发明授权
- 专利标题: Guard system for automatic network flow controls for internet of things (IoT) devices
-
申请号: US15934931申请日: 2018-03-23
-
公开(公告)号: US11140180B2公开(公告)日: 2021-10-05
- 发明人: Charles K. Davis, III , Chris Dotson , Steven Lingafelt
- 申请人: International Business Machines Corporation
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理商 Jeffrey S. LaBaw; David H. Judson
- 主分类号: H04L29/06
- IPC分类号: H04L29/06
摘要:
A method, apparatus and computer program product for use in identifying and blocking operation of compromised or potentially compromised IoT device(s) on a network, such as a local network behind a router or firewall. To this end, the technique provides for automated and seamless on-boarding of a “guard” system for IoT devices, preferably as those devices join (or re-join) into the network via a Dynamic Host Configuration Protocol message exchange. In operation, and in response to receipt of a DHCP discover message that includes a network location, a DHCP server uses the network location to locate and retrieve a set of flow attributes for the device. Those attributes are then associated with the IP address to be assigned to the IoT device in a network control device. The network control device then selectively identifies and/or blocks operation of the IoT device when the IoT device is compromised or potentially compromised, thereby protecting the network (or network resources) from damage or misuse.
公开/授权文献
信息查询