IoT Device Identification Using Network Traffic Decision Trees
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems struggle to accurately identify Internet of Things (IoT) devices from a mix of devices in a residential household, leading to inaccurate media exposure data collection and inefficient resource utilization.
Innovation Solution
A method using network traffic data analysis with an IoT classification model, specifically a decision tree, to distinguish IoT devices from other devices by processing activity parameters such as user agent count, domain name count, and average bandwidth, allowing for precise identification and filtering of IoT devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network traffic data is collected from all devices in a household, then media exposure data can be gathered, but IoT devices cannot be distinguished from media-consuming devices leading to inaccurate data
Solution Approach 1:
The patent segments devices into distinct categories (IoT devices vs. media-consuming devices) based on their network traffic characteristics. By analyzing multiple parameters such as user agent count, domain name count, and average bandwidth separately, the system can identify and filter out IoT devices from devices that consume digital media, thereby improving measurement precision without overwhelming complexity
Solution Approach 2:
The patent introduces an intermediary classification system that acts as a mediator between raw network traffic data and media exposure measurements. This intermediary layer processes network traffic data through a decision tree model to identify IoT devices, allowing the system to accurately distinguish device types without requiring direct complex analysis of each device's function
2Productivity
If all devices are included in media exposure tracking, then data collection is comprehensive, but computational resources are wasted on irrelevant IoT devices
Solution Approach 1:
The patent extracts and removes IoT devices from the set of devices subject to media exposure tracking. By identifying devices with characteristics typical of IoT devices (low user agent count, limited domain diversity, consistent bandwidth patterns) and excluding them from further analysis, the system improves productivity by focusing computational resources only on devices that actually consume digital media
Solution Approach 2:
The patent applies partial action by performing comprehensive analysis only on devices that pass the initial IoT classification filter. Rather than analyzing all devices equally, the system performs detailed media exposure tracking only on non-IoT devices, reducing unnecessary computational effort while maintaining data completeness for relevant devices
3Speed
If device classification is simplified, then processing is faster, but accuracy in identifying IoT devices decreases
Solution Approach 1:
The patent segments the classification process into hierarchical stages: first analyzing user agent count, then domain name count, and finally average bandwidth. This segmented approach allows the system to quickly eliminate obvious IoT devices using simple criteria while reserving more detailed analysis for ambiguous cases, thereby maintaining both speed and precision
Solution Approach 2:
The patent changes parameters dynamically based on device behavior patterns. By monitoring multiple parameters (user agent count, domain name count, bandwidth) and adjusting classification thresholds based on observed traffic patterns, the system can accurately identify IoT devices while maintaining efficient processing through adaptive decision-making
Data Source
AI summary
In one example, a method is described. The method includes: obtaining network traffic data characterizing network activity of devices coupled to a network at a media exposure measurement location, processing the network traffic data to generate, for each of multiple devices: activity parameters, each characterizing a network activity of the device, processing the activity parameters using an IoT classification model that includes a decision tree having: (i) multiple internal nodes, each internal node associated with an activity parameter threshold, and (ii) multiple leaf nodes, each leaf node associated with either the IoT device type or the other device type, based on the decision tree, selecting, from the device identifiers included in the network traffic data, a target device identifier corresponding to a leaf node in the decision tree that is associated with the IoT device type, and outputting the target device identifier.


