Automated Port Protocol Detection for IoT Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of configuring access to IoT/IIoT devices for remote maintenance often results in granting overly broad network access, increasing the risk of unauthorized access and creating a large attack surface.

Innovation Solution

A method that involves measuring baseline port and protocol usage of an accessing device while disabling forwarding to a remote device, then measuring usage by an accessing application of specific ports and protocols, and finally opening the necessary ports and protocols for operation with forwarding enabled.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional remote access approaches are used to configure access to IoT/IIoT devices, then remote maintenance capability is improved, but network security deteriorates due to overly broad access permissions

Engineering Contradiction:
Improveremote maintenance capabilityVSAvoidnetwork security risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by measuring baseline port and protocol usage before enabling forwarding to the remote device. This allows the system to pre-identify which ports and protocols are actually needed for the application's functionality, and then configure access permissions accordingly before the remote access connection is established, thus avoiding the need to grant overly broad permissions upfront

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously monitoring port and protocol usage during the application's operation. Based on this feedback information about actual usage patterns, the system can dynamically adjust and refine access permissions to match the minimum necessary scope, ensuring that remote maintenance capability is maintained while minimizing security risks

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If automated detection and configuration of ports and protocols is implemented, then network security is improved by reducing attack surface, but device complexity increases

Engineering Contradiction:
Improveattack surfaceVSAvoidconfiguration complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system enables self-service by allowing the accessing application to automatically discover and declare its own port and protocol requirements during operation. The system then uses this self-provided information to automatically configure the necessary access permissions, eliminating the need for manual configuration by administrators and reducing the complexity of security management despite the automated detection capabilities

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250055833A1Automated detection and configuration of protocols and ports for device access
Publication Date: 2025.02.13 CISCO TECHNOLOGY INC
  • US20250055833A1 patent drawing
  • US20250055833A1 patent drawing
  • US20250055833A1 patent drawing

AI summary

In one embodiment, a method is disclosed comprising: measuring, by a process, a baseline of port and protocol usage of an accessing device while forwarding to a particular remote device is disabled; measuring, by the process, usage by an accessing application of specific ports and protocols while attempting to connect to the particular remote device while forwarding to the particular remote device is disabled; and causing, by the process, opening of the specific ports and protocols for operation of the accessing application with forwarding enabled to the particular remote device.