IP Library Granted Patent US 10,380,348
Granted Patent B2
US 10,380,348 · App. 15/357,989 · Granted Aug 13, 2019

IoT device risk assessment

Inventors: Gong Cheng (Sunnyvale, CA); Mayuresh Ektare (Cupertino, CA); Mei Wang (Saratoga, CA)
Assignee: ZingBox, Inc.
G06F21/577H04L63/0227H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,380,348
App. No.
15/357,989
Granted
Aug 13, 2019
Kind
B2
Abstract

Techniques for assessing risks of IoT device. A system utilizing such techniques can include a packet analysis based IoT device risk assessment system and an IoT device risk assessment system. A method utilizing such techniques can include extraction of IoT device risk factors from a device profile of an IoT device and application of assessment weights to the IoT device risk factors to assess a risk level of an IoT device.

Claims (56)

1. A method comprising:

analyzing data packets transmitted to and from an IoT device in operation of the IoT device in accessing network services through a network;

profiling the IoT device into an IoT device profile based on analysis of the data packets transmitted to and from the IoT device in operation of the IoT device in accessing the network services;

extracting IoT device risk factors from the IoT device profile;

selecting assessment weights specific to the IoT device risk factors and specific to the IoT device based on characteristics of the network to apply in assessing a risk level of the IoT device;

applying the assessment weights to the IoT device risk factors according to specificity of the assessment weights to the IoT device risk factors to generate a risk score for the IoT device;

assessing the risk level of the IoT device based on the risk score;

preventing the IoT device from accessing the network services through the network based on the risk score.

2. The method of claim 1 , further comprising:

determining whether to present the risk level as part of risk assessment data to a user associated with the IoT device based on the risk level assessed to the IoT device;

presenting the risk level as part of the risk assessment data to the user associated with the IoT device, if it is determined to present the risk level as part of the risk assessment data based on the risk level assessed to the IoT device.

3. The method of claim 1 , wherein the characteristics of the network include characteristics of other IoT devices accessing network services through the network.

4. The method of claim 1 , wherein the characteristics of the network include characteristics of the IoT device.

5. The method of claim 1 , further comprising:

generating one or a combination of an event log, a system log, and an access log in analyzing data packets transmitted to and from the IoT device in the operation of the IoT device in accessing the network services through the network;

using the one or the combination of the event log, the system log, and the access log to profile the IoT device into the IoT device profile.

6. The method of claim 1 , further comprising:

actively probing the IoT device to determine vulnerabilities of the IoT device;

including the determined vulnerabilities of the IoT device in the IoT device profile in profiling the IoT device.

7. The method of claim 1 , wherein the IoT device risk factors extracted from the IoT device profile include one or a combination of risk factors related to applications used by the IoT device in accessing the network services through the network, protocols used by the IoT device in accessing the network services through the network, network activeness of the IoT device in accessing the network services through the network, network communication characteristics of the IoT device in accessing the network services through the network, security characteristics of data traffic associated with the IoT device in accessing the network services through the network, and operational performance deviations of the IoT device in accessing the network services through the network.

8. The method of claim 1 , further comprising:

comparing operation of the IoT device in accessing the network services through the network based on instances of the IoT device included in the IoT device profile to regular IoT device behavior of the IoT device in accessing network services to determine operational performance deviations of the IoT device;

profiling the IoT device into the IoT device profile based on the determined operational performance deviations of the IoT device.

9. The method of claim 1 , further comprising:

determining whether to present the risk level as part of risk assessment data to a user associated with the IoT device based on the risk level assessed to the IoT device and risk levels assessed to other IoT devices associated with the user;

presenting the risk level as part of the risk assessment data to the user associated with the IoT device, if it is determined to present the risk level as part of the risk assessment data based on the risk level assessed to the IoT device.

10. The method of claim 1 , wherein analyzing data packets transmitted to and from the IoT device in operation of the IoT device in accessing the network services through the network includes performing deep packet inspection of the data packets to determine transaction data from payloads of the data packets, the transaction data used in profiling the IoT device into the IoT device profile.

11. A system comprising:

one or more hardware processors; and

memory storing instructions that, when executed by the one or more hardware processors, cause the system to perform:

analyzing data packets transmitted to and from an IoT device in operation of the IoT device in accessing network services through a network;

profiling the IoT device into an IoT device profile based on analysis of the data packets transmitted to and from the IoT device in operation of the IoT device in accessing the network services;

extracting IoT device risk factors from the IoT device profile;

selecting assessment weights specific to the IoT device risk factors and specific to the IoT device based on characteristics of the network to apply in assessing a risk level of the IoT device;

applying the assessment weights to the IoT device risk factors according to specificity of the assessment weights to the IoT device risk factors to generate a risk score for the IoT device;

assessing the risk level of the IoT device based on the risk score;

preventing the IoT device from accessing the network services through the network based on the risk score.

12. The system of claim 11 , wherein the instructions further cause the system to:

determine whether to present the risk level as part of risk assessment data to a user associated with the IoT device based on the risk level assessed to the IoT device;

present the risk level as part of the risk assessment data to the user associated with the IoT device, if it is determined to present the risk level as part of the risk assessment data based on the risk level assessed to the IoT device.

13. The system of claim 11 , wherein the characteristics of the network include characteristics of other IoT devices accessing network services through the network.

14. The system of claim 11 , wherein the characteristics of the network include characteristics of the IoT device.

15. The system of claim 11 , wherein the instructions further cause the system to:

generate one or a combination of an event log, a system log, and an access log in analyzing data packets transmitted to and from the IoT device in the operation of the IoT device in accessing the network services through the network;

use the one or the combination of the event log, the system log, and the access log to profile the IoT device into the IoT device profile.

16. The system of claim 11 , wherein the instructions further cause the system to:

actively probe the IoT device to determine vulnerabilities of the IoT device;

include the determined vulnerabilities of the IoT device in the IoT device profile in profiling the IoT device.

17. The system of claim 11 , wherein the IoT device risk factors extracted from the IoT device profile include one or a combination of risk factors related to applications used by the IoT device in accessing the network services through the network, protocols used by the IoT device in accessing the network services through the network, network activeness of the IoT device in accessing the network services through the network, network communication characteristics of the IoT device in accessing the network services through the network, security characteristics of data traffic associated with the IoT device in accessing the network services through the network, and operational performance deviations of the IoT device in accessing the network services through the network.

18. The system of claim 11 , wherein the instructions further cause the system to:

compare operation of the IoT device in accessing the network services through the network based on instances of the IoT device included in the IoT device profile to regular IoT device behavior of the IoT device in accessing network services to determine operational performance deviations of the IoT device;

profile the IoT device into the IoT device profile based on the determined operational performance deviations of the IoT device.

19. The system of claim 11 , wherein the instructions further cause the system to:

determine whether to present the risk level as part of risk assessment data to a user associated with the IoT device based on the risk level assessed to the IoT device and risk levels assessed to other IoT devices associated with the user;

present the risk level as part of the risk assessment data to the user associated with the IoT device, if it is determined to present the risk level as part of the risk assessment data based on the risk level assessed to the IoT device.

20. The system of claim 11 , wherein the instructions further cause the system to perform deep packet inspection of the data packets to determine transaction data from payloads of the data packets, the transaction data used in profiling the IoT device into the IoT device profile as part of analyzing the data packets, the transaction data used in profiling the IoT device into the IoT device profile.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2019
From: ZINGBOX, INC
To: PALO ALTO NETWORKS, INC.
Reel/Frame 050822/0085 →
CERTIFICATE OF CORPORATE DOMESTICATION Recorded Sep 4, 2019
From: ZINGBOX, LTD.
To: ZINGBOX, INC.
Reel/Frame 050275/0436 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2016
From: CHENG, GONG; EKTARE, MAYURESH; WANG, MEI
To: ZINGBOX, LTD.
Reel/Frame 040487/0715 →
Continuity (1)
Related Publication 20180144139A1 · May 24, 2018
Cited By (5)
US 12,381,896 US 12,470,593 US 12,572,846 US 12,574,399 US 12,695,752