Blended IoT Security Management via Dynamic Response Combination
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing complexity of interconnected environments in a blended IoT setting creates diverse security threats, necessitating a method to effectively respond to various and blended security incidents across networks.
Innovation Solution
A security management method and system that detects security anomalies, collects and analyzes attack data, dynamically combines response techniques based on the analyzed attack type, and performs automatic responses using a cyber kill chain model, while updating the response model post-incident.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If various environments are complexly connected through networks to form a blended environment, then connectivity and functionality are improved, but security threats and attack surfaces increase
Solution Approach 1:
The patent segments the blended environment into multiple isolated environments (first environment, second environment, etc.) with distinct security boundaries. Each environment maintains its own security policies and controls, preventing threats from propagating across the entire network while still allowing controlled connectivity through the network connection section.
Solution Approach 2:
The patent introduces a network connection section as an intermediary component between different environments. This intermediary implements security management functions including authentication, authorization, and threat detection, allowing controlled communication while blocking malicious traffic and preventing direct exposure of internal environments to external threats.
2Reliability
If security management is implemented across multiple interconnected environments, then security coverage is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal security management approach where the network connection section serves multiple functions: authentication, authorization, threat detection, and isolated communication routing. This single multi-functional component manages security across all environments without requiring separate complex security systems in each environment.
Solution Approach 2:
The patent adds a new dimensional layer of security management at the network connection section, separate from individual environment security. This dimensional change allows centralized security policies and threat detection to operate across all environments without modifying the internal structure of each environment, thereby reducing overall system complexity.
3Speed
If automated response techniques are implemented for security anomalies, then response speed is improved, but adaptability to new attack types decreases
Solution Approach 1:
The patent implements feedback mechanisms where security anomalies and attack patterns detected in one environment are analyzed and used to update security policies and response techniques across all environments. This feedback loop enables the system to learn from new attack types and automatically adapt its response strategies while maintaining fast automated response times.
Solution Approach 2:
The patent employs preliminary security measures including pre-configured security policies, authentication mechanisms, and threat detection rules at the network connection section. These preliminary actions enable automated response to known attack types while the system simultaneously learns and adapts to new threats through feedback from detected anomalies.
Data Source
AI summary
A security management method of Internet of blended environment (IoBE) in which a plurality of environments are connected to each other through a network includes: detecting a security anomaly occurring through an attack surface existing in a device included in each of the plurality of environments in the IoBE or in a network connection section between the plurality of environments; collecting attack data related to the detected security anomaly, and analyzing an attack type based on the collected data; dynamically combining response techniques based on the analyzed attack type; and performing an automatic response to the security anomaly based on the combined response techniques.


