IP Library Granted Patent US 12,216,459
Granted Patent B2
US 12,216,459 · App. 17/523,362 · Granted Feb 4, 2025

System and method for inferring device type based on port usage

Inventors: Yuval Friedlander (Petah-Tiqwa, IL); Gil Ben Zvi (Hod Hasharon, IL); Tom Hanetz (Tel Aviv, IL); Ron Shoham (Tel Aviv, IL)
Assignee: Armis Security Ltd.
G05B19/41885G06F18/214G06N5/04H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,216,459
App. No.
17/523,362
Granted
Feb 4, 2025
Kind
B2
Abstract

A system and method for inferring device types. A method includes selecting a device type inference model from among a plurality of device type inference models based on a manufacturer of a device, wherein each device type inference model corresponds to a respective manufacturer and is trained using training data of devices manufactured by the respective manufacturer, wherein each device type inference model is trained to output a device type prediction; and determining an inferred device type for the device, wherein determining the inferred device type for the device further comprises applying the selected device type inference model to a plurality of features, wherein the plurality of features is extracted from device activity data indicating ports used by the device and at least one volume of traffic communicated via each port used by the device.

Claims (43)

1. A method for inferring device types, comprising:

selecting a manufacturer-specific device type inference model from among a plurality of device type inference models based on a manufacturer of a device, wherein each device type inference model corresponds to a respective manufacturer and is trained using training data of devices manufactured by the respective manufacturer, wherein each device type inference model is trained to output a device type prediction;

determining, from device activity data of the device, a port usage distribution indicating traffic volumes for each port used by the device, wherein the device activity data indicates ports used by the device and at least one volume of traffic communicated via each port used by the device;

extracting a plurality of features from device activity data of the device and the port usage distribution; and

determining an inferred device type for the device, wherein determining the inferred device type for the device further comprises applying the selected manufacturer-specific device type inference model to the extracted plurality of features.

2. The method of claim 1 , wherein determining the distribution of port usage further comprises:

applying a distribution dissimilarity model to the port usage distributions, wherein the distribution dissimilarity model outputs a plurality of distances, wherein each distance is based on a difference between a distribution of values for each port indicated in the port usage distribution and a distribution of values for each corresponding port of each of a plurality of device types capable of being output by the selected manufacturer-specific device type inference model, wherein the extracted plurality of features includes the plurality of distances.

3. The method of claim 1 , further comprising:

adding the inferred device type for the device to a device profile of the device.

4. The method of claim 1 , further comprising:

normalizing a plurality of manufacturer values among the device activity data, wherein the manufacturer of the device is determined based on the normalized plurality of manufacturer values.

5. The method of claim 1 , further comprising:

determining a manufacturer of the device based on the device activity data, wherein the respective manufacturer for each of the plurality of device type inference models is the determined manufacturer.

6. The method of claim 1 , further comprising:

monitoring behavior of the device with respect to the inferred device type in order to detect at least one abnormal behavior of the device.

7. The method of claim 6 , wherein the abnormal behavior is a deviation from a predetermined normal behavior associated with the inferred device type.

8. The method of claim 6 , further comprising:

performing at least one mitigation action based on the detected at least one anomaly in behavior of the device.

9. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

selecting a manufacturer-specific device type inference model from among a plurality of device type inference models based on a manufacturer of a device, wherein each device type inference model corresponds to a respective manufacturer and is trained using training data of devices manufactured by the respective manufacturer, wherein each device type inference model is trained to output a device type prediction;

determining, from device activity data of the device, a port usage distribution indicating traffic volumes for each port used by the device, wherein the device activity data indicates ports used by the device and at least one volume of traffic communicated via each port used by the device;

extracting a plurality of features from device activity data of the device and the port usage distribution; and

determining an inferred device type for the device, wherein determining the inferred device type for the device further comprises applying the selected manufacturer-specific device type inference model to the extracted plurality of features.

10. A system for inferring device types, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

select a manufacturer-specific device type inference model from among a plurality of device type inference models based on a manufacturer of a device, wherein each device type inference model corresponds to a respective manufacturer and is trained using training data of devices manufactured by the respective manufacturer, wherein each device type inference model is trained to output a device type prediction;

determine, from device activity data of the device, a port usage distribution indicating traffic volumes for each port used by the device, wherein the device activity data indicates ports used by the device and at least one volume of traffic communicated via each port used by the device;

extract a plurality of features from device activity data of the device and the port usage distribution; and

determine an inferred device type for the device, wherein determining the inferred device type for the device further comprises applying the selected manufacturer-specific device type inference model to the extracted plurality of features.

11. The system of claim 10 , wherein the system is further configured to:

apply a distribution dissimilarity model to the port usage distributions, wherein the distribution dissimilarity model outputs a plurality of distances, wherein each distance is based on a difference between a distribution of values for each port indicated in the port usage distribution and a distribution of values for each corresponding port of each of a plurality of device types capable of being output by the selected manufacturer-specific device type inference model, wherein the extracted plurality of features includes the plurality of distances.

12. The system of claim 10 , wherein the system is further configured to:

add the inferred device type for the device to a device profile of the device.

13. The system of claim 10 , wherein the system is further configured to:

normalize a plurality of manufacturer values among the device activity data, wherein the manufacturer of the device is determined based on the normalized plurality of manufacturer values.

14. The system of claim 10 , wherein the system is further configured to:

determine a manufacturer of the device based on the device activity data, wherein the respective manufacturer for each of the plurality of device type inference models is the determined manufacturer.

15. The system of claim 10 , wherein the system is further configured to:

monitor behavior of the device with respect to the inferred device type in order to detect at least one abnormal behavior of the device.

16. The system of claim 15 , wherein the abnormal behavior is a deviation from a predetermined normal behavior associated with the inferred device type.

17. The system of claim 15 , wherein the system is further configured to:

perform at least one mitigation action based on the detected at least one anomaly in behavior of the device.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Apr 21, 2026
From: HERCULES CAPITAL, INC.
To: ARMIS SECURITY LTD; ARMIS INC.
Reel/Frame 075477/0965 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 5, 2024
From: ARMIS SECURITY LTD.
To: HERCULES CAPITAL, INC., AS ADMINISTRATIVE AND COLLATERAL AGENT
Reel/Frame 066740/0499 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2021
From: FRIEDLANDER, YUVAL; BEN ZVI, GIL; HANETZ, TOM; SHOHAM, RON
To: ARMIS SECURITY LTD.
Reel/Frame 058074/0333 →
Continuity (1)
Related Publication 20230143024A1 · May 11, 2023
References Cited (11)
US 8732732B2 · Meijer et al. · 2014 [cited by applicant]
US 10320619B2 · Seddigh et al. · 2019 [cited by applicant]
US 10419931B1 · Sohail · 2019 [cited by examiner]
US 20180124096A1 · Schwartz · 2018 [cited by examiner]
US 20180270229A1 · Zhang · 2018 [cited by examiner]
US 20210329029A1 · Vasseur · 2021 [cited by examiner]
CN 107667505B · 2020 [cited by applicant]
WO WO2020136635 · 2020 [cited by applicant]
Noguchi, Hirofumi, Misao Kataoka, and Yoji Yamato. “Device identification based on communication analysis for the internet of things.” IEEE Access 7 (2019): 52903-52912. (Year: 2019). [cited by examiner]
Creager, “How can anomalous IoT device activity be detected?,” Jul. 17, 2018, retrieved from https://www.techtarget.com/iotagenda/blog/IoT-Agenda/How-can-anomalous-IoT- device-activity-be-detected, 3 pages. [cited by applicant]
International Search Report and Written Opinion from PCT/IB2022/060648, dated Jan. 18, 2023, 7 pages. [cited by applicant]
Cited By (4)
US 12,470,593 US 12,572,846 US 12,574,399 US 12,695,752