Networked Device Risk Assessment via Passive Protocol-Aware Traffic Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network management tools for IoT devices are ineffective in identifying and addressing cyber vulnerabilities in networked devices like cameras and sensors due to their passive nature, which can lead to security risks from default credentials and outdated protocols, and active querying methods can disrupt device functionality or miss dormant devices.
Innovation Solution
A passive analysis method using a programmable switch to mirror network traffic, identify communication protocols, and assess vulnerabilities by matching packet signatures with a reference data model, allowing for the extraction and comparison of attribute values against security guidelines to detect and remediate authentication issues.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If active querying methods are used to identify cyber risks, then vulnerability detection capability is improved, but device functionality may be disrupted and dormant devices may be missed
Solution Approach 1:
A programmable network switch acts as an intermediary to passively mirror network traffic to the analysis system. This allows vulnerability detection without directly querying the IoT devices, thereby avoiding disruption to device functionality while still enabling comprehensive security assessment
Solution Approach 2:
The patent replaces active mechanical querying mechanisms with passive traffic analysis. Instead of sending queries that mechanically interact with devices, the system observes and analyzes existing network traffic packets, eliminating the risk of disrupting device operation while maintaining detection capability
2Measurement precision
If repeated active queries are sent to IoT assets, then vulnerability identification is enhanced, but network traffic load increases beyond device capacity
Solution Approach 1:
The programmable network switch serves as a traffic cop that mirrors copies of network packets to the analysis system without requiring the original devices to send additional traffic. This intermediary approach enables thorough vulnerability analysis while keeping the actual network traffic load on IoT devices minimal
Solution Approach 2:
The system creates copies of existing network traffic packets through the programmable switch for analysis purposes. Instead of sending repeated queries that generate additional traffic, the analysis system works with mirrored copies of actual device communications, eliminating extra network load while maintaining identification accuracy
3Measurement precision
If manual individual attention is given to each IoT asset, then security assessment accuracy is improved, but management complexity increases for large networks
Solution Approach 1:
The system implements a universal automated analysis platform that processes security assessments for all IoT devices through a single integrated system. The programmable switch and analysis software work together to provide comprehensive security evaluation across the entire network, eliminating the need for separate manual assessments of each device while maintaining high accuracy through systematic automated analysis
4Ease of operation
If default passwords are used for initial device access, then device deployment ease is improved, but security vulnerability increases
Solution Approach 1:
The system performs preliminary security analysis by examining network traffic patterns and authentication attempts before devices can be compromised. By proactively identifying devices using default credentials through passive traffic monitoring, the system enables preemptive security remediation while devices are still being deployed, maintaining both ease of deployment and security
Data Source
AI summary
Embodiments of the present disclosure may include a computer-implemented method for assessing the risk status of one or more networked devices, including receiving a series of packets from one or more selected networked devices, the series of packets associated with at least one communication protocol. Embodiments may also include identifying the at least one communication protocol associated with the series of packets by matching one or more signatures of the series of packets with at least one reference data model. Embodiments may also include using the at least one identified communication protocol to extract at least one attribute value from the series of packets. Embodiments may also include determining a risk of the at least one attribute value of the networked device by comparing the extracted attribute value to a reference value guideline, the reference value guideline based at least in part on the identified communication protocol.


