Cyberattack Protection via Device Cluster Similarity Metrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for linking devices in a network environment are unreliable and lack accuracy, making it difficult to detect and correlate devices with a user for effective protection against cyberattacks, as they rely on removable data or inadequate heuristics.

Innovation Solution

A method that detects relationships between clusters of devices by computing a similarity metric based on communication link characteristics, grouping devices into clusters, and determining relationships to modify protection measures when a cyberattack is detected, using heuristic rules and machine learning techniques to identify and type communication links.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional automatic methods of linking devices are used, then device linkage can be established, but the linkage is unreliable and lacks accuracy

Engineering Contradiction:
Improvedevice linkage reliabilityVSAvoiddevice correlation accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent changes the parameters used for device linkage from removable data (cookies) or simple heuristics to communication link characteristics such as protocol types, port numbers, and network topology. This transformation of parameters enables reliable and accurate device correlation by using stable, non-removable network communication attributes.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces conventional mechanical/link-based device identification methods with a network communication characteristic analysis system. By substituting traditional linkage mechanisms with communication link profiling and similarity metric computation, the system achieves more accurate and reliable device correlation without relying on removable data.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Difficulty of detecting and measuring

If devices are grouped into clusters based on communication link similarity, then device relationships can be detected, but the system complexity increases

Engineering Contradiction:
Improvedevice relationship detectionVSAvoidcluster management complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent segments devices into clusters based on similar communication link characteristics, grouping devices that share common network protocols, ports, or topological patterns. This segmentation enables systematic detection of device relationships while managing complexity through hierarchical clustering and representative profile selection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal clustering mechanism that can detect various types of device relationships (home network, public network, mobile network) using a single similarity metric framework. This multi-functional approach simplifies complexity management by using one unified method to handle multiple detection scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of manufacture

If heuristic rules are used to identify communication link types, then classification can be performed, but the accuracy and adaptability are insufficient

Engineering Contradiction:
Improvelink typing processVSAvoidlink type identification accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent enhances link type identification by changing from simple heuristic rules to a multi-parameter analysis approach. The system evaluates multiple communication characteristics (protocol, port, encryption, topology) simultaneously to determine link types, significantly improving accuracy while maintaining ease of implementation through automated profile comparison.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3798882A1System and method for protecting electronic devices from cyberattacks
Publication Date: 2021.03.31 AO KASPERSKY LAB
  • EP3798882A1 patent drawingFigure 1a~1e
  • EP3798882A1 patent drawingFigure 2
  • EP3798882A1 patent drawingFigure 3

AI summary

A method for protecting electronic devices from cyberattacks includes selecting a first device from a first cluster of devices and selecting a second device from a second cluster of devices. Information related to a first communication link associated with the first device and information related to a second communication link associated with the second device is obtained. A similarity metric is computed based on the obtained information. The similarity metric represents a similarity between the first communication link and the second communication link associated with the second device. A relationship between the first and second clusters is determined using the computed similarity metric. When a cyberattack is detected on the devices in the first cluster or the second cluster, protection of all devices in the first cluster and the second cluster is modified based on the determined relationship in order to defend the respective clusters from the cyberattack.