Calibrated Confidence Intrusion Detection for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Intrusion Detection Systems (IDSs) face challenges in managing false positive alerts and identifying attacks in detail, particularly with the increasing number and scale of cyber-attacks on Internet of Things (IoT) devices, which are vulnerable due to limited resources, and Intrusion Response Systems (IRSs) struggle to deploy optimal countermeasures without compromising system security.

Innovation Solution

A computer-implemented method using a machine learning (ML) model, such as a random forest model, to process activity data and generate confidence values for anomalous activities, allowing for calibrated confidence data to determine appropriate mitigating actions based on threshold comparisons and risk metrics, thereby improving the accuracy of intrusion detection and response.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IDS methods are used to detect intrusions, then the system can identify malicious activities, but the system generates a large number of false positive alerts that are difficult to manage

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidfalse positive alerts
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent replaces traditional rule-based IDS mechanisms with a machine learning model that processes activity data and generates calibrated confidence values. This substitution enables the system to distinguish malicious activities from false positives more accurately, reducing the management burden of false positive alerts while maintaining reliable intrusion detection

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces calibrated confidence values as a new parameter to quantify the likelihood of malicious activity. By changing from binary detection to probabilistic assessment with calibrated confidence levels, the system can prioritize alerts and reduce false positives through threshold-based filtering and nuanced response decisions

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traditional IDS methods are used, then the system can detect intrusions, but the system struggles to identify attacks in detail

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidattack detail information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent replaces traditional signature-based detection with a machine learning model that analyzes activity data patterns to not only detect intrusions but also classify and characterize them in detail. The model provides calibrated confidence values for different attack types, enabling comprehensive attack identification beyond simple detection

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an Intrusion Response System (IRS) as an intermediary between IDS detection and response actions. The IRS uses calibrated confidence values to determine appropriate mitigating actions, preserving detailed attack information and enabling nuanced responses based on attack severity and confidence levels

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If IoT sensors and actuators are added to the Internet, then the system provides enhanced functionality, but the devices become more vulnerable to malware and attacks due to limited resources

Engineering Contradiction:
ImproveIoT device functionalityVSAvoiddevice security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent replaces resource-intensive traditional security software with a streamlined machine learning model that can operate on IoT devices with limited resources. The model processes activity data efficiently while providing calibrated confidence values for security decisions, enabling robust security functionality without compromising device performance

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent enables IoT devices to autonomously process activity data through the machine learning model and generate calibrated confidence values for security decisions. This self-service capability allows devices to protect themselves without requiring extensive external security infrastructure, maintaining security reliability despite resource constraints

Inventive Principle:
Principle #25Self-service

4Productivity

If an IRS is not appropriately configured, then the system responds to attacks, but the IRS deploys inappropriate actions that compromise system security

Engineering Contradiction:
Improveresponse action deploymentVSAvoidsystem security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the IRS uses calibrated confidence values from the machine learning model to inform its response decisions. The system continuously adjusts mitigating actions based on confidence levels and attack patterns, ensuring appropriate responses that maintain system security while effectively deploying countermeasures

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces calibrated confidence values as a controlling parameter for IRS decision-making. By changing from rule-based responses to confidence-driven actions, the system deploys appropriate mitigating measures based on the likelihood and severity of attacks, preventing both over-response to false positives and under-response to genuine threats

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240378288A1Anomalous activity mitigation
Publication Date: 2024.11.14 BRITISH TELECOM PLC
  • US20240378288A1 patent drawing
  • US20240378288A1 patent drawing
  • US20240378288A1 patent drawing

AI summary

A computer-implemented method comprising: obtaining activity data indicative of an anomalous activity within a computer system; processing the activity data to generate confidence data representative of a set of confidence values, each confidence value representative of a confidence that the anomalous activity comprises a respective type of activity; and determining, based on at least the confidence data, mitigating action to take to mitigate the anomalous activity. Further examples relate to a computer system configured to implement an intrusion detection system and an intrusion response system, and to a computer-implemented method of calibrating a system comprising a machine learning model trained to generate output uncalibrated confidence data representative of a set of output uncalibrated confidence values.