Broadcast Channel Control Loop for IoT Node Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Low Power and Lossy Networks (LLNs), such as IoT networks, face challenges in routing, Quality of Service (QoS), security, and traffic engineering due to their complex nature, where traditional approaches are inefficient, and machine learning algorithms have not been effectively utilized to manage changing conditions and large network sizes.

Innovation Solution

Implementing a control loop control mechanism using a broadcast channel to communicate with nodes under attack, where a management device with a learning machine engine determines attacked nodes and uses intermediate nodes to relay attack-mitigation packets, and dynamically adjusts the unicast/broadcast ratio to mitigate denial-of-service attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional routing and security approaches are used in LLNs, then device complexity is reduced, but security reliability deteriorates due to inability to effectively detect and respond to attacks in large, dynamic networks

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the LLN and external networks. This gateway hosts a learning machine engine that performs complex security analysis and attack detection, while the constrained LLN nodes simply forward packets. The gateway acts as a mediator that handles the computational burden of security monitoring, allowing nodes to maintain simplicity while the system achieves high security reliability through the learning machine's ability to detect DDoS attacks and other threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The learning machine engine automatically detects attacks, identifies victim nodes, and generates mitigation packets without human intervention. The system self-adjusts to changing network conditions by continuously learning from traffic patterns and automatically responding to threats. This self-service capability allows the security system to adapt to new attack types and network dynamics without requiring manual configuration or complex node logic.

Inventive Principle:
Principle #25Self-service

2Reliability

If machine learning algorithms are deployed at LLN nodes to detect attacks, then security detection capability improves, but processing capability and energy consumption worsen due to resource constraints

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the security functionality into two parts: simple packet forwarding at LLN nodes and complex learning machine processing at an external gateway. The LLN network is divided into resource-constrained nodes that perform only basic routing, while the gateway handles the computationally intensive attack detection and analysis. This segmentation allows the system to achieve high security detection capability without overburdening the energy-constrained nodes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway serves as an intermediary that performs the energy-intensive machine learning operations on behalf of the LLN nodes. Instead of each node running its own learning machine (which would consume excessive energy), the gateway consolidates this functionality and provides security services to the entire network, dramatically reducing per-node energy consumption while maintaining or improving overall detection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If unicast communication is used to send attack-mitigation packets to victim nodes, then communication precision improves, but communication efficiency deteriorates when multiple nodes are under attack

Engineering Contradiction:
Improvecommunication precisionVSAvoidcommunication efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements a dynamic communication strategy that adapts to the number of attacked nodes. When only one node is under attack, the system uses precise unicast communication to send mitigation packets directly to that node. When multiple nodes are attacked, the system dynamically switches to efficient broadcast communication to reach all victims simultaneously. This dynamic adaptation allows the system to maintain communication precision for single-node attacks while achieving high efficiency for multi-node attacks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the communication parameter (from unicast to broadcast) based on the attack scenario. The learning machine analyzes the attack pattern and determines the optimal communication mode, adjusting this parameter dynamically to balance precision and efficiency. This parameter change allows the system to optimize communication performance according to the specific attack conditions rather than using a fixed approach.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3090586B1Control loop control using broadcast channel to communicate with a node under attack
Publication Date: 2020.02.05 CISCO TECHNOLOGY INC
  • EP3090586B1 patent drawingFigure 1
  • EP3090586B1 patent drawingFigure 2
  • EP3090586B1 patent drawingFigure 3

AI summary

In one embodiment, a control loop control using a broadcast channel may be used to communicate with a node under attack. A management device may receive data indicating that one or more nodes in a computer network are under attack. The management device may then determine that one or more intermediate nodes are in proximity to the one or more nodes under attack, and communicate an attack-mitigation packet to the one or more nodes under attack by using the one or more intermediate nodes to relay the attack-mitigation packet to the one or more nodes under attack.