Consensus Network for IoT Device Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures for interconnected devices, such as those in 5G networks, are inadequate in detecting and addressing compromised devices within a network, leading to potential unauthorized access and attacks, especially in complex IoT environments where manual diagnostics are cumbersome and inefficient.
Innovation Solution
A consensus network system where multiple devices within a network can identify and classify anomalous behavior using machine learning and consensus algorithms, allowing for automatic detection and corrective actions, such as isolating compromised devices, without user intervention, to maintain network security and integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual security diagnostics are used in complex IoT networks, then user control is maintained, but detection efficiency and response time are significantly reduced
Solution Approach 1:
The system implements self-service through autonomous devices that automatically perform security diagnostics, anomaly detection, and compromise classification without requiring user intervention. Each device monitors itself and other network devices, automatically identifying and responding to security threats through embedded machine learning models and consensus algorithms.
Solution Approach 2:
The system performs preliminary action by continuously monitoring network traffic and device behavior patterns to detect anomalies before they can cause significant harm. The consensus network proactively identifies compromised devices and isolates them before attacks can propagate through the network, preventing rather than merely responding to security incidents.
2Measurement precision
If comprehensive message collection and analysis is performed across all devices, then detection precision is improved, but network overhead and processing requirements increase
Solution Approach 1:
The system segments the analysis workload by distributing machine learning models and detection algorithms across individual devices rather than centralizing processing. Each device independently analyzes its own messages and contributes to collective anomaly detection, dividing the computational burden while maintaining comprehensive monitoring coverage across the network.
Solution Approach 2:
The system applies local quality by enabling each device to perform specialized analysis on locally-relevant data using embedded machine learning models. Devices analyze messages and behavior patterns specific to their local network context, providing precise anomaly detection without requiring all devices to process all network data centrally.
3Reliability
If consensus algorithms are used to classify compromised devices, then reliability of detection is improved, but computational complexity and response time may increase
Solution Approach 1:
The system implements partial action by having devices participate in consensus only when anomalies are detected rather than continuously. When normal operation is observed, devices skip the consensus process, reducing computational complexity. The consensus mechanism is activated selectively to maintain reliability only when needed for anomaly classification.
Solution Approach 2:
The consensus algorithm provides feedback by allowing devices to share their anomaly assessments and collectively verify compromised device classifications. This distributed feedback mechanism improves detection reliability through peer validation while managing complexity through iterative convergence rather than exhaustive analysis of all possible device states.
Data Source
AI summary
A computer-implemented system and method for device discovery and recovery in a secure network comprises registering a plurality of devices, where the devices form the secure network at a location. Communication between the plurality of registered devices is enabled, and messages passed between the plurality of devices are collected. The method further comprises determining which one of the plurality of devices is a compromised device by using a consensus network that includes the plurality of devices of the secure network.


