IP Library Granted Patent US 12712908
Granted Patent B2
US 12712908 · App. 18/699,026 · Granted Aug 18, 2026

Computer-implemented method and system for assessing the risk status of one or more networked devices using best practices guidelines

Inventors: Jay Kartik Anand (Sydney, AU); Arunan Sivanathan (Sydney, AU); Mohammed Ayyoob Ahamed Hamza (Sydney, AU); Ziwei Long (Sydney, AU); Hassan Habibi Gharakheili (Sydney, AU)
Assignee: NEWSOUTH INNOVATIONS PTY LIMITED
H04L63/1433H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12712908
App. No.
18/699,026
Granted
Aug 18, 2026
Kind
B2
Abstract

Embodiments of the present disclosure may include a computer-implemented method for assessing the risk status of one or more networked devices, including receiving a series of packets from one or more selected networked devices, the series of packets associated with at least one communication protocol. Embodiments may also include identifying the at least one communication protocol associated with the series of packets by matching one or more signatures of the series of packets with at least one reference data model. Embodiments may also include using the at least one identified communication protocol to extract at least one attribute value from the series of packets. Embodiments may also include determining a risk of the at least one attribute value of the networked device by comparing the extracted attribute value to a reference value guideline, the reference value guideline based at least in part on the identified communication protocol.

Claims (31)

1 . A computer-implemented method for assessing the risk status of one or more networked devices, comprising:

receiving a series of packets from one or more selected networked devices, the series of packets associated with at least one communication protocol;

identifying a communication protocol associated with the series of packets, the identified communication protocol being associated with a reference data model, the reference data model comprising a plurality of attributes of the identified communication protocol;

extracting at least one attribute value of the identified communication protocol from the received series of packets using the reference data model of the identified communication protocol; and

determining a risk of a configuration of the identified communication protocol as implemented by the networked device by comparing the extracted at least one attribute value to a reference value guideline for the identified communication protocol, the reference value guideline based at least in part on the identified communication protocol.

2 . The computer-implemented method of claim 1 , wherein the one or more networked devices is one of a security camera, a thermostat, an occupancy sensor, an HVAC system, a lighting system, an access controller, a fire alarm, a physical security system, a camera, a networked appliance, an industrial device, or a robotic device.

3 . The computer-implemented method of claim 1 , wherein the reference data model is a JSON-formatted data model.

4 . The computer-implemented method of claim 3 , wherein the reference data model further comprises at least one of an attribute value, an info value, a metadata value, and a content value associated with the communication protocol.

5 . The computer-implemented method of claim 4 , wherein an attribute value is at least one of a name, a parser type, a parser pattern, a data type, and a direction.

6 . The computer-implemented method of claim 4 , wherein a meta data value is at least one of an ether type, an IP protocol, a server port, a client port, a traffic mode, a network scope, a relationship, and a content class; and

wherein an info value is at least one of a namespace, version, latest update date, abbreviation, name, description, protocol, protocol URL, and an inheritance.

7 . The computer-implemented method of claim 4 , wherein a content value is at least one of a matcher, an eval, a matcher type, a matcher pattern, and a select; and the at least one attribute value is at least one of a protocol version, an authentication method, a credential, a user agent, and a negotiated cipher.

8 . The computer-implemented method of claim 1 , wherein the at least one communication protocol comprises an application layer protocol, a Secure Socket Layer protocol, a network layer protocol, and a datalink layer.

9 . The computer-implemented method of claim 1 , further comprising implementing a selective inspection of one or more packets from within the series of packets is facilitated using a network switch.

10 . The computer-implemented method of claim 1 , wherein each packet from the series of packets comprises application layer header data and application layer payload data, wherein the at least one attribute value of the identified communication protocol is extracted from at least one of the application layer header data and application layer payload data; and wherein determining the risk comprises comparing the extracted attribute value to an expected value included in the reference value guideline.

11 . A system for assessing the risk status of one or more networked devices, the system comprising:

circuitry for receiving a series of packets from one or more selected networked devices, the series of packets associated with at least one communication protocol;

circuitry for identifying a communication protocol associated with the series of packets, the identified communication protocol being associated with a reference data model, the reference data model comprising a plurality of attributes of the identified communication protocol;

circuitry for extracting at least one attribute value of the identified communication protocol from the received series of packets using the reference data model of the identified communication protocol; and

circuitry for determining a risk of a configuration of the identified communication protocol as implemented by the networked device by comparing the at least one extracted attribute value to a reference value guideline for the identified layer communication protocol, the reference value guideline based at least in part on the identified communication protocol.

12 . The system of claim 11 , wherein the one or more networked devices is one of a security camera, a thermostat, an occupancy sensor, an HVAC system, a lighting system, an access controller, a fire alarm, a physical security system, a camera, a networked appliance, an industrial device, or a robotic device.

13 . The system of claim 11 , wherein the reference data model is a JSON-formatted data model.

14 . The system of claim 13 , wherein the reference data model further comprises at least one of an attribute value, an info value, a metadata value, and a content value associated with the at least one communication protocol.

15 . The system of claim 14 , wherein an attribute value is at least one of a name, a parser type, a parser pattern, a data type, and a direction.

16 . The system of claim 14 , wherein a meta data value is at least one of an ether type, an IP protocol, a server port, a client port, a traffic mode, a network scope, a relationship, and a content class; and

wherein an info value is at least one of a namespace, version, latest update date, abbreviation, name, description, protocol, protocol URL, and an inheritance.

17 . The system of claim 14 , wherein a content value is at least one of a matcher, an eval, a matcher type, a matcher pattern, and a select; and

wherein the at least one attribute value is at least one of a protocol version, an authentication method, a credential, a user agent, and a negotiated cipher.

18 . The system of claim 11 , wherein the at least one communication protocol comprises an application layer protocol, a Secure Socket Layer protocol, a network layer protocol, and a datalink layer.

19 . The system of claim 11 , further comprising implementing a selective inspection of one or more packets from within the series of packets using a network switch.

20 . The system of claim 11 , wherein each packet from the series of packets comprises application layer header data and application layer payload data, wherein the at least one attribute value of the identified communication protocol is extracted from at least one of the application layer header data and application layer payload data; and wherein determining the risk comprises comparing the extracted attribute value to an expected value included in the reference value guideline.