Cross-Domain IoT Anomaly Detection via Collective Device Data Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems for IoT devices struggle to accurately and quickly detect intelligent malicious codes due to their isolated monitoring approach, which makes it difficult to identify anomalies across connected devices.

Innovation Solution

A method that compares operation information from one device with another, even if they are in different domains, by considering factors like manufacturer, product name, domain identity, behavior patterns, CPU usage, memory usage, and packet information to detect anomalies collectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If isolated information on individual devices is used for anomaly detection, then device complexity and computational burden are reduced, but measurement precision and detection accuracy deteriorate

Engineering Contradiction:
Improvecomputational burdenVSAvoiddetection accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent merges information from multiple devices including operation information, vulnerability information, and patch information to perform collective anomaly detection. By combining data from devices 211, 221, 231 across different domains with the target device 212, the system achieves higher detection accuracy without requiring complex isolated analysis of each device individually.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent adds a new dimension to anomaly detection by incorporating cross-device information from different domains. Instead of analyzing devices in isolation (single dimension), the system collects and analyzes information from multiple devices simultaneously, creating a multi-dimensional detection space that improves measurement precision while managing computational complexity through structured information gathering.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If collective analysis of multiple devices is performed, then detection accuracy improves, but device complexity and information processing requirements increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidinformation processing requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the collective analysis process into distinct modules: acquiring operation information from multiple devices, acquiring vulnerability information, acquiring patch information, and performing anomaly detection by comparing these segmented information types. This segmentation reduces information processing requirements by handling each type of data separately rather than processing all data simultaneously as a monolithic task.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary computing device that collects and processes information from multiple devices before performing anomaly detection. This intermediary acts as a mediator between the target device and the analysis system, organizing and preprocessing information from devices 211, 221, 231, and the target device 212, thereby reducing the complexity burden on individual devices while maintaining high detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If information from devices in different domains is analyzed, then detection versatility improves, but loss of information increases due to domain isolation

Engineering Contradiction:
Improvedetection versatilityVSAvoidinformation availability
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent implements a universal information collection mechanism that can gather operation information, vulnerability information, and patch information from devices across different domains (first domain, second domain, third domain). This multi-functional approach allows the system to adapt to various device types and domain configurations while maintaining consistent information gathering capabilities, thereby improving detection versatility without losing critical information due to domain isolation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11336671B2Method and apparatus for detecting anomaly in a plurality of devices by collectively analyzing information on devices
Publication Date: 2022.05.17 KOREA INTERNET & SECURITY AGENCY
  • US11336671B2 patent drawing
  • US11336671B2 patent drawing
  • US11336671B2 patent drawing

AI summary

Provided are a method for detecting an anomaly in devices, the method being performed by a computing device and comprising: acquiring operation information on a first device connected to a security management unit (SMU) of a first domain, and operation information on a second device connected to a SMU of a second domain, and detecting an anomaly in the first device and/or the second device by comparing the operation information on the first device with the operation information on the second device, wherein the SMU of the first domain is not directly connected to the SMU of the second domain.