Cyberattack Protection via Device Cluster Similarity Metrics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for linking devices in a network environment are unreliable and lack accuracy, making it difficult to detect and correlate devices with a user for effective protection against cyberattacks, as they rely on removable data or inadequate heuristics.
Innovation Solution
A method that detects relationships between clusters of devices by computing a similarity metric based on communication link characteristics, grouping devices into clusters, and determining relationships to modify protection measures when a cyberattack is detected, using heuristic rules and machine learning techniques to identify and type communication links.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional automatic methods of linking devices are used, then device linkage can be established, but the linkage is unreliable and lacks accuracy
Solution Approach 1:
The patent changes the parameters used for device linkage from removable data (cookies) or simple heuristics to communication link characteristics such as protocol types, port numbers, and network topology. This transformation of parameters enables reliable and accurate device correlation by using stable, non-removable network communication attributes.
Solution Approach 2:
The patent replaces conventional mechanical/link-based device identification methods with a network communication characteristic analysis system. By substituting traditional linkage mechanisms with communication link profiling and similarity metric computation, the system achieves more accurate and reliable device correlation without relying on removable data.
2Difficulty of detecting and measuring
If devices are grouped into clusters based on communication link similarity, then device relationships can be detected, but the system complexity increases
Solution Approach 1:
The patent segments devices into clusters based on similar communication link characteristics, grouping devices that share common network protocols, ports, or topological patterns. This segmentation enables systematic detection of device relationships while managing complexity through hierarchical clustering and representative profile selection.
Solution Approach 2:
The patent creates a universal clustering mechanism that can detect various types of device relationships (home network, public network, mobile network) using a single similarity metric framework. This multi-functional approach simplifies complexity management by using one unified method to handle multiple detection scenarios.
3Ease of manufacture
If heuristic rules are used to identify communication link types, then classification can be performed, but the accuracy and adaptability are insufficient
Solution Approach 1:
The patent enhances link type identification by changing from simple heuristic rules to a multi-parameter analysis approach. The system evaluates multiple communication characteristics (protocol, port, encryption, topology) simultaneously to determine link types, significantly improving accuracy while maintaining ease of implementation through automated profile comparison.
Data Source
Figure 1a~1e
Figure 2
Figure 3
AI summary
A method for protecting electronic devices from cyberattacks includes selecting a first device from a first cluster of devices and selecting a second device from a second cluster of devices. Information related to a first communication link associated with the first device and information related to a second communication link associated with the second device is obtained. A similarity metric is computed based on the obtained information. The similarity metric represents a similarity between the first communication link and the second communication link associated with the second device. A relationship between the first and second clusters is determined using the computed similarity metric. When a cyberattack is detected on the devices in the first cluster or the second cluster, protection of all devices in the first cluster and the second cluster is modified based on the determined relationship in order to defend the respective clusters from the cyberattack.