IP Library › Granted Patent US 11,496,394
Granted Patent B2
US 11,496,394 · App. 17/139,398 · Granted Nov 8, 2022

Internet of things (IoT) device identification on corporate networks via adaptive feature set to balance computational complexity and model bias

Inventors: Sameer T. Khanna (Cupertino, CA); Xiaoguang Liu (San Ramon, CA); Jianwen Zhang (Saratoga, CA)
Assignee: Fortinet, Inc.
H04L45/74H04L69/16H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,496,394
App. No.
17/139,398
Granted
Nov 8, 2022
Kind
B2
Abstract

Systems and methods for efficient kernel space packet processing and IoT device classification are provided. According to one embodiment, a computer system performs IoT device detection processing. Packet header information is received for multiple packets. Based on the packet header information, multiple Transmission Control Protocol (TCP) or User Datagram Protocol (UDP) flows between a given source device of multiple devices and a given destination device of the multiple devices are identified. For each TCP or UDP flow: a variable-length feature set is created having a size limited by a predetermined or configurable aggregate number of packets sent and received for the TCP or UDP flow; and it is inferred whether the TCP or UDP flow represents an IoT device communication or a non-IoT device communication by applying a machine-learning model to the variable length feature set. The devices are then each classified as either an IoT device or a non-IoT device by aggregating one or more results of the inference processing for each device of the multiple devices with a voting classifier.

Claims (59)

1. A method performed by a processing resource of a computer system, the method comprising:

receiving, by the processing resource, packet header information corresponding to a plurality of packets;

identifying, by the processing resource, based on the packet header information, a plurality of Transmission Control Protocol (TCP) or User Datagram Protocol (UDP) flows between a given source device of a plurality of devices and a given destination device of the plurality of devices;

for each TCP or UDP flow of the plurality of TCP or UDP flows:

creating, by the processing resource, a variable-length feature set having a size limited by a predetermined or configurable aggregate number of packets sent and received for the TCP or UDP flow, wherein the variable-length feature set has a number of features determined by N, the number of packets from a given source to be evaluated for a given bidirectional flow, for a total of 2N packets evaluated per flow; and

inferring, by the processing resource, whether the TCP or UDP flow represents an IoT device communication or a non-IoT device communication by applying a machine-learning model to the variable length feature set; and

classifying, by the processing resource, the plurality of devices as either an IoT device or a non-IoT device by aggregating one or more results of said inferring for each device of the plurality of devices with a voting classifier.

2. The method of claim 1 , further comprising organizing the packet header information based upon their respective TCP or UDP bidirectional flows based on any or combination of Media Access Control (MAC) addresses contained within the packet header information, TCP or UDP ports contained within the packet header information, and Internet Protocol (IP) addresses contained within the packet header information.

3. The method of claim 1 , wherein the variable-length feature set comprises:

information regarding the TCP flow;

the size;

a Time-To-Live (TTL) value from with the packet header information; and

an Inter-Arrival-Time (IAT) derived from the packet header information.

4. A computer system comprising:

a processing resource;

a non-transitory computer-readable medium, coupled to the processing resource, having stored therein instructions that when executed by the processing resource cause the processing resource to:

receive packet header information corresponding to a plurality of packets;

identify based on the packet header information, a plurality of Transmission Control Protocol (TCP) or User Datagram Protocol (UDP) flows between a given source device of a plurality of devices and a given destination device of the plurality of devices;

for each TCP or UDP flow of the plurality of TCP or UDP flows:

create a variable-length feature set having a size limited by a predetermined or configurable aggregate number of packets sent and received for the TCP or UDP flow, wherein the variable-length feature set includes: information regarding the TCP flow; the size; a Time-To-Live (TTL) value from with the packet header information; and an Inter-Arrival-Time (IAT) derived from the packet header information; and

infer whether the TCP or UDP flow represents an IoT device communication or a non-IoT device communication by applying a machine-learning model to the variable length feature set; and

classify the plurality of devices as either an IoT device or a non-IoT device by aggregating one or more results of said inferring for each device of the plurality of devices with a voting classifier.

5. The computer system of claim 4 , wherein the instructions further cause the processing resource to organize the packet header information based upon their respective TCP or UDP bidirectional flows based on any or combination of Media Access Control (MAC) addresses contained within the packet header information, TCP or UDP ports contained within the packet header information, and Internet Protocol (IP) addresses contained within the packet header information.

6. The computer system of claim 4 , wherein the variable-length feature set has a number of features determined by N, the number of packets from a given source to be evaluated for a given bidirectional flow, for a total of 2N packets evaluated per flow.

7. A non-transitory computer-readable storage medium embodying a set of instructions, which when executed by one or more processing resources of a computer system, causes the one or more processing resources to perform a method comprising:

receiving packet header information corresponding to a plurality of packets;

identifying based on the packet header information, a plurality of Transmission Control Protocol (TCP) or User Datagram Protocol (UDP) flows between a given source device of a plurality of devices and a given destination device of the plurality of devices;

for each TCP or UDP flow of the plurality of TCP or UDP flows:

creating a variable-length feature set having a size limited by a predetermined or configurable aggregate number of packets sent and received for the TCP or UDP flow, wherein the variable length feature set includes: information regarding the TCP flow; the size; a Time-To-Live (TTL) value from with the packet header information; and an Inter-Arrival-Time (IAT) derived from the packet header information; and

inferring whether the TCP or UDP flow represents an IoT device communication or a non-IoT device communication by applying a machine-learning model to the variable length feature set; and

classifying the plurality of devices as either an IoT device or a non-IoT device by aggregating one or more results of said inferring for each device of the plurality of devices with a voting classifier.

8. The computer system of claim 7 , wherein the instructions further cause the processing resource to organize the packet header information based upon their respective TCP or UDP bidirectional flows based on any or combination of Media Access Control (MAC) addresses contained within the packet header information, TCP or UDP ports contained within the packet header information, and Internet Protocol (IP) addresses contained within the packet header information.

9. The computer system of claim 7 , where the variable-length feature set has a number of features determined by N, the number of packets from a given source to be evaluated for a given bidirectional flow, for a total of 2N packets evaluated per flow.

10. A method performed by a processing resource of a computer system, the method comprising:

receiving, by the processing resource, packet header information corresponding to a plurality of packets;

identifying, by the processing resource, based on the packet header information, a plurality of Transmission Control Protocol (TCP) or User Datagram Protocol (UDP) flows between a given source device of a plurality of devices and a given destination device of the plurality of devices;

for each TCP or UDP flow of the plurality of TCP or UDP flows:

creating, by the processing resource, a variable-length feature set having a size limited by a predetermined or configurable aggregate number of packets sent and received for the TCP or UDP flow; wherein the variable length feature set includes: information regarding the TCP flow; the size; a Time-To-Live (TTL) value from with the packet header information; and an Inter-Arrival-Time (IAT) derived from the packet header information; and

inferring, by the processing resource, whether the TCP or UDP flow represents an IoT device communication or a non-IoT device communication by applying a machine-learning model to the variable length feature set; and

classifying, by the processing resource, the plurality of devices as either an IoT device or a non-IoT device by aggregating one or more results of said inferring for each device of the plurality of devices with a voting classifier.

11. The method of claim 10 , further comprising organizing the packet header information based upon their respective TCP or UDP bidirectional flows based on any or combination of Media Access Control (MAC) addresses contained within the packet header information, TCP or UDP ports contained within the packet header information, and Internet Protocol (IP) addresses contained within the packet header information.

12. A computer system comprising:

a processing resource;

a non-transitory computer-readable medium, coupled to the processing resource, having stored therein instructions that when executed by the processing resource cause the processing resource to:

receive packet header information corresponding to a plurality of packets;

identify based on the packet header information, a plurality of Transmission Control Protocol (TCP) or User Datagram Protocol (UDP) flows between a given source device of a plurality of devices and a given destination device of the plurality of devices;

for each TCP or UDP flow of the plurality of TCP or UDP flows:

create a variable-length feature set having a size limited by a predetermined or configurable aggregate number of packets sent and received for the TCP or UDP flow, wherein where the variable-length feature set has a number of features determined by N, the number of packets from a given source to be evaluated for a given bidirectional flow, for a total of 2N packets evaluated per flow; and

infer whether the TCP or UDP flow represents an IoT device communication or a non-IoT device communication by applying a machine-learning model to the variable length feature set; and

classify the plurality of devices as either an IoT device or a non-IoT device by aggregating one or more results of said inferring for each device of the plurality of devices with a voting classifier.

13. The computer system of claim 12 , wherein the instructions further cause the processing resource to organize the packet header information based upon their respective TCP or UDP bidirectional flows based on any or combination of Media Access Control (MAC) addresses contained within the packet header information, TCP or UDP ports contained within the packet header information, and Internet Protocol (IP) addresses contained within the packet header information.

14. A non-transitory computer-readable storage medium embodying a set of instructions, which when executed by one or more processing resources of a computer system, causes the one or more processing resources to perform a method comprising:

receiving packet header information corresponding to a plurality of packets;

identifying based on the packet header information, a plurality of Transmission Control Protocol (TCP) or User Datagram Protocol (UDP) flows between a given source device of a plurality of devices and a given destination device of the plurality of devices;

for each TCP or UDP flow of the plurality of TCP or UDP flows:

creating a variable-length feature set having a size limited by a predetermined or configurable aggregate number of packets sent and received for the TCP or UDP flow, wherein the variable-length feature set has a number of features determined by N, the number of packets from a given source to be evaluated for a given bidirectional flow, for a total of 2N packets evaluated per flow; and

inferring whether the TCP or UDP flow represents an IoT device communication or a non-IoT device communication by applying a machine-learning model to the variable length feature set; and

classifying the plurality of devices as either an IoT device or a non-IoT device by aggregating one or more results of said inferring for each device of the plurality of devices with a voting classifier.

15. The computer system of claim 14 , wherein the instructions further cause the processing resource to organize the packet header information based upon their respective TCP or UDP bidirectional flows based on any or combination of Media Access Control (MAC) addresses contained within the packet header information, TCP or UDP ports contained within the packet header information, and Internet Protocol (IP) addresses contained within the packet header information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 31, 2020
From: KHANNA, SAMEER T.; ZHANG, JIANWEN; LIU, XIAOGUANG
To: FORTINET, INC.
Reel/Frame 054786/0532 →
Continuity (1)
Related Publication 20220210066A1 · Jun 30, 2022