate network profiles for each IoT device make and function. Instead of using a single generic detection rule, the system divides detection into device-specific profiles that capture normal communication patterns for each device type, enabling more precise anomaly detection without false positives from normal variations in device behavior

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary action by proactively generating network profiles for IoT devices before malware infection occurs. These profiles establish baseline acceptable communication patterns in advance, allowing the system to quickly compare actual device behavior against predetermined norms and detect deviations that indicate malware infection without being confused by normal behavior variations

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If network profiles are generated for each IoT device make and function, then detection precision is improved, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidprofile management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies universality by creating network profiles based on device make and function categories rather than individual device instances. A single profile template serves multiple devices of the same type, reducing the number of profiles needed while maintaining detection precision. The profile system is multi-functional, serving both as a detection baseline and as a template for generating policies

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses copying by replicating proven network profiles across multiple devices of the same make and function. Once a profile is established for one device type, it can be copied and applied to other devices of the same type, significantly reducing the manual effort required to create and maintain profiles while ensuring consistent detection accuracy across the network

Inventive Principle:
Principle #26Copying

3Reliability

If network policies are implemented to restrict communications, then security is improved, but network functionality may be limited

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by making network policies adaptive rather than static. Policies are generated dynamically based on the device-specific network profiles and can be automatically updated as profiles are refined or as new device types are added to the network. This allows security restrictions to evolve with the network while maintaining functionality for legitimate communications

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback by continuously monitoring network communications and comparing them against device profiles. When legitimate communication patterns are observed that differ from current policies, the system can adjust policies to accommodate these patterns while maintaining security. The feedback loop ensures policies remain aligned with actual network usage and device functionality

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11968223B2Method for generating, sharing and enforcing network profiles for IoT devices
Publication Date: 2024.04.23 CHECK POINT SOFTWARE TECH LTD
  • US11968223B2 patent drawing
  • US11968223B2 patent drawing
  • US11968223B2 patent drawing

AI summary

A method and system is provided for setting network policies based on electronic devices connected to a network. The electronic devices present on the network are detected and their behavior is captured using profiles. These profiles are then used to generate network policies based on the electronic devices connected to the network. Instead of reacting to behavior of the electronic devices (e.g., anomaly detection to detect malware), the method and system sets the network policies to prevent unauthorized communications (e.g., before malware is present in the system).