Ontology Graph for Networked Device Security Posture Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current networked device management approaches fail to accurately and efficiently discover and secure IoT devices, particularly due to issues like intermittent air-gapping, vendor specificity, vulnerability to typographical errors, and failure to account for device context and importance.

Innovation Solution

The implementation of an ontology graph that represents relationships between devices and physical facilities, using telemetry data to extract device identifications and characteristics, and providing facility-specific security scores for informed management and security posture management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If general device management recommendations are used, then management coverage is improved, but device-specific security effectiveness deteriorates

Engineering Contradiction:
Improvemanagement coverageVSAvoidsecurity effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system transitions from uniform general recommendations to device-specific security recommendations by analyzing individual device characteristics, network roles, and vulnerability profiles. Each device receives tailored security guidance based on its specific context rather than applying the same management approach to all devices.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The device fleet is segmented into distinct groups or individuals based on their security characteristics, network positions, and vulnerability profiles. This segmentation enables the system to apply different management strategies to different device segments, improving both coverage and effectiveness.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If device context and importance are not accounted for, then management simplicity is improved, but security posture accuracy deteriorates

Engineering Contradiction:
Improvemanagement simplicityVSAvoidsecurity posture accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system introduces multiple parameters to characterize devices including their security context, network role, criticality level, and vulnerability profile. By changing from a single-parameter to multi-parameter device characterization, the system achieves both operational simplicity through automated classification and precise security posture measurement.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Devices automatically provide their own context information through telemetry data, eliminating the need for manual device assessment. The system self-organizes device profiles by automatically collecting and analyzing device characteristics, network relationships, and security states.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If comprehensive device discovery is implemented, then device coverage is improved, but system complexity and administrative burden deteriorate

Engineering Contradiction:
Improvedevice coverageVSAvoidadministrative burden
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Devices automatically register themselves with the management system through telemetry data transmission, eliminating the need for manual device discovery and registration. The system self-updates its device inventory as devices join or leave the network, reducing administrative burden while maintaining comprehensive coverage.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-establishes device profiles and security baselines before devices are fully deployed or before security incidents occur. By preparing device contexts and security configurations in advance, the system reduces the complexity of real-time device management and incident response.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12184646B2Networked device security posture management
Publication Date: 2024.12.31 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12184646B2 patent drawing
  • US12184646B2 patent drawing
  • US12184646B2 patent drawing

AI summary

Networked device management is based on an ontology graph which includes device nodes, physical facility nodes, and edges. The ontology graph may go beyond network topology by also documenting: relationships between devices and facilities, facility attributes such as facility-specific security scores, and device characteristics such as whether a device is recognized, whether it is authorized, and its mission criticality. Medical devices, physical condition sensors, and other internet of things devices, including those embedded in vehicles, those located on a vehicle, those used for industrial control, or those which are intermittently air-gapped, are managed. Devices may be discovered by extraction of identifications and characteristics from telemetry data in a staged architecture. Security postures may be assessed, and security recommendations based on device context may be provided.