IP Library › Granted Patent US 11,765,590
Granted Patent B2
US 11,765,590 · App. 17/474,538 · Granted Sep 19, 2023

System and method for rogue device detection

Inventors: Anil Kaushik (Karnataka, IN); Ravjibhai Kamani Bhaveshkumar (Ahmedabad, IN)
Assignee: Sophos Limited
H04W12/122G06F16/955H04W12/009H04W12/60H04W24/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,765,590
App. No.
17/474,538
Granted
Sep 19, 2023
Kind
B2
Abstract

Methods, systems, and computer readable media for rogue device detection are described. A method may include identifying a device type of a device transmitting data over a network and obtaining one or more uniform resource locators (URLs) from the data, where the one or more URLs form a portion of a request transmitted over the network by the device. The method can also include programmatically analyzing the data to determine a pattern of network data within a given time period. The method can further include determining that the device is a rogue device if the pattern of network data deviates from a baseline pattern of the device type, or at least one of the one or more URLs matches one or more rogue URL criteria. The method can also include taking an action in response to determining the device is a rogue device to improve security of the network.

Claims (52)

1. A method comprising:

identifying a device type of a device transmitting data over a network;

obtaining one or more uniform resource locators (URLs) from the data, wherein the one or more URLs form a portion of a request transmitted over the network by the device;

programmatically analyzing the obtained one or more URLs from the data to determine a pattern of network data within a given time period;

determining that the device is a rogue device based on the pattern of network data deviating from a baseline pattern of the device and whether at least one of the one or more URLs matches a rogue URL criteria, wherein:

the baseline pattern of the device includes one or more of device historical data or aggregate historical data for devices of a same type as the device type, and

the rogue URL criteria includes one or more of:

two or more simultaneous URL requests,

a request for an invalid URL, wherein the invalid URL includes one or more of a URL with a domain name service (DNS) failure,

a URL associated with a request response that is indicative of invalidity of the URL,

multiple instances of a same URL in the data,

a count of URL requests within a particular time period that exceeds a threshold number of URLs, or

a rate at which of URL requests are transmitted to the network; and

taking an action in response to determining the device is a rogue device to improve security of the network.

2. The method of claim 1 , further comprising:

determining that the device is an authenticated device that has been authenticated to a cloud-based network security system; and

based on the determining, marking the device as a potentially compromised device.

3. The method of claim 1 , wherein the action includes one or more of: isolating the device, disconnecting the device from the network, or moving the device to a separate virtual network.

4. The method of claim 3 , wherein the action is based on determining whether the device has been authenticated by the network, and wherein the action comprises:

disconnecting the device from the network based on a determination that the device has not been authenticated by the network; and

isolating the device or moving the device to the separate virtual network based on a determination that the device has been authenticated by the network.

5. The method of claim 1 , wherein the device type includes information from a device registry, wherein the information includes one or more of device manufacturer, device model, device operating system, device hardware version, or device software version.

6. The method of claim 1 , wherein the device historical data in the baseline pattern includes one or more URLs accessed by the device at one or more times within a baseline monitoring time period.

7. The method of claim 1 , further comprising generating the baseline pattern by analyzing one or more of the device historical data or the aggregate historical data for the devices of the same type as the device type.

8. The method of claim 1 , further comprising generating the device historical data in the baseline pattern by collecting a list of URLs previously accessed by the device.

9. The method of claim 8 , wherein collecting the list of URLs previously accessed by the device further comprises collecting a time of day when each URL in the list of URLs is accessed by the device.

10. The method of claim 1 , wherein the baseline pattern further includes time period information indicating a time of previous access of the obtained one or more URLs.

11. The method of claim 1 , further comprising determining, based on the device type of the device, a suitability of the one or more uniform resource locators (URLs) accessed by the device, wherein an unsuitable URL is indicative of a likelihood of the device being the rogue device.

12. The method of claim 1 , wherein the device historical data in the baseline pattern further includes a baseline roaming pattern of the device, and wherein determining that the device is the rogue device further comprises determining that the device is connected to a particular access point indicative of a roaming pattern that deviates from the baseline roaming pattern of the device.

13. A threat management system, comprising:

one or more processors; and

a nontransitory computer readable medium coupled to the one or more processors, the nontransitory computer readable medium having stored thereon instructions that, when executed by the one or more processors, causes the one or more processors to perform operations including:

identifying a device type of a device transmitting data over a network;

obtaining one or more uniform resource locators (URLs) from the data, wherein the one or more URLs form a portion of a request transmitted over the network by the device;

programmatically analyzing the obtained one or more URLs from the data to determine a pattern of network data within a given time period;

determining that the device is a rogue device based on the pattern of network data deviating from a baseline pattern of the device and whether at least one of the one or more URLs matches a rogue URL criteria, wherein:

the baseline pattern of the device includes one or more of device historical data or aggregate historical data for devices of a same type as the device type, and

the rogue URL criteria includes one or more of:

two or more simultaneous URL requests,

a request for an invalid URL, wherein the invalid URL includes one or more of a URL with a domain name service (DNS) failure,

a URL associated with a request response that is indicative of invalidity of the URL,

multiple instances of a same URL in the data,

a count of URL requests within a particular time period that exceeds a threshold number of URLs, or

a rate at which of URL requests are transmitted to the network; and

taking an action in response to determining the device is a rogue device to improve security of the network.

14. The threat management system of claim 13 , wherein the operations further comprise:

determining that the device is a device that has been authenticated to a cloud-based network security system; and

based on the determining, marking the device as a potentially compromised device.

15. The threat management system of claim 13 , wherein the action includes one or more of isolating the device, disconnecting the device from the network, or moving the device to a separate virtual network.

16. The threat management system of claim 15 , wherein the action is based on determining whether the device has been authenticated by the network, and wherein the action comprises:

disconnecting the device from the network based on a determination that the device has not been authenticated by the network; and

isolating the device or moving the device to the separate virtual network based on a determination that the device has been authenticated by the network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2021
From: KAUSHIK, ANIL; BHAVESHKUMAR, RAVIJBHAI KAMANI
To: SOPHOS LIMITED
Reel/Frame 057483/0338 →
Priority Claims (1)
IN 202011039929 · Sep 15, 2020 · national
Continuity (1)
Related Publication 20220086645A1 · Mar 17, 2022