IP Library Granted Patent US 12,192,175
Granted Patent B2
US 12,192,175 · App. 16/838,822 · Granted Jan 7, 2025

Intent-based security for industrial IoT devices

Inventors: Robert Edgar Barton (Richmond, CA); Thomas Szigeti (Vancouver, CA); Jerome Henry (Pittsboro, NC); Ruben Gerald Lobo (Raleigh, NC); Laurent Jean Charles Hausermann (Lyons, FR); Maik Guenter Seewald (Nuremberg, DE); Daniel R. Behrens (Chardon, OH)
Assignee: Cisco Technology, Inc.
H04L63/0263G05B19/05G06Q10/0875H04L12/4641H04L41/0803H04L41/0893H04L43/026H04L47/20H04L47/2441H04L47/323H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,192,175
App. No.
16/838,822
Granted
Jan 7, 2025
Kind
B2
Abstract

According to one or more embodiments of the disclosure, a device in a network identifies a packet sent via the network towards an endpoint as being a control packet for the endpoint. The device extracts one or more control parameter values from the control packet. The device compares the one or more control parameter values to a policy associated with the endpoint. The device initiates a corrective measure, based on a determination that the one or more control parameter values violate the policy associated with the endpoint.

Claims (40)

1. A method comprising:

identifying, by a device in a network, a packet sent via the network towards an endpoint as being a control packet for the endpoint, wherein a sensor module executed by the device analyzes the packet by performing deep packet inspection to identify use of an automation protocol by the packet;

extracting, by the device, one or more control parameter values from the control packet;

assigning, by the device, and to the endpoint, one or more component tags that identify a type and software of the endpoint and one or more activity tags that identify what the endpoint is doing at a protocol level;

comparing, by the device, the one or more control parameter values to a policy associated with the endpoint, wherein the policy associated with the endpoint defines an expected behavior of the endpoint based on the one or more component tags and the one or more activity tags assigned to the endpoint; and

initiating, by the device, a corrective measure, based on a determination that the one or more control parameter values violate the policy associated with the endpoint.

2. The method as in claim 1 , wherein initiating the corrective measure comprises:

blocking, by the device, the packet from being delivered to the endpoint.

3. The method as in claim 1 , wherein the endpoint controls an actuator, and wherein the one or more control parameter values affect how the actuator operates.

4. The method as in claim 3 , wherein the endpoint comprises a programmable logic controller (PLC) or variable-frequency drive (VFD) connected to the actuator.

5. The method as in claim 1 , wherein identifying the packet sent via the network towards the endpoint as being a control packet for the endpoint comprises:

identifying the packet as using an automation protocol.

6. The method as in claim 1 , wherein the device comprises a network firewall.

7. The method as in claim 1 , wherein the one or more control parameter values affect powering of a circuit.

8. An apparatus, comprising:

one or more network interfaces to communicate with a network;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process when executed configured to:

identify a packet sent via the network towards an endpoint as being a control packet for the endpoint, wherein a sensor module executed by the apparatus analyzes the packet by performing deep packet inspection to identify use of an automation protocol by the packet;

extract one or more control parameter values from the control packet;

assign to the endpoint one or more component tags that identify a type and software of the endpoint and one or more activity tags that identify what the endpoint is doing at a protocol level;

compare the one or more control parameter values to a policy associated with the endpoint, wherein the policy associated with the endpoint defines an expected behavior of the endpoint based on the one or more component tags and the one or more activity tags assigned to the endpoint; and

initiate a corrective measure, based on a determination that the one or more control parameter values violate the policy associated with the endpoint.

9. The apparatus as in claim 8 , wherein the corrective measure comprises blocking the packet from being delivered to the endpoint.

10. The apparatus as in claim 8 , wherein the endpoint controls an actuator, and wherein the one or more control parameter values affect how the actuator operates.

11. The apparatus as in claim 10 , wherein the endpoint comprises a programmable logic controller (PLC) or variable-frequency drive (VFD) connected to the actuator.

12. The apparatus as in claim 8 , wherein the apparatus identifies the packet sent via the network towards the endpoint as being a control packet for the endpoint by:

identifying the packet as using an automation protocol.

13. The apparatus as in claim 8 , wherein the apparatus comprises a network firewall.

14. The apparatus as in claim 8 wherein the one or more control parameter values affect powering of a circuit.

15. A tangible, non-transitory, computer-readable medium storing program instructions that cause a device in a network to execute a process comprising:

identifying, by the device in the network, a packet sent via the network towards an endpoint as being a control packet for the endpoint, wherein a sensor module executed by the device analyzes the packet by performing deep packet inspection to identify use of an automation protocol by the packet;

extracting, by the device, one or more control parameter values from the control packet;

assigning, by the device, and to the endpoint, one or more component tags that identify a type and software of the endpoint and one or more activity tags that identify what the endpoint is doing at a protocol level;

comparing, by the device, the one or more control parameter values to a policy associated with the endpoint, wherein the policy associated with the endpoint defines an expected behavior of the endpoint based on the one or more component tags and the one or more activity tags assigned to the endpoint; and

initiating, by the device, a corrective measure, based on a determination that the one or more control parameter values violate the policy associated with the endpoint.

16. The computer-readable medium as in claim 15 , wherein initiating the corrective measure comprises:

blocking, by the device, the packet from being delivered to the endpoint.

17. The computer-readable medium as in claim 15 , wherein the endpoint controls an actuator, and wherein the one or more control parameter values affect how the actuator operates.

18. The computer-readable medium as in claim 17 , wherein the endpoint comprises a programmable logic controller (PLC) or variable-frequency drive (VFD) connected to the actuator.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2020
From: BARTON, ROBERT EDGAR; SZIGETI, THOMAS; HENRY, JEROME; LOBO, RUBEN GERALD; HAUSERMANN, LAURENT JEAN CHARLES; SEEWALD, MAIK GUENTER; BEHRENS, DANIEL R.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 052307/0665 →
Continuity (2)
Provisional Application 62951645 · Dec 20, 2019
Related Publication 20210194851A1 · Jun 24, 2021
References Cited (34)
US 9838352B2 · Wetterwald et al. · 2017 [cited by applicant]
US 10212182B2 · Wetterwald et al. · 2019 [cited by applicant]
US 10298542B2 · Thubert et al. · 2019 [cited by applicant]
US 10530665B2 · Thubert et al. · 2020 [cited by applicant]
US 20170295071A1 · Yang · 2017 [cited by examiner]
US 20180276254A1 · Whitlock · 2018 [cited by examiner]
US 20190014137A1 · Du · 2019 [cited by examiner]
US 20190028434A1 · Cianfrocca · 2019 [cited by examiner]
US 20190220760A1 · Kolar · 2019 [cited by examiner]
US 20190238443A1 · Di Pietro et al. · 2019 [cited by applicant]
US 20190280942A1 · Cote et al. · 2019 [cited by applicant]
US 20190306011A1 · Fenoglio · 2019 [cited by examiner]
US 20190342195A1 · Mermoud et al. · 2019 [cited by applicant]
US 20190349426A1 · Smith · 2019 [cited by examiner]
US 20190356533A1 · Vasseur et al. · 2019 [cited by applicant]
US 20200007395A1 · Fainberg · 2020 [cited by examiner]
US 20200021560A1 · Hefley · 2020 [cited by examiner]
US 20200022016A1 · Fenoglio et al. · 2020 [cited by applicant]
US 20200358794A1 · Vasseur · 2020 [cited by examiner]
US 20210099424A1 · Li · 2021 [cited by examiner]
WO WO2019172762A1 · 2019 [cited by examiner]
WO WO2019190403A1 · 2019 [cited by examiner]
Aleksandrova, Mary, “Industrial IoT Security: How to Protect Smart Manufacturing”, Jul. 2019, 13 pages, Eastern Peak. [cited by applicant]
Gonzalez, Carlos, “Is Intent-Based Networking the Future of IoT?”, online: https://www.machinedesign.com/automation-iiot/article/21836153/is-intentbased-networking-the-future-of-iot, Nov. 2017, 14 pages, Machine Design. [cited by applicant]
Vasseur, et al., “Securing Your Network with Anomaly Detection Using Distributed Learning Architecture (Learning Networks)”, 2016, 39 pages, Cisco. [cited by applicant]
“Asset Intelligence: Focus on the OT and IoT Incidents that Matter”, Data Sheet, 2020, 4 pages, Nozomi Networks, Inc. [cited by applicant]
“Create a Tag”, Jan. 2020, 1 page, ExtraHop Networks, Inc. [cited by applicant]
“Devices”, Jan. 2020, 8 pages, ExtraHop. [cited by applicant]
“Extreme Visibility: Why Extreme Visibility in Industrial Networks is no Longer just a Nice-to-Have”, White Paper, Dec. 2018, 5 pages, Claroty, Clarity for OT Networks. [cited by applicant]
“Find a Device”, Jan. 2020, 8 pages, ExtraHop. [cited by applicant]
“Introduction to the ExtraHop System”, Jan. 2020, 7 pages, ExtraHop. [cited by applicant]
“OT and IoT Security and Visibility”, Solution Brief, 2020, 12 pages, Nozomi Networks, Inc. [cited by applicant]
“Threat Intelligence”, Data Sheet, 2020, 4 pages, Nozomi Networks, Inc. [cited by applicant]
“Using Service Classification to Build and Application-Aware NFV Infrastructure for Virtual CPE Services”, 2015, 6 pages, Intel Corporation. [cited by applicant]