IoT Workload Capture for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing approaches to protecting computer systems against malware are not universally effective and can be evaded by malware authors, necessitating improved techniques for detection and prevention.

Innovation Solution

The implementation of a data appliance that provides passive AAA support for IoT devices, enabling the identification and classification of IoT devices within a network, and the capture of IoT device application workload to enhance security and prevent malicious activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing protection approaches are implemented, then some level of security is achieved, but malware authors can evade detection and compromise systems

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidmalware evasion capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary classification of IoT devices by analyzing network traffic patterns, device behaviors, and communication characteristics before malware can execute or spread. This proactive approach establishes baseline security profiles that enable early detection of malicious activities, preventing compromises rather than reacting to them after occurrence.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors network traffic from classified IoT devices and provides real-time feedback on detected anomalies and threats. This feedback mechanism enables dynamic adjustment of security measures, allowing the system to adapt to new malware techniques and evolving threats while maintaining reliable protection against known attack patterns.

Inventive Principle:
Principle #23Feedback

2Reliability

If fine-grained control over IoT device access is implemented, then security is improved, but device complexity and management overhead increase

Engineering Contradiction:
Improveaccess control securityVSAvoidnetwork management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements a universal classification framework that handles multiple IoT device types, protocols, and network configurations through a single unified approach. By creating generalizable security profiles and policies that apply across diverse device categories, the system achieves fine-grained access control without requiring separate complex management procedures for each device type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables automated device classification and policy assignment, where IoT devices are automatically categorized based on their network behavior and characteristics, and appropriate security policies are automatically applied. This self-service approach eliminates manual configuration requirements, allowing fine-grained access control to be implemented without increasing management overhead for network administrators.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12224984B2IoT device application workload capture
Publication Date: 2025.02.11 PALO ALTO NETWORKS INC
  • US12224984B2 patent drawing
  • US12224984B2 patent drawing
  • US12224984B2 patent drawing

AI summary

Internet of Things (IoT) device application workload capture is disclosed. A target IoT device is selected. A flow associated with the target IoT device is determined and tagged. Packets from the tagged flow are admitted into a ring buffer. An indication is received that an extraction should be performed on a portion of the packets included in the ring buffer.