IP Library › Granted Patent US 11,757,836
Granted Patent B2
US 11,757,836 · App. 17/199,571 · Granted Sep 12, 2023

Management of internet of things (IoT) by security fabric

Inventors: John Lunsford Gregory Whittle (Menlo Park, CA); Jonathan Q. Nguyen-Duy (Fairfax, VA); Michael Craig Woolfe (Ashburn, VA)
Assignee: Fortinet, Inc.
H04L63/0227H04L49/25H04L63/105H04L63/1408H04L63/1416H04L63/1425H04L63/205H04L67/01H04L67/02H04L67/10H04L67/12H04L67/303H04L63/0272H04L63/1458
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,757,836
App. No.
17/199,571
Granted
Sep 12, 2023
Kind
B2
Abstract

The present invention relates to a method for managing IoT devices by a security fabric. A method is provided for managing IoT devices comprises collecting, by analyzing tier, data of Internet of Things (IoT) devices from a plurality of data sources, abstracting, by analyzing tier, profiled element baselines (PEBs) of IoT devices from the data, wherein each PEB includes characteristics of IoT devices; retrieving, by executing tier, the PEBs from the analyzing tier, wherein the executing tier is configured to control network traffic of IoT devices of a private network; generating, by the executing tier, security policies for IoT devices from PEBs of the IoT devices; and controlling, by the executing tier, network traffic of the IoT devices of the private network to comply with the security policies.

Claims (33)

1. A cloud-based network security system on a data communication network accessed by a plurality of subscribers from a plurality of private networks for automatically customizing management for variations in IoT (Internet of Things) devices, comprising:

an analyzing tier of the network security system, communicatively coupled to resources over the data communication network, to generate generic PEBs (profiled element baselines) for IoT devices of different types, wherein the generic PEBs each have a rigid class of policies that are mandatory for implementation and a discretionary class of policies that are optional for implementation;

an adapting tier of the network security system, communicatively coupled to the analyzing tier and to the private networks over the data communication network, to collect data from IoT devices on a specific private network of the plurality of private networks, wherein the adapting tier retrieves specific PEBs from the analyzing tier based on the collected data and tailors the specific PEBs according to the discretionary class of policies based on local conditions; and

an executing tier of the network security system, communicatively coupled to the adapting tier and to the specific private network, to interpret the specific PEBs and create local network security policies for controlling network traffic of the IoT devices of the private network to comply with the one or more security policies.

2. The network security system of claim 1 , wherein the at least one class comprises a smart sensor class.

3. The network security system of claim 2 , wherein the smart sensor class comprises at least one of a heating sensor, alighting sensor, a location sensor, a positioning sensor, a pressure sensor and a motion sensor.

4. The network security system of claim 2 , wherein a complex appliance class comprises at least one of a smart office, a smart house and a smart building.

5. The network security system of claim 1 , wherein the analyzing tier receives a request from the executive tier responsive to a new IoT device discovered on the specific private network.

6. The network security system of claim 5 , wherein the new IoT device is controlled by an updated security policy without manual configuration.

7. The network security system of claim 1 , wherein the adapting tier is located remote from the specific private network.

8. The network security system of claim 1 , wherein the adapting tier is located on the specific private network.

9. The network security system of claim 1 , wherein the adapting tier modifies one of the specific PEBs to disable unsafe HTTP access.

10. The network security system of claim 1 , wherein the executing tier creates the local network security policies to allow a communication protocol or a port number blocked by the executing tier.

11. A computer-implemented method in a cloud-based network security system on a data communication network accessed by a plurality of subscribers from a plurality of private networks for automatically customizing management for variations in IoT (Internet of Things) devices, the method comprising:

generating, by an analyzing tier of the network security system, generic PEBs (profiled element baselines) for IoT devices of different types, wherein the generic PEBs each have a rigid class of policies that are mandatory for implementation and a discretionary class of policies that are optional for implementation;

collecting, by an adapting tier of the network security system, data from IoT devices on a specific private network of the plurality of private networks

retrieving, by the adapting tier of the network security system, specific PEBs from the analyzing tier based on the collected data and tailors the specific PEBs according to the discretionary class of policies based on local conditions;

interpreting, by an executing tier of the network security system, the specific PEBs to create local network security policies to control network traffic of the IoT devices of the private network to comply with the one or more security policies; and

controlling network traffic of the IoT devices of the private network to comply with the one or more security policies.

12. The method of claim 11 , wherein the at least one class comprises a smart sensor class.

13. The method of claim 12 , wherein the smart sensor class comprises at least one of a heating sensor, alighting sensor, a location sensor, a positioning sensor, a pressure sensor and a motion sensor.

14. The method of claim 12 , wherein a complex appliance class comprises at least one of a smart office, a smart house and a smart building.

15. The network security system of claim 1 , wherein the analyzing tier receives a request from the executive tier responsive to a new IoT device discovered on the specific private network.

16. The method of claim 15 , wherein the new IoT device is controlled by an updated security policy without manual configuration.

17. The method of claim 11 , wherein the adapting tier is located remote from the specific private network.

18. The method of claim 11 , wherein the adapting tier is located on the specific private network.

19. The method of claim 11 , wherein the adapting tier modifies one of the specific PEBs to disable unsafe HTTP access.

20. A non-transitory computer-readable media for storing source code that, when executed by a processor, performs a computer-implemented method in a cloud-based network security system on a data communication network accessed by a plurality of subscribers from a plurality of private networks for automatically customizing management for variations in IoT (Internet of Things) devices, the method comprising:

generating, by an analyzing tier of the network security system, generic PEBs (profiled element baselines) for IoT devices of different types, wherein the generic PEBs each have a rigid class of policies that are mandatory for implementation and a discretionary class of policies that are optional for implementation;

collecting, by an adapting tier of the network security system, data from IoT devices on a specific private network of the plurality of private networks

retrieving, by the adapting tier of the network security system, specific PEBs from the analyzing tier based on the collected data and tailors the specific PEBs according to the discretionary class of policies based on local conditions;

interpreting, by an executing tier of the network security system, the specific PEBs to create local network security policies to control network traffic of the IoT devices of the private network to comply with the one or more security policies; and

controlling network traffic of the IoT devices of the private network to comply with the one or more security policies.

Continuity (3)
Continuation 15396423 · Dec 31, 2016
Continuation 15396378 · Dec 30, 2016
Related Publication 20210288939A1 · Sep 16, 2021