US 12,216,459 B2
System and method for inferring device type based on port usage
Yuval Friedlander, Petah-Tiqwa (IL); Gil Ben Zvi, Hod Hasharon (IL); Tom Hanetz, Tel Aviv (IL); and Ron Shoham, Tel Aviv (IL)
Assigned to Armis Security Ltd., Tel Aviv-Jaffa (IL)
Filed by Armis Security Ltd., Tel Aviv-Jaffa (IL)
Filed on Nov. 10, 2021, as Appl. No. 17/523,362.
Prior Publication US 2023/0143024 A1, May 11, 2023
Int. Cl. G05B 19/418 (2006.01); G06F 18/214 (2023.01); G06N 5/04 (2023.01); H04L 9/40 (2022.01)
CPC G05B 19/41885 (2013.01) [G06F 18/214 (2023.01); G06N 5/04 (2013.01); H04L 63/1425 (2013.01)] 17 Claims
OG exemplary drawing
 
1. A method for inferring device types, comprising:
selecting a manufacturer-specific device type inference model from among a plurality of device type inference models based on a manufacturer of a device, wherein each device type inference model corresponds to a respective manufacturer and is trained using training data of devices manufactured by the respective manufacturer, wherein each device type inference model is trained to output a device type prediction;
determining, from device activity data of the device, a port usage distribution indicating traffic volumes for each port used by the device, wherein the device activity data indicates ports used by the device and at least one volume of traffic communicated via each port used by the device;
extracting a plurality of features from device activity data of the device and the port usage distribution; and
determining an inferred device type for the device, wherein determining the inferred device type for the device further comprises applying the selected manufacturer-specific device type inference model to the extracted plurality of features.