IoT SBOM Extraction via Deep Packet Inspection for Vulnerability Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge of maintaining accurate software component and version data on IoT devices is exacerbated by the lack of outgoing data from these devices, which often act as black boxes without native security agents, leading to outdated information and potential security vulnerabilities due to unmonitored software installations and updates.
Innovation Solution
A system that analyzes IoT network traffic using deep packet inspection to detect devices, extract software components and versions, filters out irrelevant data, and updates a device database with uniform schema, periodically querying vulnerability databases for risk assessments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If deep packet inspection is used to extract software component data from IoT network traffic, then measurement precision of software components is improved, but device complexity increases
Solution Approach 1:
The patent introduces an intermediary system positioned between IoT devices and the external network that performs deep packet inspection of traffic flows. This intermediary extracts software component identifiers from protocol messages without requiring modifications to the IoT devices themselves, thereby achieving precise software detection while isolating the complexity within the intermediary rather than the end devices.
Solution Approach 2:
The patent replaces manual or agent-based software inventory methods with automated network traffic analysis. Instead of requiring physical access to devices or installation of security agents, the system uses automated deep packet inspection of network communications to extract software component data, substituting a mechanical/manual process with an automated electronic monitoring system.
2Productivity
If automated tracking of software components is implemented through network traffic analysis, then productivity is improved, but loss of information increases due to filtering out irrelevant data
Solution Approach 1:
The patent implements a feedback mechanism where the system continuously monitors network traffic, extracts software component identifiers, compares them against known software databases, and refines its extraction rules based on observed traffic patterns. This feedback loop enables the system to improve its accuracy over time while maintaining automated operation, balancing productivity gains with information completeness.
Solution Approach 2:
The patent performs preliminary classification and filtering of network traffic data before detailed analysis. By pre-identifying relevant protocol types and message structures that contain software identifiers, the system prepares the data in advance, reducing the need for extensive filtering later and minimizing information loss while maintaining automated tracking efficiency.
3Ease of operation
If vendor-provided SBOM files are used for IoT devices, then ease of operation is improved, but reliability deteriorates due to outdated or incomplete data
Solution Approach 1:
The patent implements continuous automated monitoring of network traffic to track software components on IoT devices. Rather than relying on periodic vendor updates, the system continuously extracts software identifier information from ongoing network communications, ensuring the software inventory remains current and reliable while maintaining ease of operation through automation.
Solution Approach 2:
The patent enables the system to automatically generate and maintain its own software inventory data by analyzing network traffic itself, rather than depending on external vendors to provide accurate SBOM files. This self-service approach allows the system to independently verify and update software component information, improving reliability while keeping the operation simple through automated processes.
Data Source
AI summary
A software bill of materials (SBOM) and vulnerability management system (“system”) disclosed herein extracts software component-related identifiers for Internet of Things (IoT) devices using deep packet inspection. The system filters the identifiers by removing identifiers that match a blacklist of identifiers known to not correspond to software components. The system then populates SBOM fields using a database storing the filtered identifiers with a schema that is uniform across SBOM file formats and queries a vulnerability database with software components indicated in the filtered identifiers to identify vulnerabilities for each IoT device for security risk assessment.


