IoT device application workload capture

US12224984B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12224984-B2
Application numberUS-202318520385-A
CountryUS
Kind codeB2
Filing dateNov 27, 2023
Priority dateMar 31, 2021
Publication dateFeb 11, 2025
Grant dateFeb 11, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Internet of Things (IoT) device application workload capture is disclosed. A target IoT device is selected. A flow associated with the target IoT device is determined and tagged. Packets from the tagged flow are admitted into a ring buffer. An indication is received that an extraction should be performed on a portion of the packets included in the ring buffer.

First claim

Opening claim text (preview).

What is claimed is: 1. A system, comprising: a processor configured to: select a target IoT device; determine and tag a flow associated with the target IoT device; admit packets from the tagged flow into a ring buffer; receive an indication that an extraction should be performed on a portion of the packets included in the ring buffer; and extract the portion of the packets; and a memory coupled to the processor and configured to provide the processor with instructions. 2. The system of claim 1 , wherein the target IoT device is selected at least in part based on a detection of an elevation of a risk score. 3. The system of claim 2 , wherein the risk score is elevated based at least in part on a determination of an applicability of a known exploit to the target IoT device. 4. The system of claim 2 , wherein the risk score is elevated based at least in part on an observation of an attempted exploit of the target IoT device. 5. The system of claim 1 , wherein the target IoT device is selected at least in part based on a URL with which the target IoT device communicates. 6. The system of claim 1 , wherein the indication is received as part of a time-based trigger. 7. The system of claim 1 , wherein the indication is received in response to a generation of an alert. 8. The system of claim 1 , wherein the extracted portion of the packets is provided to a network traffic analysis system. 9. The system of claim 1 , wherein the processor is further configured to receive an indication to stop admitting packets associated with the target IoT device into the ring buffer. 10. The system of claim 9 , wherein the indication to stop admitting the packets is received in response to a predefined number of sessions associated with the target IoT device. 11. A method, comprising: selecting a target IoT device; determining and tagging a flow associated with the target IoT device; admitting packets from the tagged flow into a ring buffer; receiving an indication that an extraction should be performed on a portion of the packets included in the ring buffer; and extracting the portion of the packets. 12. A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for: selecting a target IoT device; determining and tagging a flow associated with the target IoT device; admitting packets from the tagged flow into a ring buffer; receiving an indication that an extraction should be performed on a portion of the packets included in the ring buffer; and extracting the portion of the packets. 13. The method of claim 11 , wherein the target IoT device is selected at least in part based on a detection of an elevation of a risk score. 14. The method of claim 13 , wherein the risk score is elevated based at least in part on a determination of an applicability of a known exploit to the target IoT device. 15. The method of claim 13 , wherein the risk score is elevated based at least in part on an observation of an attempted exploit of the target IoT device. 16. The method of claim 11 , wherein the target IoT device is selected at least in part based on a URL with which the target IoT device communicates. 17. The method of claim 11 , wherein the indication is received as part of a time-based trigger. 18. The method of claim 11 , wherein the indication is received in response to a generation of an alert. 19. The method of claim 11 , wherein the extracted portion of the packets is provided to a network traffic analysis system. 20. The method of claim 11 , further comprising receiving an indication to stop admitting packets associated with the target IoT device into the ring buffer. 21. The method of claim 20 , wherein the indication to stop admitting the packets is received in response to a predefined number of sessions associated with the target IoT device.

Assignees

Inventors

Classifications

  • Security thereof · CPC title

  • Management of faults, events, alarms or notifications · CPC title

  • the condition being an adaptation, e.g. in response to network events · CPC title

  • Information technology; Communication · CPC title

  • by filtering · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12224984B2 cover?
Internet of Things (IoT) device application workload capture is disclosed. A target IoT device is selected. A flow associated with the target IoT device is determined and tagged. Packets from the tagged flow are admitted into a ring buffer. An indication is received that an extraction should be performed on a portion of the packets included in the ring buffer.
Who is the assignee on this patent?
Palo Alto Networks Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/0254. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Feb 11 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).