Security monitoring system for internet of things (iot) device environments
Abstract
Techniques are described for implementing a security service that can be used to monitor and provide security-related information for Internet of Things (IoT) devices. An IoT security service uses a reference framework to model the progressive stages of IoT security attacks, also referred to herein as an IoT kill chain. Each stage of an IoT kill chain is associated with a set of security threat “facilitators” and/or security threat “indicators.” Facilitators represent characteristics of an IoT device that cause the device to be susceptible to various types of security threats, while indicators represent detected device activity indicating a potential ongoing security attack. An IoT security service collects data from IoT devices being monitored and possibly other related components, analyzes the collected data to detect defined facilitators and indicators, and uses the detected facilitators and indicators to calculate various security scores for individual devices or for groups of devices.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A computer-implemented method comprising:
sending, by an agent running in an Internet of Things (IoT) environment comprising a plurality of IoT devices, device configuration information and security data to a cloud security service providing IoT security threat protection, wherein the device configuration information and security data relate to an IoT device of the plurality of IoT devices; generating, based on the device configuration information, a recommendation for improving the security posture of the IoT device; generating, based on the security data, a security alert indicating potential malicious activity in the IoT environment; and causing display of a graphical user interface (GUI) including an indication of the recommendation and the security alert.
22 . The computer-implemented method of claim 21 , wherein the agent executes on the IoT device and logs, processes, and sends the device configuration and security data to the cloud security service.
23 . The computer-implemented method of claim 21 , wherein the device configuration information and the security data is collected by the cloud security service.
24 . The computer-implemented method of claim 21 , wherein the data includes device profile data including at least one of: an indication of a device type, software running on the IoT device, software versions running on the IoT device, device network configurations, device encryption configurations, and wherein the data further includes device activity data including one or more of network traffic data, application data, file modification data, and device error activity.
25 . The computer-implemented method of claim 21 , wherein the security alert is associated with a severity level.
26 . The computer-implemented method of claim 21 , further comprising causing execution of an action to occur relative to the IoT device, the action including one or more of: rebooting the IoT device, sending a software update to the IoT device, modifying one or more network or system configurations associated with the IoT device, collecting additional data from the IoT device.
27 . The computer-implemented method of claim 21 , further comprising identifying, based on the security data and a defined IoT kill chain, a stage of the IoT kill chain associated with the security alert.
28 . The computer-implemented method of claim 21 , further comprising calculating, based on one or more identified security threat facilitators and one or more security threat indicators, a breach likelihood score indicating a likelihood that the IoT device has been compromised.
29 . A computer-implemented method comprising:
obtaining, by an Internet of Things (IoT) security service, device data related to an IoT device located in a computer network comprising a plurality of IoT devices, the device data including data reflecting device configurations and reflecting operation of the IoT device; generating, based on the device data, at least one recommendation for improving the security posture of the IoT device and at least one security alert indicating potential malicious activity; and causing display of a graphical user interface (GUI) including an indication of the recommendation for improving the security posture of the IoT device and an indication of the security alert.
30 . The computer-implemented method of claim 29 , wherein the device data is collected by an on-device agent running on the IoT device.
31 . The computer-implemented method of claim 29 , wherein the device data is collected by the IoT security service.
32 . The computer-implemented method of claim 29 , wherein the device data includes device profile data including at least one of: an indication of a device type, software running on the IoT device, software versions running on the IoT device, device network configurations, device encryption configurations, and wherein the data further includes device activity data including one or more of network traffic data, application data, file modification data, and device error activity.
33 . The computer-implemented method of claim 29 , wherein the security alert is associated with a severity level.
34 . The computer-implemented method of claim 29 , further comprising causing execution of an action to occur relative to the IoT device, the action including one or more of: rebooting the IoT device, sending a software update to the IoT device, modifying one or more network or system configurations associated with the IoT device, collecting additional data from the IoT device.
35 . The computer-implemented method of claim 29 , further comprising identifying, based on the device data and a defined IoT kill chain, a stage of the IoT kill chain associated with the security alert.
36 . A system comprising:
a first one or more electronic devices to implement a cloud security service providing Internet of Things (IoT) security threat protection, the cloud security service including instructions that upon execution cause the cloud security service to:
obtain device configuration information related to an IoT device located in a computer network comprising a plurality of IoT devices and security data reflecting operation of the IoT device;
generate, based on the device configuration information, a recommendation for improving the security posture of the IoT device;
generate, based on the security data, a security alert indicating potential malicious activity in the computer network, and
cause display of a graphical user interface (GUI) including an indication of the recommendation and the security alert; and
a second one or more electronic devices to implement an IoT agent, the IoT agent including instructions that upon execution cause the IoT agent to:
collect the device configuration information and the security data from the IoT device; and
send the configuration information and the security data to the cloud security service.
37 . The system of claim 36 , wherein the device configuration information and the security data is collected by an on-device agent.
38 . The system of claim 36 , wherein the device configuration information and the security data is collected by the cloud security service.
39 . The system of claim 36 , wherein the data includes device profile data including at least one of: an indication of a device type, software running on the computing device, software versions running on the computing device, device network configurations, device encryption configurations, and wherein the data further includes device activity data including one or more of network traffic data, application data, file modification data, and device error activity.
40 . The system of claim 36 , wherein the security alert is associated with a severity level.Join the waitlist — get patent alerts
Track US2021029156A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.