IP Library › Granted Patent US 12,028,316
Granted Patent B2
US 12,028,316 · App. 17/133,177 · Granted Jul 2, 2024

Automating IOT device identification using statistical payload fingerprints

Inventor: Feng Wang (Fremont, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/0227
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,028,316
App. No.
17/133,177
Filed
Dec 23, 2020
Granted
Jul 2, 2024
Kind
B2
Art Unit
2438
USPC
726/13
Abstract

Internet of Things (IoT) device classification is disclosed. A byte frequency pattern associated with network traffic of an IoT device is received. The received pattern is used to determine a classification for the IoT device. The classification is provided to a security appliance. The security appliance is configured to apply a policy to the IoT device based at least in part on the classification.

Claims (32)

1. A system, comprising:

a processor configured to:

receive, from a data appliance, byte frequency information for an application executing on an Internet of Things (IoT) device that has a corresponding flow observed by the data appliance, wherein the data appliance is unable to determine a classification of the application, at least in part because the data appliance lacks a protocol decoder applicable to the flow, and wherein the system also lacks the protocol decoder;

use, by the system, the received byte frequency information for the application to determine the classification for the IoT device, including by comparing at least some of the received byte frequency information against a library of previously determined byte frequency patterns based at least in part on a threshold match; and

provide the classification to the data appliance, wherein the data appliance is configured to apply a policy to the IoT device based at least in part on the received classification; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the byte frequency information comprises a byte flow distribution.

3. The system of claim 1 , wherein the data appliance is configured to monitor the IoT device.

4. The system of claim 1 , wherein the received byte frequency information is determined to be within a threshold of an existing byte frequency profile and in response the processor is configured to classify the IoT device with other devices associated with the profile.

5. The system of claim 1 , wherein the received byte frequency information is determined to be outside a threshold of a plurality of existing byte frequency profiles and in response the processor is configured to generate a new profile.

6. The system of claim 1 , wherein the threshold match is based at least in part on a plurality of features.

7. The system of claim 1 , wherein the classification is determined based at least in part on a model.

8. The system of claim 7 , wherein the model is trained using a set of features that include byte flow distribution information.

9. The system of claim 1 , wherein the byte frequency information is determined based at least in part on a predefined number of packets in the flow.

10. The system of claim 1 , wherein the byte frequency information is determined using a transport layer payload.

11. A method, comprising:

receiving, from a data appliance, and at a system, byte frequency information for an application executing on an Internet of Things (IoT) device that has a corresponding flow observed by the data appliance, wherein the data appliance is unable to determine a classification of the application, at least in part because the data appliance lacks a protocol decoder applicable to the flow, and wherein the system also lacks the protocol decoder;

using, by the system, the received byte frequency information for the application to determine the classification for the IoT device, including by comparing at least some of the received byte frequency information against a library of previously determined byte frequency patterns based at least in part on a threshold match; and

providing the classification to the data appliance, wherein the data appliance is configured to apply a policy to the IoT device based at least in part on the received classification.

12. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving, from a data appliance, and at a system, byte frequency information for an application executing on an Internet of Things (IoT) device that has a corresponding flow observed by the data appliance, wherein the data appliance is unable to determine a classification of the application, at least in part because the data appliance lacks a protocol decoder applicable to the flow, and wherein the system also lacks the protocol decoder;

using, by the system, the received byte frequency information for the application to determine the classification for the IoT device, including by comparing at least some of the received byte frequency information against a library of previously determined byte frequency patterns based at least in part on a threshold match; and

providing the classification to the data appliance, wherein the data appliance is configured to apply a policy to the IoT device based at least in part on the received classification.

13. The method of claim 11 , wherein the byte frequency information comprises a byte flow distribution.

14. The method of claim 11 , wherein the data appliance is configured to monitor the IoT device.

15. The method of claim 11 , wherein the received byte frequency information is determined to be within a threshold of an existing byte frequency profile and in response classifying the IoT device with other devices associated with the profile.

16. The method of claim 11 , wherein the received byte frequency information is determined to be outside a threshold of a plurality of existing byte frequency profiles and in response generating a new profile.

17. The method of claim 11 , wherein the threshold match is based at least in part on a plurality of features.

18. The method of claim 11 , wherein the classification is determined based at least in part on a model.

19. The method of claim 18 , wherein the model is trained using a set of features that include byte flow distribution information.

20. The method of claim 11 , wherein the byte frequency information is determined based at least in part on a predefined number of packets in the flow.

21. The method of claim 11 , wherein the byte frequency information is determined using a transport layer payload.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2021
From: WANG, FENG
To: PALO ALTO NETWORKS, INC.
Reel/Frame 055752/0560 →
Continuity (2)
Provisional Application 63033012 · Jun 1, 2020
Related Publication 20210377215A1 · Dec 2, 2021
Cited By (3)
US 12,463,989 US 12,476,948 US 12,574,734