IP Library Patent Application 16942648
Patent Application
App. No. 16/942,648

AUTOMATIC INTEGRATION OF IOT DEVICES INTO A NETWORK

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/942,648
Abstract

Some embodiments provide a novel method that performs an automated process that identifies features of an IoT device connected to a network, and based on the identified features specifies, without an administrator input, one or more network policies (e.g., security policies) to apply to packets sent or received by the IoT device. The method of some embodiments also performs automated processes that (1) analyze packet flows to and from the IoT devices to identify dynamic network behavior of these devices, and then (2) specify network policies based on the identified dynamic network behavior.

Claims (34)

1 . A method for enforcing network policies in a network comprising a plurality of IoT (Internet of Things) devices, the method comprising:

collecting network statistics for a set of IoT devices in the plurality of IoT devices;

analyzing the collected network statistics to identify anomalous behavior exhibited by any IoT devices in the set of IoT devices;

determining that a particular IoT device in the plurality of IoT devices has exhibited anomalous behavior; and

identifying one or more network policies to apply to the particular IoT device to remediate the anomalous behavior.

2 . The method of claim 1 , wherein the collected network statistics comprises data tuples relating to data packets sent or received by the IoT devices.

3 . The method of claim 2 , wherein the set of IoT devices comprises a set of IoT devices of a particular classification, wherein analyzing the collected data tuples comprises analyzing a subset of features in the collected data tuples determined to be relevant to IoT devices of the particular classification.

4 . The method of claim 3 , wherein the subset of features is determined to be relevant to the IoT devices of the particular classification by a learning engine that identifies discriminating feature sets of different classifications of IoT devices.

5 . The method of claim 3 , wherein analyzing the subset of features comprises comparing the subset of features of each IoT device in the set of IoT devices to other IoT devices in the set of IoT devices to identify outlying behavior exhibited by any of the IoT devices.

6 . The method of claim 5 , wherein for each IoT device for which outlying behavior is identified, the method further comprises comparing the identified outlying behavior of the IoT device to past behavior of the IoT device in order to determine whether the identified outlying behavior is anomalous for the IoT device and should be identified to the set of policy engines for risk mitigation.

7 . The method of claim 3 , wherein analyzing the subset of features comprises comparing the data tuples collected for the subset of features of each IoT device in the set of IoT devices with data tuples collected previously for the same IoT device to determine whether the IoT device's current behavior differs from the IoT device's past behavior.

8 . The method of claim 3 , wherein analyzing the subset of features comprises comparing the data tuples collected for the subset of features of each IoT device in the set of IoT devices with data tuples collected from other IoT devices of the particular classification operating in other similar environments.

9 . The method of claim 1 , wherein determining that the particular IoT device has exhibited anomalous behavior further comprises determining that the particular IoT device is misclassified.

10 . The method of claim 9 , wherein determining that the particular IoT device is misclassified further comprises at least one of:

adjusting a set of features for at least one classification rule based on the detected misclassification;

adding a new classification rule to ensure proper classification of the IoT device and other similar IoT devices.

11 . The method of claim 10 , wherein providing the set of features relevant to the particular IoT device to the device classification system further comprises modifying a classification process used by the device classification system in order to prevent future misclassifications.

12 . The method of claim 1 , wherein identifying one or more network policies to apply comprises directing one or more services in the network to enforce the identified network policies.

13 . The method of claim 12 , wherein at least one service is a firewall service.

14 . The method of claim 12 , wherein at least one service is a network access control service.

15 . A non-transitory machine readable medium storing a program for execution by a set of processing units, the program for enforcing network policies in a network comprising a plurality of IoT (Internet of Things) devices, the program comprising sets of instructions for:

collecting network statistics for a set of IoT devices in the plurality of IoT devices;

analyzing the collected network statistics to identify anomalous behavior exhibited by any IoT devices in the set of IoT devices;

determining that a particular IoT device in the plurality of IoT devices has exhibited anomalous behavior; and

identifying one or more network policies to apply to the particular IoT device to remediate the anomalous behavior.

16 . The non-transitory machine readable medium of claim 15 , wherein the collected network statistics comprises data tuples relating to data packets sent or received by the IoT devices.

17 . The non-transitory machine readable medium of claim 16 , wherein the set of IoT devices comprises a set of IoT devices of a particular classification, wherein the set of instructions for analyzing the collected data tuples further comprises a set of instructions for analyzing a subset of features in the collected data tuples determined to be relevant to IoT devices of the particular classification.

18 . The non-transitory machine readable medium of claim 17 , wherein the subset of features is determined to be relevant to the IoT devices of the particular classification by a learning engine that identifies discriminating feature sets of different classifications of IoT devices.

19 . The non-transitory machine readable medium of claim 17 , wherein the set of instructions for analyzing the subset of features further comprises a set of instructions for comparing the subset of features of each IoT device in the set of IoT devices to other IoT devices in the set of IoT devices to identify outlying behavior exhibited by any of the IoT devices.

20 . The non-transitory machine readable medium of claim 19 , wherein for each IoT device for which outlying behavior is identified, the program further comprises a set of instructions for comparing the identified outlying behavior of the IoT device to past behavior of the IoT device in order to determine whether the identified outlying behavior is anomalous for the IoT device and should be identified to the set of policy engines for risk mitigation.

21 . The non-transitory machine readable medium of claim 17 , wherein the set of instructions for analyzing the subset of features further comprises a set of instructions for comparing the data tuples collected for the subset of features of each IoT device in the set of IoT devices with data tuples collected previously for the same IoT device to determine whether the IoT device's current behavior differs from the IoT device's past behavior.

22 . The non-transitory machine readable medium of claim 15 , wherein the set of instructions for determining that the particular IoT device has exhibited anomalous behavior further comprises a set of instructions for determining that the particular IoT device is misclassified.

23 . The non-transitory machine readable medium of claim 15 , wherein the set of instructions for identifying one or more network policies to apply further comprises a set of instructions for directing one or more services in the network to enforce the identified network policies.

24 . The non-transitory machine readable medium of claim 23 , wherein at least one service is a firewall service.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2025
From: VMWARE, LLC
To: VELOCLOUD NETWORKS, LLC
Reel/Frame 072326/0693 →
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2020
From: SRINIVAS, ANAND; ZAFER, MURTAZA; VIJAYAKUMAR, GOUTHAM; WAN, CHEOK
To: VMWARE, INC.
Reel/Frame 053347/0590 →