Data Traffic Metadata Extraction for IoT Security Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data processing methods for technical systems, such as sensor systems, lack effective monitoring of communication behavior and fail to detect unusual patterns or potential attacks in data traffic, particularly across different units like gateways, public networks, and cloud systems.
Innovation Solution
A computer-implemented method that ascertains metadata from data traffic, including average frequency, duration, and data volume, and uses models to estimate metadata for comparison, enabling detection of unusual behavior or attacks by analyzing deviations in data transfers between systems, with functionalities distributed across gateways, edge servers, and cloud servers to influence system operations or initiate error reactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data traffic is monitored and metadata is ascertained to detect unusual patterns, then security detection capability is improved, but system complexity and processing overhead increase
Solution Approach 1:
The patent extracts only the necessary metadata (frequency, duration, data volume) from the data traffic, separating these monitoring parameters from the actual data payload. This allows security monitoring without processing the entire data stream, reducing system complexity while maintaining detection capability.
Solution Approach 2:
The monitoring system is segmented into multiple functional components: metadata extraction module, model comparison module, and anomaly detection module. This segmentation allows each component to handle specific tasks independently, improving security detection while managing system complexity through modular design.
2Measurement precision
If metadata extraction and model comparison are performed for every data transfer, then detection accuracy is improved, but processing time and energy consumption increase
Solution Approach 1:
The system performs partial action by only extracting and analyzing metadata (frequency, duration, volume) rather than examining complete data packets. This partial processing maintains detection accuracy for security anomalies while significantly reducing processing time and energy consumption.
Solution Approach 2:
The patent uses pre-trained models that contain baseline knowledge of normal data traffic patterns. By comparing metadata against these pre-established models, the system achieves accurate detection without performing complex real-time analysis, thus reducing processing time.
3Adaptability or versatility
If distributed functionality is implemented across gateways, edge servers, and cloud servers, then system versatility and coverage are improved, but coordination complexity increases
Solution Approach 1:
The patent implements a universal metadata extraction and comparison mechanism that can operate across different system levels (gateway, edge, cloud). The same core functionality of extracting frequency, duration, and volume metadata is applied universally, allowing the system to adapt to various deployment scenarios without requiring fundamentally different approaches at each level.
Solution Approach 2:
The patent uses metadata as an intermediary that bridges different system levels. Instead of direct complex coordination between gateways, edge servers, and cloud systems, the standardized metadata format serves as a common language that simplifies information exchange and reduces coordination complexity across the distributed architecture.
Data Source
AI summary
A method, in particular a computer-implemented method, for processing data of a technical system. The method includes the following steps: ascertaining first pieces of information which are associated with a data traffic of the system, and ascertaining metadata associated with the data traffic of the system based on the first pieces of information.


