Distributed IoT Intrusion Detection With Centralized Event Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing intrusion detection systems (IDS) for IoT devices face challenges due to their limited processing power, memory, and network capabilities, making it difficult to implement effective security measures directly on these devices.

Innovation Solution

A distributed intrusion detection system (IDS) comprising a plurality of sensors in IoT devices and a server that collects and analyzes event data through a network, utilizing inspection and reconnaissance engines to monitor system health and network activity, and correlates data to detect intrusion events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If intrusion detection systems are implemented directly on IoT devices, then security detection capability is improved, but device processing power and energy consumption are insufficient

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoiddevice energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The intrusion detection system is segmented into distributed sensors deployed on IoT devices and a centralized server for heavy processing. Sensors collect and transmit event data to the server, which performs correlation analysis and generates alerts. This segmentation allows lightweight device implementation while maintaining comprehensive detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A centralized server acts as an intermediary between distributed IDS sensors and the analysis processing. The server receives event data from multiple sensors, performs correlation analysis, and generates alerts. This intermediary approach enables complex analysis without burdening individual IoT devices with high processing requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If more sensors and analysis capabilities are added to IoT devices, then intrusion detection accuracy is improved, but device complexity and cost increase

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments detection functions into simple sensors on devices and complex analysis on a centralized server. Sensors perform basic event collection while the server handles correlation analysis across multiple data sources. This segmentation achieves high detection accuracy without increasing individual device complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Multiple IDS sensors from different IoT devices are merged into a unified analysis system on the server. The server correlates event data from multiple sensors to detect intrusion patterns that individual sensors cannot identify alone. This merging approach improves detection accuracy while keeping individual device implementations simple.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12432250B2Distributed intrusion detection systems (IDS) and methods for internet of things (IoT) devices
Publication Date: 2025.09.30 HONEYWELL INTERNATIONAL INC
  • US12432250B2 patent drawing
  • US12432250B2 patent drawing
  • US12432250B2 patent drawing

AI summary

A distributed intrusion detection system (IDS) is provided. The IDS includes, but is not limited to: a plurality of IDS sensors distributed in internet of things (IoT) devices; and a server, coupled to the plurality of IDS sensors through a network, where the plurality of IDS sensors is configured to collect event data from the IoT devices, and the server is configured to: receive the collected event data from the plurality of IDS sensors; determine if an intrusion event occurs by correlating and analyzing the collected event data; and generate an alert in an instance in which the intrusion event occurs.