IoT SBOM Extraction via Deep Packet Inspection for Vulnerability Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge of maintaining accurate software component and version data on IoT devices is exacerbated by the lack of outgoing data from these devices, which often act as black boxes without native security agents, leading to outdated information and potential security vulnerabilities due to unmonitored software installations and updates.

Innovation Solution

A system that analyzes IoT network traffic using deep packet inspection to detect devices, extract software components and versions, filters out irrelevant data, and updates a device database with uniform schema, periodically querying vulnerability databases for risk assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep packet inspection is used to extract software component data from IoT network traffic, then measurement precision of software components is improved, but device complexity increases

Engineering Contradiction:
Improvesoftware component detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system positioned between IoT devices and the external network that performs deep packet inspection of traffic flows. This intermediary extracts software component identifiers from protocol messages without requiring modifications to the IoT devices themselves, thereby achieving precise software detection while isolating the complexity within the intermediary rather than the end devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual or agent-based software inventory methods with automated network traffic analysis. Instead of requiring physical access to devices or installation of security agents, the system uses automated deep packet inspection of network communications to extract software component data, substituting a mechanical/manual process with an automated electronic monitoring system.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If automated tracking of software components is implemented through network traffic analysis, then productivity is improved, but loss of information increases due to filtering out irrelevant data

Engineering Contradiction:
Improveautomated software tracking efficiencyVSAvoidsoftware component information completeness
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent implements a feedback mechanism where the system continuously monitors network traffic, extracts software component identifiers, compares them against known software databases, and refines its extraction rules based on observed traffic patterns. This feedback loop enables the system to improve its accuracy over time while maintaining automated operation, balancing productivity gains with information completeness.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary classification and filtering of network traffic data before detailed analysis. By pre-identifying relevant protocol types and message structures that contain software identifiers, the system prepares the data in advance, reducing the need for extensive filtering later and minimizing information loss while maintaining automated tracking efficiency.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If vendor-provided SBOM files are used for IoT devices, then ease of operation is improved, but reliability deteriorates due to outdated or incomplete data

Engineering Contradiction:
Improvesoftware inventory management simplicityVSAvoidsoftware component data accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements continuous automated monitoring of network traffic to track software components on IoT devices. Rather than relying on periodic vendor updates, the system continuously extracts software identifier information from ongoing network communications, ensuring the software inventory remains current and reliable while maintaining ease of operation through automation.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent enables the system to automatically generate and maintain its own software inventory data by analyzing network traffic itself, rather than depending on external vendors to provide accurate SBOM files. This self-service approach allows the system to independently verify and update software component information, improving reliability while keeping the operation simple through automated processes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12470588B2Software bill of materials and vulnerability management via deep packet inspection
Publication Date: 2025.11.11 PALO ALTO NETWORKS INC
  • US12470588B2 patent drawing
  • US12470588B2 patent drawing
  • US12470588B2 patent drawing

AI summary

A software bill of materials (SBOM) and vulnerability management system (“system”) disclosed herein extracts software component-related identifiers for Internet of Things (IoT) devices using deep packet inspection. The system filters the identifiers by removing identifiers that match a blacklist of identifiers known to not correspond to software components. The system then populates SBOM fields using a database storing the filtered identifiers with a schema that is uniform across SBOM file formats and queries a vulnerability database with software components indicated in the filtered identifiers to identify vulnerabilities for each IoT device for security risk assessment.