IP Library › Granted Patent US 12,418,554
Granted Patent B1
US 12,418,554 · App. 18/604,768 · Granted Sep 16, 2025

Device population anomaly detection

Inventors: Rajesh Kumar Saxena (Thane West, IN); Harish Bharti (Pune, IN); Ankit Singhal (Meerut, IN); Sandeep Sukhija (Sri Ganganagar, IN)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L63/1425H04L41/145H04L63/0823H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,418,554
App. No.
18/604,768
Filed
Mar 14, 2024
Granted
Sep 16, 2025
Kind
B1
Art Unit
2451
USPC
709/224
Abstract

An embodiment establishes a network model based at least in part on network data received from a network, wherein the network data comprises device data and certificate data. The embodiment samples the network to receive a network data sample. The embodiment compares the network data sample to the network model to determine whether an anomalous amount of devices is present in the network. The embodiment compares the network data sample to the network model to determine whether an anomalous amount of certificates is present in the network. The embodiment identifies a device population anomaly upon a determination that an anomalous amount of devices and/or an anomalous amount of certificates is present in the network.

Claims (37)

1. A computer-implemented method comprising:

establishing a network model based at least in part on network data received from a network, wherein the network data comprises device data and certificate data;

sampling the network to receive a network data sample;

comparing the network data sample to the network model to determine whether an anomalous amount of devices is present in the network;

upon a determination that an anomalous amount of devices is present in the network, comparing the network data sample to the network model to determine whether an anomalous amount of certificates is present in the network; and

upon a determination that an anomalous amount of certificates is present in the network, identifying a device population anomaly.

2. The computer-implemented method of claim 1 , wherein the method further comprises executing a responsive action upon identification of the device population anomaly.

3. The computer-implemented method of claim 1 , wherein the device data comprises at least one of a number of registered devices, a number of connected devices, a number of idle devices, a number of suspended devices, and a number of deprovisioned devices.

4. The computer-implemented method of claim 1 , wherein the certificate data comprises at least one of a number of validated certificates, a number of revoked certificates, a number of created certificates, and a number of renewed certificates.

5. The computer-implemented method of claim 2 , wherein the responsive action comprises generating and transmitting an alert related to the identification of the device population anomaly.

6. The computer-implemented method of claim 2 , wherein the responsive action comprises identifying a set of suspicious devices connected to the network and removing the set of suspicious devices from the network.

7. The computer-implemented method of claim 2 , wherein the responsive action comprises isolating a segment of the network.

8. A computer program product comprising one or more computer readable storage media, and program instructions collectively stored on the one or more computer readable storage media, the program instructions executable by a processor to cause the processor to perform operations comprising:

establishing a network model based at least in part on network data received from a network, wherein the network data comprises device data and certificate data;

sampling the network to receive a network data sample;

comparing the network data sample to the network model to determine whether an anomalous amount of devices is present in the network;

upon a determination that an anomalous amount of devices is present in the network, comparing the network data sample to the network model to determine whether an anomalous amount of certificates is present in the network; and

upon a determination that an anomalous amount of certificates is present in the network, identifying a device population anomaly.

9. The computer program product of claim 8 , wherein the program instructions are stored in a computer readable storage device in a data processing system, and wherein the program instructions are transferred over the network from a remote data processing system.

10. The computer program product of claim 8 , wherein the program instructions are stored in a computer readable storage device in a server data processing system, and wherein the program instructions are downloaded in response to a request over the network to a remote data processing system for use in a computer readable storage device associated with the remote data processing system, the operations further comprising:

metering a use of the program instructions associated with the request; and

generating an invoice based on the metered use.

11. The computer program product of claim 8 further comprises executing a responsive action upon identification of the device population anomaly.

12. The computer program product of claim 11 , wherein the responsive action comprises generating and transmitting an alert related to the identification of the device population anomaly.

13. The computer program product of claim 11 , wherein the responsive action comprises identifying a set of suspicious devices connected to the network and removing the set of suspicious devices from the network.

14. The computer program product of claim 11 , wherein the responsive action comprises isolating a segment of the network.

15. The computer program product of claim 8 , wherein the certificate data comprises at least one of a number of validated certificates, a number of revoked certificates, a number of created certificates, and a number of renewed certificates.

16. The computer program product of claim 8 , wherein the device data comprises at least one of a number of registered devices, a number of connected devices, a number of idle devices, a number of suspended devices, and a number of deprovisioned devices.

17. A computer system comprising a processor and one or more computer readable storage media, and program instructions collectively stored on the one or more computer readable storage media, the program instructions executable by the processor to cause the processor to perform operations comprising:

establishing a network model based at least in part on network data received from a network, wherein the network data comprises device data and certificate data;

sampling the network to receive a network data sample;

comparing the network data sample to the network model to determine whether an anomalous amount of devices is present in the network;

upon a determination that an anomalous amount of devices is present in the network, comparing the network data sample to the network model to determine whether an anomalous amount of certificates is present in the network; and

upon a determination that an anomalous amount of certificates is present in the network, identifying a device population anomaly.

18. The computer system of claim 17 , further comprises executing a responsive action upon identification of the device population anomaly.

19. The computer system of claim 18 , wherein the responsive action comprises isolating a segment of the network.

20. The computer system of claim 18 , wherein the responsive action comprises identifying a set of suspicious devices connected to the network and removing the set of suspicious devices from the network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2024
From: SAXENA, RAJESH KUMAR; BHARTI, HARISH; SINGHAL, ANKIT; SUKHIJA, SANDEEP
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 066770/0256 →
References Cited (11)
US 10419931B1 · Sohail et al. · 2019 [cited by applicant]
US 11522879B2 · Koral et al. · 2022 [cited by applicant]
US 20140283054A1 · Janjua et al. · 2014 [cited by applicant]
US 20160050200A1 · Yu · 2016 [cited by applicant]
US 20210160262A1 · Bynum · 2021 [cited by examiner]
US 20210312040A1 · Duttachoudhury · 2021 [cited by examiner]
US 20220294715A1 · Agrawal · 2022 [cited by examiner]
US 20230275918A1 · Tse · 2023 [cited by examiner]
Bargaje, Detect anomalies on connected devices using AWS IoT Device Defender, Sep. 14, 2018. [cited by applicant]
Bhatt et al., Attribute-Based Access Control for AWS Internet of Things and Secure Industries of the Future, Jul. 30, 2021. [cited by applicant]
Fellinge, Identify Anomalous Device Behavior Through Logging and Alerting, Nov. 9, 2018. [cited by applicant]
Cited By (1)
US 12,726,509