System and method for monitoring the security configurations of connected devices
View Patent ↗A system and method for monitoring and modifying the security configurations of multiple devices is disclosed. The method includes monitoring multiple devices for security triggers and taking action in response to the triggers. The triggers include changes in security configurations, known security issues and pending updates. The devices may be any connected devices, including Internet of Things devices.
1 . A method of modifying security configurations of one or more devices, comprising:
building a database comprising a list of monitored devices and associated security configurations of the monitored devices based on fencing parameters;
detecting that a first security configuration for a first monitored device in the list of monitored devices has been automatically updated;
retrieving a second security configuration for a second monitored device in the list of monitored devices, wherein the second monitored device can communicate with the first monitored device;
determining if there is a conflict between the first security configuration and the second security configuration; and
modifying the first security configuration or the second security configuration when there is a conflict between the first security configuration and the second security configuration.
2 . The method of claim 1 , wherein modifying the first security configuration or the second security configuration comprises modifying the first security configuration or the second security configuration to remove the conflict.
3 . The method of claim 1 , wherein modifying the first security configuration or the second security configuration comprises modifying the first security configuration or the second security configuration to disable one or more functions.
4 . The method of claim 1 , wherein the method includes restoring a previous security configuration for the first monitored device.
5 . The method of claim 1 , wherein modifying the first security configuration or the second security configuration comprises updating the second security configuration to a new configuration that is not in conflict with the first security configuration.
6 . The method of claim 1 , wherein the first device and the second monitored device are on different networks.
7 . The method of claim 1 , wherein detecting that the first security configuration has been automatically updated further comprises detecting that the first security configuration has been updated by a manufacturer of the first monitored device.
8 . The method of claim 1 , wherein the first monitored device and the second monitored device are substantially different.
9 . The method of claim 1 , wherein the first monitored device runs a first operating system, the second monitored device runs a second operating system, and the first operating system and the second operating system are substantially different.
10 . A method of modifying security configurations of one or more devices, comprising:
building a database comprising a list of monitored devices and associated security configurations of the monitored devices based on fencing parameters;
detecting that a first security configuration for a first monitored device from the list of monitored devices has been automatically updated;
retrieving security configurations for other monitored devices from the list or monitored devices, wherein the other monitored devices can communicate with the first monitored device;
determining whether the first security configuration conflicts with any of the retrieved security configurations; and
modifying the first security configuration or the retrieved security configurations for the other monitored devices having conflicting security configurations.
11 . The method of claim 10 , wherein modifying the first security configuration or the retrieved security configurations for the other monitored devices comprises modifying the first security configuration or the retrieved security configurations for the other monitored devices to remove the conflicting security configurations.
12 . The method of claim 10 , wherein modifying the first security configuration or the retrieved security configurations for the other monitored devices comprises modifying the first security configuration or the retrieved security configurations for the other monitored devices to disable one or more functions.
13 . The method of claim 10 , wherein the method further comprises building a list of the other monitored devices with conflicting security configurations.
14 . The method of claim 10 , wherein the method includes restoring a previous security configuration for the first monitored device.
15 . The method of claim 10 , wherein modifying the first security configuration or the retrieved security configurations comprises updating the retrieved security configurations to new configurations that are not in conflict with the first security configuration.
16 . The method of claim 10 , wherein the first monitored device and the other monitored devices are on different networks.
17 . The method of claim 10 , wherein detecting that the first security configuration has been automatically updated further comprises detecting that the first security configuration has been updated by a manufacturer of the first monitored device.
18 . The method of claim 10 , wherein the first monitored device and the other monitored devices are substantially different.
19 . A system for modifying security configurations of one or more devices, the system comprising:
a plurality of devices; and
a hub device connected to each one of the devices, the hub device comprising:
a security management module comprising a security monitoring application running on a computing device, the security management module building a database comprising a plurality of monitored devices and associated security configurations of the plurality of monitored devices from the plurality of devices based on fencing parameters, each monitored device of the plurality of monitored devices comprising a security configuration interface to allow a security configuration of each monitored device to be changed, and the security management module in communication with the security configuration interface of each monitored device; and
a security configuration files database in communication with the security management module;
wherein the security management module detects that a first security configuration for a first monitored device in the plurality of monitored devices has been automatically updated, retrieves a second security configuration for a second monitored device in the plurality of monitored devices, wherein the second monitored device can communicate with the first monitored device, determines if there is a conflict between the first security configuration and the second security configuration, and modifies the first security configuration or the second security configuration when there is a conflict between the first security configuration and the second security configuration.
20 . The system of claim 19 , wherein to modifying the first security configuration or the second security configuration the security management module modifies the first security configuration or the second security configuration to remove the conflict or to disable one or more functions.