IP Library Granted Patent US 10,122,745
Granted Patent B2
US 10,122,745 · App. 15/396,632 · Granted Nov 6, 2018

Heuristics-based identification of IoT (internet of things) attacks in Wi-fi

Inventor: Anil Kaushik (Bangalore, IN)
Assignee: Fortinet, Inc.
H04L63/1425H04L63/145G06F21/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,122,745
App. No.
15/396,632
Granted
Nov 6, 2018
Kind
B2
Abstract

Attacks from IoT (Internet of Things) devices (or other statins) on a Wi-Fi network are identified using heuristics. Frames are detected from an IoT device (or conventional station) over a window of time. The frame is processed to expose IoT application data from the frame over the time window. Deviations are identified in the IoT application data to detect malicious activity from the IoT device by comparing the IoT application data from at least a first time and a second time within the time. Responsive to the IoT data comparison detecting a malicious activity from the IoT device, a network security action is performed in reference to the IoT device, the network security action to prevent the malicious activity.

Claims (22)

1. A computer-implemented method, in an access point of a data communication network, for heuristics-based identification of IoT (Internet of Things) attacks in wireless communication from data, the method comprising the steps of:

transmitting beacons for setting-up a wireless communication connection with an IoT device utilizing a BSSID (Basic Service Set Identifier);

wherein the IoT device comprises a non-computerized physical device that is retrofitted for a network presence;

detecting wireless communication frames transmitted from the IoT device to the access point over a window of time;

applying a heuristic analysis to identify whether the IoT device is malicious by:

processing the wireless communication frames to expose IoT application data from the wireless communication frame over the time window in conjunction with a wireless communication controller having network-wide visibility of the IoT device interactions from at least one other access point;

identifying deviations in the IoT application data to detect malicious activity from the IoT device by comparing the IoT application data from at least a first time and a second time within the time window at least partially based on the network-wide visibility of the IoT device interactions from the at least one other access point; and

responsive to the IoT application data comparison detecting a malicious activity from the IoT device, performing a network security action in reference to the IoT device, the network security action to prevent the malicious activity.

2. The method of claim 1 , further comprising:

comparing the IoT application data to a range of expected IoT application data.

3. The method of claim 1 , further comprises: receiving input from the wireless communication controller for the deviation identification.

4. The method of claim 1 , wherein the IoT device is indirectly connected to a network with a passive RF tag.

5. The method of claim 1 , wherein the IoT device comprises a conventional computer networking device.

6. The method of claim 1 , wherein the malicious activity sent from the IoT device is being sent outside of a local access network.

7. A non-transitory computer-readable medium storing source code that, when executed by a processor, performs a method in an access point of a data communication network, for heuristics-based identification of IoT attacks in wireless communication from data, the method comprising the steps of:

transmitting beacons for setting-up a wireless communication connection with an IoT device utilizing a BSSID (Basic Service Set Identifier);

wherein the IoT device comprises a non-computerized physical device that is retrofitted for a network presence;

detecting wireless communication frames transmitted from the IoT device to the access point over a window of time;

applying a heuristic analysis to identify whether the IoT device is malicious by:

processing the wireless communication frames to expose IoT application data from the wireless communication frame over the time window in conjunction with a wireless communication controller having network-wide visibility of the IoT device interactions from at least one other access point;

identifying deviations in the IoT application data to detect malicious activity from the IoT device by comparing the IoT application data from at least a first time and a second time within the time window at least partially based on the network-wide visibility of the IoT device interactions from the at least one other access point; and

responsive to the IoT application data comparison detecting a malicious activity from the IoT device, performing a network security action in reference to the IoT device, the network security action to prevent the malicious activity.

Assignments (2)
MERGER Recorded Jan 23, 2018
From: MERU NETWORKS, INC.
To: FORTINET, LLC
Reel/Frame 045112/0786 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2017
From: KAUSHIK, ANIL
To: FORTINET, INC.
Reel/Frame 042048/0696 →
Continuity (1)
Related Publication 20180191756A1 · Jul 5, 2018