Methods and systems for transmitting performance beacons from an embedded device
Abstract
A network sensor, inserted into a mirror port of a network switch or router, may be configured to monitor the network traffic originating from an embedded device. Metadata in the network traffic may be passively extracted by the network sensor and transmitted to a server in order to monitor and analyze the behavior of the embedded device. The server may employ machine learning to distinguish typical behavior of the embedded device from atypical behavior. Further, code may be injected into the firmware of the embedded device, and the code may be programmed to broadcast a performance beacon whenever certain firmware functions are executed. A collection of the performance beacons may be analyzed at the server to reconstruct an execution path of the embedded device, and machine learning may be applied to determine whether the execution path is typical or atypical.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for an embedded device, the embedded device including a processor, a network interface, and a data storage device storing firmware of the embedded device, the method comprising:
for each of a plurality of functions that are part of the firmware of the embedded device,
(i) executing the function by the processor of the embedded device, wherein prior the execution of the function, code is inserted into the function, the code configured to initiate a process during which a performance beacon is wirelessly transmitted from the embedded device, and
(ii) in response to the function being executed, wirelessly transmitting, by the network interface, the performance beacon from the embedded device, wherein the performance beacon includes an identifier of the embedded device, an identifier of the function, and a time stamp recording a time at which the function was executed,
wherein a plurality of performance beacons wirelessly transmitted from the embedded device are received by a server, and are used by the server to reconstruct an execution flow of the embedded device.
2 . The method of claim 1 , wherein the inserted code comprises a code snippet, and execution of the inserted code causes a routine that is stored in a library to be invoked, the routine causing the performance beacon to be wirelessly transmitted.
3 . The method of claim 1 , wherein the identifier of the embedded device includes a media access control (MAC) address of the embedded device.
4 . The method of claim 1 , wherein the performance beacon further comprises a program counter value of the processor when the performance beacon was generated.
5 . The method of claim 1 , wherein the performance beacon further comprises a stack value of the processor when the performance beacon was generated.
6 . The method of claim 1 , wherein wirelessly transmitting the performance beacon from the embedded device comprises transmitting the performance beacon in an unencrypted form to a broadcast address of a network using a user datagram protocol (UDP).
7 . The method of claim 1 , wherein the plurality of functions includes a function that is only executed during a boot process of the embedded device.
8 . An embedded device including a processor, a network interface, and a data storage device configured to store firmware of the embedded device, the firmware including instructions which when executed by the processor causes the processor to:
for each of a plurality of functions that are part of the firmware of the embedded device,
(i) execute the function, wherein prior to the execution of the function, code is inserted into the function, the code configured to initiate a process during which a performance beacon is wirelessly transmitted from the embedded device, and
(ii) in response to the function being executed, instruct the network interface to wirelessly transmit the performance beacon from the embedded device, wherein the performance beacon includes an identifier of the embedded device, an identifier of the function, and a time stamp recording a time at which the function was executed,
wherein a plurality of performance beacons wirelessly transmitted from the embedded device are received by a server, and are used by the server to reconstruct an execution flow of the embedded device.
9 . The embedded device of claim 8 , wherein the inserted code comprises a code snippet, and the execution of the inserted code causes a routine that is stored in a library to be invoked, the routine causing the performance beacon to be wirelessly transmitted.
10 . The embedded device of claim 8 , wherein the identifier of the embedded device includes a media access control (MAC) address of the embedded device.
11 . The embedded device of claim 8 , wherein the performance beacon further comprises a program counter value of the processor when the performance beacon was generated.
12 . The embedded device of claim 8 , wherein the performance beacon further comprises a stack value of the processor when the performance beacon was generated.
13 . The embedded device of claim 8 , wherein wirelessly transmitting the performance beacon from the embedded device comprises transmitting the performance beacon in an unencrypted form to a broadcast address of a network using a user datagram protocol (UDP).
14 . The embedded device of claim 8 , wherein the plurality of functions includes a function that is only executed during a boot process of the embedded device.
15 . A non-transitory computer-readable medium for an embedded device including a processor, a network interface, and a storage device configured to store firmware of the embedded device, the non-transitory computer-readable medium including instructions which when executed by the processor cause the processor to:
for each of a plurality of functions that are part of the firmware of the embedded device,
(i) execute the function, wherein prior to the execution of the function, code is inserted into the function, the code configured to initiate a process during which a performance beacon is wirelessly transmitted from the embedded device, and
(ii) in response to the function being executed, instruct the network interface to wirelessly transmit the performance beacon from the embedded device, wherein the performance beacon includes an identifier of the embedded device, an identifier of the function, and a time stamp recording a time at which the function was executed,
wherein a plurality of performance beacons wirelessly transmitted from the embedded device are received by a server, and are used by the server to reconstruct an execution flow of the embedded device.
16 . The non-transitory computer-readable medium of claim 15 , wherein the inserted code comprises a code snippet, and the execution of the inserted code causes a routine that is stored in a library to be invoked, the routine causing the performance beacon to be wirelessly transmitted.
17 . The non-transitory computer-readable medium of claim 15 , wherein the identifier of the embedded device includes a media access control (MAC) address of the embedded device.
18 . The non-transitory computer-readable medium of claim 15 , wherein the performance beacon further comprises a program counter value of the processor when the performance beacon was generated.
19 . The non-transitory computer-readable medium of claim 15 , wherein the performance beacon further comprises a stack value of the processor when the performance beacon was generated.
20 . The non-transitory computer-readable medium of claim 15 , wherein the plurality of functions includes a function that is only executed during a boot process of the embedded device.Join the waitlist — get patent alerts
Track US2018212991A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.