Cross-Domain IoT Anomaly Detection via Collective Device Data Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security systems for IoT devices struggle to accurately and quickly detect intelligent malicious codes due to their isolated monitoring approach, which makes it difficult to identify anomalies across connected devices.
Innovation Solution
A method that compares operation information from one device with another, even if they are in different domains, by considering factors like manufacturer, product name, domain identity, behavior patterns, CPU usage, memory usage, and packet information to detect anomalies collectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If isolated information on individual devices is used for anomaly detection, then device complexity and computational burden are reduced, but measurement precision and detection accuracy deteriorate
Solution Approach 1:
The patent merges information from multiple devices including operation information, vulnerability information, and patch information to perform collective anomaly detection. By combining data from devices 211, 221, 231 across different domains with the target device 212, the system achieves higher detection accuracy without requiring complex isolated analysis of each device individually.
Solution Approach 2:
The patent adds a new dimension to anomaly detection by incorporating cross-device information from different domains. Instead of analyzing devices in isolation (single dimension), the system collects and analyzes information from multiple devices simultaneously, creating a multi-dimensional detection space that improves measurement precision while managing computational complexity through structured information gathering.
2Measurement precision
If collective analysis of multiple devices is performed, then detection accuracy improves, but device complexity and information processing requirements increase
Solution Approach 1:
The patent segments the collective analysis process into distinct modules: acquiring operation information from multiple devices, acquiring vulnerability information, acquiring patch information, and performing anomaly detection by comparing these segmented information types. This segmentation reduces information processing requirements by handling each type of data separately rather than processing all data simultaneously as a monolithic task.
Solution Approach 2:
The patent introduces an intermediary computing device that collects and processes information from multiple devices before performing anomaly detection. This intermediary acts as a mediator between the target device and the analysis system, organizing and preprocessing information from devices 211, 221, 231, and the target device 212, thereby reducing the complexity burden on individual devices while maintaining high detection accuracy.
3Adaptability or versatility
If information from devices in different domains is analyzed, then detection versatility improves, but loss of information increases due to domain isolation
Solution Approach 1:
The patent implements a universal information collection mechanism that can gather operation information, vulnerability information, and patch information from devices across different domains (first domain, second domain, third domain). This multi-functional approach allows the system to adapt to various device types and domain configurations while maintaining consistent information gathering capabilities, thereby improving detection versatility without losing critical information due to domain isolation.
Data Source
AI summary
Provided are a method for detecting an anomaly in devices, the method being performed by a computing device and comprising: acquiring operation information on a first device connected to a security management unit (SMU) of a first domain, and operation information on a second device connected to a SMU of a second domain, and detecting an anomaly in the first device and/or the second device by comparing the operation information on the first device with the operation information on the second device, wherein the SMU of the first domain is not directly connected to the SMU of the second domain.


