IP Library Granted Patent US 11,916,949
Granted Patent B2
US 11,916,949 · App. 16/951,904 · Granted Feb 27, 2024

Internet of things and operational technology detection and visualization platform

Inventors: Vincent Urias (Albuquerque, NM); Brian P. Van Leeuwen (Albuquerque, NM); Douglas M. Kayatt, Jr. (Albuquerque, NM)
Assignee: National Technology & Engineering Solutions of Sandia, LLC
H04L63/1433G06F9/547G16Y40/50H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,916,949
App. No.
16/951,904
Granted
Feb 27, 2024
Kind
B2
Abstract

A computer-implemented method of monitoring activity of devices in a network is provided. The method comprises passively collecting data regarding how the devices access the network, and for each device on the network, identifying all other devices on the network with which the device communicates. All communication traffic from the devices to outside the network is identified. A determination is made if there are any required updates and if patches for the devices execute in a fashion defined as safe. A number of risk indicators for privacy risks are determined according to device communication within the network, device communication to outside the network, and update and patch execution. A visualization of any identified risk factors is displayed to a user through a user interface.

Claims (148)

1. A method of monitoring activity of devices in a network, the method comprising:

using a number of processors to perform the steps of:

passively collecting data regarding how the devices access the network;

for each device on the network, identifying all other devices on the network with which the device communicates;

identifying all communication traffic from the devices to outside the network;

determining if there any required updates for the devices;

determining a number of risk indicators for privacy risks according to device communication within the network, device communication to outside the network, and the required updates for the devices; and

displaying a visualization of any identified risk factors to a user through a user interface,

wherein determining the risk indicators comprises:

creating a model of the network;

testing the model for accuracy;

evaluating, with the model, system level security compliance of the network;

simulating, with the model, effects on the network of a number of different device failures; and

simulating, with the model, effects on the network of a number of different configuration changes.

2. The method of claim 1 , wherein collecting data regarding how the devices access the network comprises analyzing at least one of:

uniform resource locator;

media access control address;

custom protocols;

certificates; or

domain queries.

3. The method of claim 1 , wherein determining the risk factors according to device communication within the network and device communication to outside the network comprises evaluating each type of communication according to at least one of:

operational configurations;

organizationally unique identifier data;

network topology data;

network traffic classification;

network mapping data;

asset inventory databases;

employee and personnel databases;

network assessment data;

domain name system data; or

universal resource locator data.

4. The method of claim 3 , wherein the operational configurations comprise:

forward and reverse proxies;

firewalls; and

routers.

5. The method of claim 1 , wherein the user interface is configured to interact with device objects and modify the network.

6. The method of claim 1 , wherein determining the risk indicators comprise detection of duplicate internet protocol addresses and media access control address on the network.

7. The method of claim 1 , wherein determining the risk indicators comprises auditing network device configurations.

8. The method of claim 7 , wherein auditing the network device configurations comprises:

generating error, warning, or note messages to report on misconfiguration; and

providing information about a configuration and operation of the network.

9. The method of claim 1 , wherein passively collecting data regarding how the devices access the network further comprises:

accessing a number of network data sources from a data store; and

providing an application programming interface (API) to gather data from the data source.

10. The method claim 9 , wherein the API is database agnostic and capable of incorporating data from the data source into a display model.

11. The method of claim 9 , wherein the data store comprises one of:

mySQL;

MongoDB; or

Splunk Indexer.

12. A system for monitoring activity of devices in a network, the system comprising:

a storage device configured to store program instructions; and

one or more processors operably connected to the storage device and configured to execute the program instructions to cause the system to:

passively collect data regarding how the devices access the network;

for each device on the network, identify all other devices on the network with which the device communicates;

identify all communication traffic from the devices to outside the network;

determine if there any required updates for the devices;

determine a number of risk indicators for privacy risks according to device communication within the network, device communication to outside the network, and the required updates for the devices; and

display a visualization of any identified risk factors to a user through a user interface,

wherein determining the risk indicators comprises:

creating a model of the network;

testing the model for accuracy;

evaluating, with the model, system level security compliance of the network;

simulating, with the model, effects on the network of a number of different device failures; and

simulating, with the model, effects on the network of a number of different configuration changes.

13. The system of claim 12 , wherein collecting data regarding how the devices access the network comprises analyzing at least one of:

uniform resource locator;

media access control address;

custom protocols;

certificates; or

domain queries.

14. The system of claim 12 , wherein determining the risk factors according to device communication within the network and device communication to outside the network comprises evaluating each type of communication according to at least one of:

operational configurations;

organizationally unique identifier data;

network topology data;

network traffic classification;

network mapping data;

asset inventory databases;

employee and personnel databases;

network assessment data;

domain name system data; or

universal resource locator data.

15. The system of claim 14 , wherein the operational configurations comprise:

forward and reverse proxies;

firewalls; and

routers.

16. The system of claim 12 , wherein the user interface is configured to interact with device objects and modify the network.

17. The system of claim 12 , wherein determining the risk indicators comprise detection of duplicate internet protocol addresses and media access control address on the network.

18. The system of claim 12 , wherein determining the risk indicators comprises auditing network device configurations.

19. The system of claim 18 , wherein auditing the network device configurations comprises:

generating error, warning, or note messages to report on misconfiguration; and

providing information about a configuration and operation of the network.

20. The system of claim 12 , wherein passively collecting data regarding how the devices access the network further comprises:

accessing a number of network data sources from a data store; and

providing an application programming interface (API) to gather data from the data source.

21. The system of claim 20 , wherein the API is database agnostic and capable of incorporating data from the data source into a display model.

22. The system of claim 20 , wherein the data store comprises one of:

mySQL;

MongoDB; or

Splunk Indexer.

23. A computer program product for monitoring activity of devices in a network, the computer program product comprising:

a computer-readable storage medium having program instructions embodied thereon to perform the steps of:

passively collecting data regarding how the devices access the network;

for each device on the network, identifying all other devices on the network with which the device communicates;

identifying all communication traffic from the devices to outside the network;

determining if there any required updates for the devices;

determining a number of risk indicators for privacy risks according to device communication within the network, device communication to outside the network, and the required updates for the devices; and

displaying a visualization of any identified risk factors to a user through a user interface,

wherein determining the risk indicators comprises:

creating a model of the network;

testing the model for accuracy;

evaluating, with the model, system level security compliance of the network;

simulating, with the model, effects on the network of a number of different device failures; and

simulating, with the model, effects on the network of a number of different configuration changes.

24. The computer program product of claim 23 , wherein collecting data regarding how the devices access the network comprises analyzing at least one of:

uniform resource locator;

media access control address;

custom protocols;

certificates; or

domain queries.

25. The computer program product of claim 23 , wherein determining the risk factors according to device communication within the network and device communication to outside the network comprises evaluating each type of communication according to at least one of:

operational configurations;

organizationally unique identifier data;

network topology data;

network traffic classification;

network mapping data;

asset inventory databases;

employee and personnel databases;

network assessment data;

domain name system data; or

universal resource locator data.

26. The computer program product of claim 25 , wherein the operational configurations comprise:

forward and reverse proxies;

firewalls; and

routers.

27. The computer program product of claim 23 , wherein the user interface is configured to interact with device objects and modify the network.

28. The computer program product of claim 23 , wherein determining the risk indicators comprise detection of duplicate internet protocol addresses and media access control address on the network.

29. The computer program product of claim 23 , wherein determining the risk indicators comprises auditing network device configurations.

30. The computer program product of claim 29 , wherein auditing the network device configurations comprises:

generating error, warning, or note messages to report on misconfiguration; and

providing information about a configuration and operation of the network.

31. The computer program product of claim 23 , wherein passively collecting data regarding how the devices access the network further comprises:

accessing a number of network data sources from a data store; and

providing an application programming interface (API) to gather data from the data source.

32. The computer program product of claim 31 , wherein the API is database agnostic and capable of incorporating data from the data source into a display model.

33. The computer program product of claim 31 , wherein the data store comprises one of:

mySQL;

MongoDB; or

Splunk Indexer.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2021
From: URIAS, VINCENT; VAN LEEUWEN, BRIAN P.; KAYATT, DOUGLAS M., JR
To: NATIONAL TECHNOLOGY & ENGINEERING SOLUTIONS OF SANDIA, LLC
Reel/Frame 055195/0842 →
CONFIRMATORY LICENSE Recorded Feb 2, 2021
From: NATIONAL TECHNOLOGY & ENGINEERING SOLUTIONS OF SANDIA, LLC
To: U.S. DEPARTMENT OF ENERGY
Reel/Frame 055108/0357 →
Continuity (2)
Provisional Application 62937494 · Nov 19, 2019
Related Publication 20210152590A1 · May 20, 2021