Dynamic Whitelist Update for IoT Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The presence of IoT devices in networks poses a security risk due to potential DDoS attacks and unauthorized data transmission, which can disrupt legitimate internet activity and compromise sensitive information, as administrators often lack the ability to configure these devices effectively.

Innovation Solution

A method and system for updating a whitelist at a network node that determines and manages destination addresses for IoT devices, restricting data packet transmission based on a predetermined identifier, time period, and maximum data packet transmission rate, with the ability to reset and update the whitelist through an administrator interface and server communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IoT devices are allowed to transmit data freely in the network, then network communication flexibility is improved, but security risk increases due to potential DDoS attacks and unauthorized data transmission

Engineering Contradiction:
Improvenetwork communication flexibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The whitelist is dynamically updated based on observed communication patterns of IoT devices. The system monitors data packets from IoT devices within a time period, automatically adds legitimate destination addresses to the whitelist, and restricts transmissions to non-whitelisted addresses, creating a adaptive security mechanism that evolves with device behavior

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

A network node acts as an intermediary between IoT devices and destination addresses. This intermediary monitors and controls data packet transmissions, determining whether to allow or block packets based on whitelist status, thereby mediating security enforcement without requiring direct configuration of IoT devices

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If administrators configure IoT devices to control data transmission, then security is improved, but ease of operation deteriorates because IoT devices may not be configurable or are under vendor control

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system enables self-service security management where the network node automatically learns and updates whitelists based on observed communication patterns of IoT devices. This eliminates the need for administrators to manually configure each IoT device, as the system autonomously identifies legitimate destinations and enforces transmission restrictions

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The network node serves as an intermediary that implements security controls without requiring configuration of IoT devices. It monitors transmissions, manages whitelists, and enforces restrictions, thereby decoupling security management from device configuration capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If a whitelist is implemented to restrict IoT device transmissions, then security is improved, but device complexity increases due to whitelist management requirements

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The whitelist management system operates autonomously by monitoring data packets from IoT devices, automatically identifying legitimate destination addresses, and updating the whitelist without administrator intervention. This self-learning mechanism simplifies deployment and maintenance despite the underlying complexity of whitelist management

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary monitoring of data packet transmissions within a specified time period before enforcing strict whitelist restrictions. This preliminary phase allows the system to learn legitimate communication patterns and populate the whitelist, preparing the security mechanism in advance of full enforcement

Inventive Principle:
Principle #10Preliminary action

4Object-affected harmful factors

If data transmission from IoT devices is monitored and restricted, then security is improved, but network resource consumption increases due to monitoring overhead

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork resource consumption
Core Design Contradiction:
Object-affected harmful factorsVSLoss of energy

Solution Approach 1:

The system applies monitoring and whitelist management selectively to IoT devices rather than all network traffic. By focusing resources on learning and controlling IoT device transmissions specifically, the system achieves security improvements for this high-risk category while minimizing overall network resource consumption

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10965789B2Method and system for updating a whitelist at a network node
Publication Date: 2021.03.30 PISMO LABS TECH
  • US10965789B2 patent drawing
  • US10965789B2 patent drawing
  • US10965789B2 patent drawing

AI summary

A method and a system for updating a first whitelist at a network node. The network node receives data packets from an Internet of Things (IoT) device and determines a predetermined identifier for the IoT device. The network node then determines whether the predetermined identifier is in the first whitelist. When the predetermined identifier is not in the first whitelist, the network node starts a first time period. When the predetermined identified is on the first whitelist, the network node determines whether the data packets are received within the first time period. When the data packets are received within the first time period, the network node identifies destination addresses of the data packets and updates the first whitelist based on the destination addresses and the predetermined identifier. The updated first whitelist is stored in non-transitory computer readable storage medium in the network node.