IP Library Granted Patent US 11,616,793
Granted Patent B2
US 11,616,793 · App. 16/237,946 · Granted Mar 28, 2023

System and method for device context and device security

Inventors: Peter Fry (Peterborough, NH); Jeremy Hitchcock (Manchester, NH); Jonathan T. Rajewski (South Burlington, VT); Alec Rooney (Eliot, ME)
Assignee: Minim Inc.
H04L63/1425H04L41/046H04L63/1416H04L67/12G06F16/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,616,793
App. No.
16/237,946
Filed
Jan 2, 2019
Granted
Mar 28, 2023
Kind
B2
Art Unit
2458
USPC
726/23
Abstract

A system includes local area network (LAN) devices in communication with network devices external to the LAN. An agent in the LAN examines traffic between LAN devices and external devices. The agent executes scans of the LAN devices, generates fingerprint and telemetry data for the LAN devices, and sends the telemetry data and the fingerprint data to a cloud server external to the LAN. The cloud server receives telemetry data and fingerprint data and updates a device attribute database with fingerprints and/or device profiles for the LAN devices to identify anomalous behavior of the LAN devices.

Claims (61)

1. A system for a local area network (LAN) ( 120 ) in communication with a first network ( 180 ), the LAN comprising a LAN router ( 110 ) in communication with a plurality of LAN network devices ( 131 - 136 ), the plurality of LAN network devices in communication with a plurality of external network devices ( 141 , 142 ) in the first network via the LAN router, the system comprising:

a cloud server ( 160 ) in communication with the first network, the cloud server further comprising a device attribute database ( 530 ) and configured to receive telemetry data and fingerprint data and update the device attribute database; and

an agent ( 115 ) in communication with the cloud server and the plurality of network devices and the plurality of external network devices via the LAN router, wherein the agent comprises a processor and a memory configured to store non-transitory instructions which, when executed, perform the steps of:

examining LAN router network traffic between one of the plurality of LAN network devices and one of the plurality of external network devices;

executing a scan of the plurality of LAN network devices;

generating the fingerprint data based upon one of the group consisting of the network traffic, the LAN network device scans, and the network traffic and the LAN network device scans;

generating the telemetry data based upon one of the group consisting of the network traffic, the LAN network device scans, and the network traffic and the LAN network device scans; and

sending the telemetry data and the fingerprint data to the cloud server,

wherein the telemetry or fingerprint data includes at least one of the group consisting of destination data, Dynamic Host Configuration Protocol (DHCP) fingerprint, multicast domain name service (mDNS) data, Hypertext Transfer Protocol (HTTP) data, hostname data, packet size data, and data specific to a web-based service.

2. The system of claim 1 , wherein the cloud server is further configured to generate a fingerprint from one of the group consisting of the telemetry data, the fingerprint data, and the telemetry data and the fingerprint data.

3. The system of claim 1 , wherein the cloud server is further configured to:

associate the fingerprint with a device profile identifier;

compare the fingerprint to a stored fingerprint of a device type indicated by the device profile identifier; and

determine if the fingerprint indicates anomalous behavior for the device type.

4. The system of claim 1 , wherein the agent is resident within the LAN router.

5. The system of claim 1 , wherein the cloud server is further configured to update a user interface to indicate the update the device attribute database.

6. A server ( 160 ) in communication with an agent ( 115 ) in a local area network (LAN) ( 120 ) via a first network ( 180 ) comprising a LAN router ( 110 ), the LAN comprising a plurality of LAN network devices ( 131 - 136 ), in communication with a plurality of external network devices ( 141 , 142 ) in the first network via the LAN router, the server comprising:

a device attribute database ( 530 ); and

a processor and a memory configured to store non-transitory instructions which, when executed, perform the steps of:

requesting the agent perform a scan of one or more of the plurality of LAN network devices;

receiving telemetry data and fingerprint data from the agent regarding traffic addressed to or transmitted by one of the plurality of LAN network devices;

generating a fingerprint for one of the plurality of LAN network devices from one of the group consisting of the telemetry data, the fingerprint data, and the telemetry data and the fingerprint data; and

storing the fingerprint in the device attribute database,

wherein the telemetry data includes at least one of the group consisting of destination data, Dynamic Host Configuration Protocol (DHCP) fingerprint, multicast domain name service (mDNS) data, Hypertext Transfer Protocol (HTTP) data, hostname data, packet size data, and data specific to a web-based service, and the fingerprint data excludes data measuring timing of traffic sent to and/or received by any of the plurality of LAN network devices.

7. The server of claim 6 , wherein the server is further configured to perform the steps of:

associating the fingerprint with a device profile identifier;

comparing the fingerprint to a stored fingerprint of a device type indicated by the device profile identifier; and

determining if the fingerprint indicates anomalous behavior for the device type.

8. A method for monitoring a plurality of LAN network devices ( 131 - 136 ), in a local area network (LAN) ( 120 ) comprising a LAN router ( 110 ) in communication with a first network ( 180 ), the plurality of LAN network devices in communication via the first network with a plurality of external network devices ( 141 , 142 ) in the first network, the method comprising the steps of:

examining LAN router network traffic between one of the plurality of LAN network devices and one of the plurality of external network devices;

executing a scan of the plurality of LAN network devices;

receiving telemetry data and fingerprint data regarding traffic between one of the plurality of LAN network devices and one of the plurality of external network devices;

generating a fingerprint for one of the plurality of LAN network devices from one of the group consisting of the telemetry data, the fingerprint data, and the telemetry data and the fingerprint data;

storing the fingerprint in the device attribute database; and

associating the fingerprint with a device profile identifier,

wherein the telemetry data includes at least one of the group consisting of destination data, Dynamic Host Configuration Protocol (DHCP) fingerprint, multicast domain name service (mDNS) data, Hypertext Transfer Protocol (HTTP) data, hostname data, packet size data, and data specific to a web-based service, and the fingerprint data excludes data measuring timing of traffic sent to and/or received by any of the plurality of LAN network devices.

9. The method of claim 8 , further comprising the steps of:

comparing the fingerprint to a stored fingerprint of a device type indicated by the device profile identifier; and

determining if the fingerprint indicates anomalous behavior for the device type.

10. An agent ( 115 ) in a local area network (LAN) ( 120 ) comprising a LAN router ( 110 ) in communication with a server ( 160 ) via a first network ( 180 ), the LAN comprising a plurality of LAN network devices ( 131 - 136 ), in communication via the first network with a plurality of external network devices ( 141 , 142 ), the agent comprising:

a processor and a memory configured to store non-transitory instructions which, when executed, perform the steps of:

examining LAN router network traffic between one of the plurality of LAN network devices and one of the plurality of external network devices;

executing a scan of the plurality of LAN network devices;

generating fingerprint data based upon one of the group consisting of the network traffic, the LAN network device scans, and the network traffic and the LAN network device scans;

generating telemetry data based upon one of the group consisting of the network traffic, the LAN network device scans, and the network traffic and the LAN network device scans; and

sending the telemetry data and the fingerprint data to the cloud server,

wherein the telemetry data includes at least one of the group consisting of destination data, Dynamic Host Configuration Protocol (DHCP) fingerprint, multicast domain name service (mDNS) data, Hypertext Transfer Protocol (HTTP) data, hostname data, packet size data, and data specific to a web-based service, and the telemetry and fingerprint data excludes data measuring timing of traffic sent to and/or received by any of the plurality of LAN network devices.

11. The agent of claim 10 , wherein the agent is resident within the LAN router.

12. A system for a local area network (LAN) ( 120 ) in communication with a first network ( 180 ), the LAN comprising a LAN router 110 in communication with a plurality of LAN network devices ( 131 - 136 ), the plurality of LAN network devices in communication via the first network with a plurality of external network devices ( 141 , 142 ), the system comprising:

a cloud server ( 160 ) in communication with the first network, the cloud server further comprising a device attribute database ( 530 ) and configured to receive telemetry data and fingerprint data and update the device attribute database; and

an agent ( 115 ) in communication with the cloud server and the plurality of network devices and the plurality of external network devices via the LAN router, wherein the agent comprises a processor and a memory configured to store non-transitory instructions which, when executed, perform the steps of:

examining LAN router network traffic between a first device of the plurality of LAN network devices and a second device of the plurality of LAN network devices;

executing a scan of the plurality of LAN network devices;

generating the fingerprint data based upon one of the group consisting of the network traffic, the LAN network device scans, and the network traffic and the LAN network device scans;

generating the telemetry data based upon one of the group consisting of the network traffic, the LAN network device scans, and the network traffic and the LAN network device scans; and

sending the telemetry data and the fingerprint data to the cloud server.

13. The system of claim 12 , wherein the cloud server is further configured to generate a fingerprint from one of the group consisting of the telemetry data, the fingerprint data, and the telemetry data and the fingerprint data.

14. The system of claim 12 , wherein the cloud server is further configured to:

associate the fingerprint with a device profile identifier;

compare the fingerprint to a stored fingerprint of a device type indicated by the device profile identifier; and

determine if the fingerprint indicates anomalous behavior for the device type.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 2, 2019
From: FRY, PETER; HITCHCOCK, JEREMY; RAJEWSKI, JONATHAN T.; ROONEY, ALEC
To: MINIM INC
Reel/Frame 047880/0918 →
Continuity (2)
Provisional Application 62649025 · Mar 28, 2018
Related Publication 20190306182A1 · Oct 3, 2019
Cited By (2)
US 12,261,818 US 12,671,689