IP Library Granted Patent US 10,523,549
Granted Patent B1
US 10,523,549 · App. 16/429,001 · Granted Dec 31, 2019

Method and system for detecting and classifying networked devices

Inventors: Sofia Belikovetsky (Petach Tikva, IL); Moty Zaltsman (Sde Warburg, IL)
Assignee: CYBERTOKA LTD
H04L43/12H04L67/02H04L67/141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,523,549
App. No.
16/429,001
Granted
Dec 31, 2019
Kind
B1
Abstract

Systems and methods are provided for the discovery and classification of Internet of Things (IoT) devices on networks.

Claims (45)

1. A computer-implemented method, for detecting a device on a network, comprising:

probing the network to obtain at least one network parameter from at least one device along the network;

receiving at least one response to the probing the network, the at least one response including a payload of a content length, the content length defining the at least one network parameter;

performing an initial classification into at least one category of the at least one device, based on the content length of the at least one response from the at least one device; and,

performing a secondary classification on the at least one device in the at least one initial category based on data returned by the at least one device after issuing at least one application protocol specific request to the at least one device.

2. The computer-implemented method of claim 1 , wherein the probing the network includes: sending at least one active request to ports associated with the at least one device to establish communication with the at least one device.

3. The computer-implemented method of claim 2 , wherein the at least one active request includes one or more Hypertext Transfer Protocol (HTTP) requests.

4. The computer-implemented method of claim 2 , wherein the probing the network additionally includes: sending at least one GET request to the ports associated with the at least one device.

5. The computer-implemented method of claim 4 , wherein in response to the GET request being received, querying the at least one device through the associated port with protocols for identifying the device by its type.

6. The computer-implemented method of claim 4 , wherein the probing includes applying probing tools to obtain the at least one network parameter.

7. The computer-implemented method of claim 4 , wherein the probing includes one or more of: a) applying probing tools; b) sniffing; or c) applying log analyzers, to obtain the at least one network parameter.

8. The computer-implemented method of claim 7 , wherein the applying log analyzers to obtain the at least one network parameter includes analyzing logs generated by one or more of: routers, wireless access points, security gateways, firewalls, packet filters, load balancers, Domain Name Servers (DNS), Dynamic Host Configuration Protocol (DHCP) servers, and network proxies.

9. The computer-implemented method of claim 1 , wherein the content length is determined by at least one of:

counting the bytes in the payload of the at least one response; or

obtaining the content length from a content-length portion of a header of the at least one response.

10. The computer-implemented method of claim 1 , wherein the performing the initial classification further includes establishing a classification for the at least one device by one or more of:

determining the application protocol used by the at least one device;

determining the function of the application protocol for the at least one device;

determining whether the content length of the probing response is within a predetermined range; and,

the content of the probing response.

11. The computer-implemented method of claim 1 , wherein the application specific protocol request includes a Hypertext Transfer Protocol (HTTP) request.

12. The computer-implemented method of claim 11 , wherein the HTTP request is for a resource associated with the at least one device.

13. The computer implemented method of claim 1 , wherein the secondary classification is based on website content received from the at least one response to the probing the network.

14. The computer-implemented method of claim 13 , wherein the secondary classification additionally comprises: sending one or more of: 1) Transmission Control Protocol (TCP) requests containing vendor specific data, or 2) HTTP requests to vendor specific Uniform Resource Locator (URL), to determine the type of the at least one device from the website associated with the at least one device.

15. A computer system for detecting and classifying a networked device comprising:

a computerized processor coupled to a memory, wherein the processor is configured for:

probing the network to obtain at least one network parameter from at least one device along the network;

receiving at least one response to the probing the network, the at least one response including a payload of a content length, the content length defining the at least one network parameter; and,

performing an initial classification into at least one category of the at least one device, based on the content length of the at least one response from the at least one device; and,

performing a secondary classification on the at least one device in the at least one initial category based on data returned by the at least one device after issuing at least one application protocol specific request to the at least one device.

16. The computer system of claim 15 , wherein the probing the network includes one or more of: a probing tool, a sniffer, and a log analyzer.

17. The system of claim 15 , wherein the receiving the at least one response to the probing the network is configured for determining the content length by at least one of:

counting the bytes in the payload of the at least one response; or

obtaining the content length from a content-length portion of a header of the at least one response.

18. The computer system of claim 15 , wherein the performing the initial classification includes establishing a classification for the at least one device by one or more of:

determining the application protocol used by the at least one device;

determining the function of the application protocol for the at least one device;

determining whether the content length of the probing response is within a predetermined range; and,

the content of the probing response.

19. The computer system of claim 15 , wherein the performing the secondary classification includes receiving website content received from the at least one response to the probing the network.

20. A computer usable non-transitory storage medium having a computer program embodied thereon for causing a suitably programmed system to discover and classify a device on a network, by performing the following steps when such program is executed on the system, the steps comprising:

probing the network to obtain at least one network parameter from at least one device along the network;

receiving at least one response to the probing the network, the at least one response including a payload of a content length, the content length defining the at least one network parameter;

performing an initial classification into at least one category of the at least one device, based on the content length of the at least one response from the at least one device; and,

performing a secondary classification on the at least one device in the at least one initial category based on data returned by the at least one device after issuing at least one application protocol specific request to the at least one device.

Assignments (5)
SECURITY INTEREST Recorded Mar 2, 2026
From: CYBERTOKA LTD.
To: BANK LEUMI LE-ISRAEL B.M.
Reel/Frame 073933/0517 →
SECURITY INTEREST Recorded Jan 20, 2023
From: CYBERTOKA LTD.
To: TRIPLEPOINT CAPITAL LLC
Reel/Frame 062443/0168 →
SECURITY INTEREST Recorded Sep 1, 2022
From: CYBERTOKA LTD.
To: SILICON VALLEY BANK
Reel/Frame 060966/0552 →
SECURITY INTEREST Recorded Jun 18, 2020
From: CYBERTOKA LTD
To: SILICON VALLEY BANK
Reel/Frame 052978/0083 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2019
From: BELIKOVETSKY, SOFIA; ZALTSMAN, MOTY
To: CYBERTOKA LTD.
Reel/Frame 049340/0680 →
Cited By (1)
US 12,739,298