IP Library Granted Patent US 12,407,705
Granted Patent B1
US 12,407,705 · App. 17/677,240 · Granted Sep 2, 2025

Prediction of network vulnerability of a user's network-connected smart device using crowdsourced vulnerability profiles

Inventors: Michael D. Melnick (Brighton, NY); David L Knudsen (Saint Helena, CA); Alyssa J. Kersey (Chicago, IL)
Assignee: EVERYTHING SET INC.
H04L63/1433H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,407,705
App. No.
17/677,240
Granted
Sep 2, 2025
Kind
B1
Abstract

Network vulnerability is predicted for a user's network-connected smart device, wherein the user's network-connected smart device has one or more device classifications. A memory stores a plurality of crowdsourced vulnerability profiles generated from individual vulnerability profiles of a plurality of network-connected smart devices, and anomalous behavior associated with each of the respective crowdsourced vulnerability profiles. Each crowdsourced vulnerability profile is generated from individual vulnerability profiles of a plurality of network-connected smart devices having one of the same device classifications, and each of the individual vulnerability profiles are created from network scans for the respective network-connected smart device. A vulnerability profile is generated of the user's network-connected smart device. One or more of the crowdsourced vulnerability profiles in the memory are identified that matches the vulnerability profile of the user's network-connected smart device by matching the one or more device classifications of the user's network-connected smart device with the device classifications of the crowdsourced vulnerability profiles in the memory. In this manner, anomalous behavior that the user's network-connected smart device is at risk of exhibiting is identified, the anomalous behavior being the same anomalous behavior identified by the respective matching one or more crowdsourced vulnerability profiles.

Claims (14)

1. An automated method of predicting network vulnerability of a user's network-connected smart device, wherein the user's network-connected smart device has one or more device classifications, the method comprising:

(a) storing in memory:

(i) a plurality of crowdsourced vulnerability profiles generated from individual vulnerability profiles of a plurality of network-connected smart devices, each crowdsourced vulnerability profile being generated from individual vulnerability profiles of a plurality of network-connected smart devices having one of the same device classifications, each of the individual vulnerability profiles being created from network scans for a respective network-connected smart device, and

(ii) anomalous behavior associated with each of a respective crowdsourced vulnerability profile, wherein a database in the memory stores anomalous behavior for each crowdsourced vulnerability profile in a one-to-one correlation, and wherein the anomalous behavior is separate and distinct from the crowdsourced vulnerability profile;

(b) generating, by a processor, a vulnerability profile of the user's network-connected smart device;

(c) identifying, by the processor, the crowdsourced vulnerability profiles in the memory that match the vulnerability profile of the user's network-connected smart device by matching the one or more device classifications of the user's network-connected smart device with the device classifications of the crowdsourced vulnerability profiles in the memory; and

(d) identifying, using the matched crowdsourced vulnerability profiles and the database that stores anomalous behavior for each crowdsourced vulnerability profile in a one-to-one correlation, a percentage of each anomalous behavior associated with the crowdsourced vulnerability profiles that the user's network-connected smart device is at risk of exhibiting.

2. The method of claim 1 wherein the user's network-connected smart device is associated with application software that executes on a mobile device of the user, the method further comprising:

(e) the processor electronically communicating to the application software executing on the mobile device of the user information regarding the anomalous behavior that the user's network-connected smart device is at risk of exhibiting.

3. The method of claim 1 wherein one of the device classifications is a category type, and wherein the memory stores a plurality of crowdsourced vulnerability profiles generated from individual vulnerability profiles of a plurality of network-connected smart devices having the same category type, and wherein the user's network-connected smart device has a category type, and wherein the processor identifies the crowdsourced vulnerability profiles in the memory that match the vulnerability profile of the user's network-connected smart device by matching the category type of the user's network-connected smart device to the category types of the crowdsourced vulnerability profiles in the memory.

4. The method of claim 1 wherein one of the device classifications is a device type, and wherein the memory stores a plurality of crowdsourced vulnerability profiles generated from individual vulnerability profiles of a plurality of network-connected smart devices having the same device type, and wherein the user's network-connected smart device has a device type, and wherein the processor identifies the crowdsourced vulnerability profiles in the memory that match the vulnerability profile of the user's network-connected smart device by matching the device type of the user's network-connected smart device with the device types of the crowdsourced vulnerability profiles in the memory.

5. The method of claim 1 wherein one of the device classifications is a device make, and wherein the memory stores a plurality of crowdsourced vulnerability profiles generated from individual vulnerability profiles of a plurality of network-connected smart devices having the same device make, and wherein the user's network-connected smart device has a device make, and wherein the processor identifies the crowdsourced vulnerability profiles in the memory that match the vulnerability profile of the user's network-connected smart device by matching the device make of the user's network-connected smart device with the device make of the crowdsourced vulnerability profiles in the memory.

6. The method of claim 1 wherein one of the device classifications is a device model, and wherein the memory stores a plurality of crowdsourced vulnerability profiles generated from individual vulnerability profiles of a plurality of network-connected smart devices having the same device model, and wherein the user's network-connected smart device has a device model, and wherein the processor identifies the crowdsourced vulnerability profiles in the memory that match the vulnerability profile of the user's network-connected smart device by matching the device model of the user's network-connected smart device with the device model of the crowdsourced vulnerability profiles in the memory.

7. The method of claim 1 wherein one of the device classifications is a device operating system (OS), and wherein the memory stores a plurality of crowdsourced vulnerability profiles generated from individual vulnerability profiles of a plurality of network-connected smart devices having the same device OS, and wherein the user's network-connected smart device has a device OS, and wherein the processor identifies the crowdsourced vulnerability profiles in the memory that match the vulnerability profile of the user's network-connected smart device by matching the device OS of the user's network-connected smart device with the device OS of the crowdsourced vulnerability profiles in the memory.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2022
From: MELNICK, MICHAEL D.; KNUDSEN, DAVID L.; KERSEY, ALYSSA J.
To: EVERYTHING SET INC.
Reel/Frame 059076/0447 →
References Cited (41)
US 9349103B2 · Eberhardt, III et al. · 2016 [cited by applicant]
US 9537876B2 · Kelekar · 2017 [cited by applicant]
US 9621517B2 · Martini · 2017 [cited by applicant]
US 9838292B2 · Polychronis · 2017 [cited by applicant]
US 9984365B2 · Desai et al. · 2018 [cited by applicant]
US 10063585B2 · Salajegheh et al. · 2018 [cited by applicant]
US 10142122B1 · Hill et al. · 2018 [cited by applicant]
US 10454950B1 · Aziz · 2019 [cited by examiner]
US 10587633B2 · Muddu et al. · 2020 [cited by applicant]
US 11057409B1 · Bisht et al. · 2021 [cited by applicant]
US 11184386B1 · Schroeder et al. · 2021 [cited by applicant]
US 11658863B1 · Salinas · 2023 [cited by examiner]
US 20090265784A1 · Waizumi et al. · 2009 [cited by applicant]
US 20100285820A1 · Jozwiak et al. · 2010 [cited by applicant]
US 20140181972A1 · Karta et al. · 2014 [cited by applicant]
US 20150033340A1 · Giokas · 2015 [cited by applicant]
US 20150163121A1 · Mahaffey et al. · 2015 [cited by applicant]
US 20160006753A1 · McDaid · 2016 [cited by examiner]
US 20160112374A1 · Branca · 2016 [cited by applicant]
US 20160232358A1 · Grieco · 2016 [cited by examiner]
US 20180139179A1 · Ettema et al. · 2018 [cited by applicant]
US 20190114404A1 · Nowak et al. · 2019 [cited by applicant]
US 20190306182A1 · Fry · 2019 [cited by examiner]
US 20190380037A1 · Lifshitz et al. · 2019 [cited by applicant]
US 20200044927A1 · Apostolopoulos et al. · 2020 [cited by applicant]
US 20200366689A1 · Lotia et al. · 2020 [cited by applicant]
US 20200396211A1 · Dobbins et al. · 2020 [cited by applicant]
US 20210006583A1 · Ryabenkiy · 2021 [cited by examiner]
US 20210306341A1 · Tiwari et al. · 2021 [cited by applicant]
US 20230188540A1 · Valluri · 2023 [cited by examiner]
Bayesian Hierarchical Models in Ecology, Chapter 4 Bayesian Machinery, downloaded from:<https://bookdown.org/steve_midway/BHME/Ch3.html>, download date: Jan. 31, 2022, initial posting date: unknown, 12 pages. [cited by applicant]
D.4. dumpcap: Capturing with “dumpcap” for viewing with Wireshark, Appendix D. Related command line tools, downloaded from webpage: <https://www.wireshark.org/docs/wsug_html_chunked/AppToolsdumpcap.html>, download date:… [cited by applicant]
Fing DeveRecog API—Fing Device Recognition Cloud API, Fing Limited, Nov. 4, 2019, 10 pages. [cited by applicant]
Sivanathan et al. “Can We Classify an IoT Device using TCP Port Scan?” downloaded from: <https://www2.ee.unsw.edu.au/˜hhabibi/pubs/conf/18iciafs-1.pdf> 2018 IEEE International Conference on Information and Automation fo… [cited by applicant]
Tshark(1) Manual Page, downloaded from: <https://www.wireshark.org/docs/man-pages/tshark.html>, download date: Feb. 1, 2022, initial posting date: unknown, 37 pages. [cited by applicant]
WAGO 852 Industrial Managed Switch Series Code Execution/Hardcoded Credentials, downloaded from web page: <https://vulners.com/packetstorm/PACKETSTORM:153278> download date: Feb. 3, 2022, initial posting date: unknown, … [cited by applicant]
Wikipedia entry for “Man-in-the-middle attack.” page last edited on Sep. 5, 2021, 7 pages. [cited by applicant]
Wikipedia entry for “Prior Probability,” page last edited on Mar. 13, 2021, 8 pages. [cited by applicant]
Li et al., “Crowdsourcing based large-scale network anomaly detection,” IEEE, pp. 1-6 (2018). [cited by applicant]
Sanchez et al., “A Survey on Device Behavior Fingerprinting: Data Sources, Techniques, Application Scenarios, adn Datasets,” IEEE Communications Surveys & Tutorials, vol. 23, No. 2, pp. 1048-1077 (2021). [cited by applicant]
Notice of Allowance issued Apr. 15, 2024 in U.S. Appl. No. 17/677,235. [cited by applicant]