×

METHODS AND SYSTEMS FOR DETECTING ANOMALOUS BEHAVIOR OF NETWORK-CONNECTED EMBEDDED DEVICES

  • US 20180115574A1
  • Filed: 10/24/2016
  • Published: 04/26/2018
  • Est. Priority Date: 10/24/2016
  • Status: Active Grant
First Claim
Patent Images

1. A method for monitoring one or more embedded devices communicatively coupled to a first network, the method comprising:

  • monitoring, by a first network sensor, network traffic on the first network;

    inspecting, by the first network sensor, the network traffic so as to distinguish network traffic that is associated with the embedded devices from network traffic that is associated with devices other than the embedded devices;

    transmitting, by the first network sensor, metadata from the network traffic associated with the embedded devices to a server;

    storing, at the server, the metadata in a first queue associated with the first network sensor; and

    for each of the embedded devices communicatively coupled to the first network,(i) building, by a machine learning module hosted on the server, a behavioral profile of the embedded device;

    (ii) monitoring, by a behavioral analysis module hosted on the server, a behavior of the embedded device;

    (iii) comparing, by the behavioral analysis module, the monitored behavior of the embedded device with a typical behavior of the embedded device as captured in the behavioral profile of the embedded device so as to determine whether the monitored behavior deviated from the typical behavior; and

    (iv) if the monitored behavior deviates from the typical behavior, notifying, by a notification module hosted on the server, a user that the monitored behavior of the embedded device deviated from the typical behavior of the embedded device.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×