IP Library › Granted Patent US 10,742,678
Granted Patent B2
US 10,742,678 · App. 15/891,749 · Granted Aug 11, 2020

Vulnerability analysis and segmentation of bring-your-own IoT devices

Inventors: Manikandan Kesavan (Campbell, CA); Plamen Nedeltchev (San Jose, CA); Hugo Latapie (Long Beach, CA); Enzo Fenoglio (Issy-les-Moulineaux, FR)
Assignee: Cisco Technology, Inc.
H04L63/1433G06N20/00H04L63/105H04L63/20H04W12/08H04W12/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,742,678
App. No.
15/891,749
Granted
Aug 11, 2020
Kind
B2
Abstract

In one embodiment, a security device maintains a plurality of security enclaves for a computer network, each associated with a given level of security policies. After detecting a given device joining the computer network, the security device places the given device in a strictest security enclave of the plurality of security enclaves in response to joining the computer network. The security device then subjects the given device to joint adversarial training, where a control agent representing behavior of the given device is trained against an inciting agent, and where the inciting agent attempts to force the control agent to misbehave by applying destabilizing policies. Accordingly, the security device may determine control agent behavior during the joint adversarial training, and promotes the given device to a less strict security enclave of the plurality of enclaves in response to the control agent being robust against the attempts by the inciting agent.

Claims (51)

1. A method, comprising:

maintaining, by a security device for a computer network, a plurality of security enclaves for the computer network, each security enclave associated with a given level of security policies;

detecting, by the security device, a given device joining the computer network;

placing, by the security device, the given device in a strictest security enclave of the plurality of security enclaves in response to joining the computer network;

subjecting, by the security device, the given device to joint adversarial training, wherein a control agent representing behavior of the given device is trained against an inciting agent, wherein the inciting agent attempts to force the control agent to misbehave by applying destabilizing policies;

determining, by the security device, control agent behavior during the joint adversarial training; and

promoting, by the security device, the given device to a less strict security enclave of the plurality of enclaves in response to the control agent being robust against the attempts by the inciting agent based on the control agent behavior.

2. The method as in claim 1 , further comprising:

continuing to subject the given device to joint adversarial training throughout placement in each of the plurality of security enclaves.

3. The method as in claim 1 , further comprising:

demoting the given device to a stricter security enclave of the plurality of security enclaves.

4. The method as in claim 3 , wherein demoting is in response to a detected security failure of the given device.

5. The method as in claim 3 , wherein demoting is in response to a misbehaving control agent during continued subjecting of the given device to joint adversarial training.

6. The method as in claim 3 , wherein demoting is in response to administrator control.

7. The method as in claim 1 , further comprising:

applying a given security policy to the given device according to a current security enclave associated with the given device.

8. The method as in claim 1 , further comprising:

instructing one or more network devices of the computer network to apply a given security policy to the given device according to a current security enclave associated with the given device.

9. The method as in claim 1 , wherein the plurality of security enclaves comprise a guest enclave as the strictest security enclave, a trust enclave as the least strict security enclave, and a quarantine enclave between the guest enclave and trust enclave.

10. The method as in claim 1 , wherein the joint adversarial training is based on unsupervised reinforcement learning.

11. The method as in claim 1 , further comprising:

feeding a data set to the joint adversarial training that was obtained through groups of similar devices to the given device within a secured environment.

12. The method as in claim 1 , wherein the inciting agent within the joint adversarial training is rewarded only for failure of the control agent, and learns actions that make the control agent fail.

13. The method as in claim 1 , wherein the control agent learns a robust policy against disturbances created by actions of the inciting agent.

14. An apparatus, comprising:

one or more network interfaces to communicate with a computer network;

a processor coupled to the network interfaces and configured to execute one or more process; and

a memory configured to store a process executable by the processor, the process when executed configured to:

maintain a plurality of security enclaves for the computer network, each security enclave associated with a given level of security policies;

detect a given device joining the computer network;

place the given device in a strictest security enclave of the plurality of security enclaves in response to joining the computer network;

subject the given device to joint adversarial training, wherein a control agent representing behavior of the given device is trained against an inciting agent, wherein the inciting agent attempts to force the control agent to misbehave by applying destabilizing policies;

determine control agent behavior during the joint adversarial training; and

promote the given device to a less strict security enclave of the plurality of enclaves in response to the control agent being robust against the attempts by the inciting agent based on the control agent behavior.

15. The apparatus as in claim 14 , wherein the process when executed is further configured to:

continue to subject the given device to joint adversarial training throughout placement in each of the plurality of security enclaves.

16. The apparatus as in claim 14 , wherein the process when executed is further configured to:

demote the given device to a stricter security enclave of the plurality of security enclaves.

17. The apparatus as in claim 14 , wherein the process when executed is further configured to:

apply a given security policy to the given device according to a current security enclave associated with the given device.

18. A tangible, non-transitory, computer-readable medium storing program instructions that cause a computer to execute a process comprising:

maintaining a plurality of security enclaves for a computer network, each security enclave associated with a given level of security policies;

detecting a given device joining the computer network;

placing the given device in a strictest security enclave of the plurality of security enclaves in response to joining the computer network;

subjecting the given device to joint adversarial training, wherein a control agent representing behavior of the given device is trained against an inciting agent, wherein the inciting agent attempts to force the control agent to misbehave by applying destabilizing policies;

determining control agent behavior during the joint adversarial training; and

promoting the given device to a less strict security enclave of the plurality of enclaves in response to the control agent being robust against the attempts by the inciting is agent based on the control agent behavior.

19. The computer-readable medium as in claim 18 , wherein the process further comprises:

continuing to subject the given device to joint adversarial training throughout placement in each of the plurality of security enclaves.

20. The computer-readable medium as in claim 18 , wherein the process further comprises:

demoting the given device to a stricter security enclave of the plurality of security enclaves.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2018
From: KESAVAN, MANIKANDAN; NEDELTCHEV, PLAMEN; LATAPIE, HUGO; FENOGLIO, ENZO
To: CISCO TECHNOLOGY, INC.
Reel/Frame 044871/0094 →
Continuity (1)
Related Publication 20190245882A1 · Aug 8, 2019