Distributed Threat Sensor Analysis for IoT Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices lack robust malware infection detection capabilities due to limited compute resources and data visibility, making it challenging to accurately detect and differentiate between legitimate and malicious activities.

Innovation Solution

A malware threat intelligence system comprising threat sensors deployed across different network addresses and geographic regions, which collect and aggregate data, compute significance scores, and correlate malicious actors with known devices to identify infected IoT devices, utilizing a combination of threat sensor deployment and management, data aggregation, and analysis components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If malware infection detection is implemented on IoT devices, then security detection capability is improved, but device resource consumption increases and detection reliability deteriorates due to limited compute resources

Engineering Contradiction:
Improvemalware detection reliabilityVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the malware detection functionality into two parts: lightweight detection agents deployed on IoT devices that collect local threat data, and a centralized cloud-based analysis service that performs complex malware detection using hundreds of millions of parameters. This segmentation allows IoT devices to maintain simple local agents while achieving enterprise-grade detection reliability through cloud processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces threat sensors as intermediary components that are deployed on IoT devices to collect threat intelligence data locally. These sensors act as intermediaries between the resource-constrained IoT devices and the cloud-based analysis service, gathering relevant threat data that is then transmitted to the cloud for comprehensive analysis, enabling reliable detection without burdening the IoT device itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If more parameters are used for malware detection, then detection accuracy is improved, but data transmission requirements and processing overhead increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoiddata volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system applies local quality by having threat sensors on IoT devices collect and pre-process threat data locally before transmission. Only relevant and pre-processed threat intelligence data is transmitted to the cloud, rather than raw device data. This allows the centralized service to use hundreds of millions of parameters for high-precision detection while minimizing data transmission requirements through intelligent local filtering and aggregation.

Inventive Principle:
Principle #3Local quality

3Reliability

If honeypots are deployed to gather threat intelligence, then threat detection capability is improved, but system complexity and maintenance cost increase

Engineering Contradiction:
Improvethreat intelligence qualityVSAvoidhoneypot system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements multi-functional threat sensors that can operate in multiple modes: they can function as honeypots to actively attract and monitor malicious actors, collect passive threat intelligence from network traffic, or perform local malware detection. This universal threat sensor design consolidates multiple threat intelligence gathering approaches into a single flexible component, reducing overall system complexity while maintaining high threat detection capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12058148B2Distributed threat sensor analysis and correlation
Publication Date: 2024.08.06 AMAZON TECH INC
  • US12058148B2 patent drawing
  • US12058148B2 patent drawing
  • US12058148B2 patent drawing

AI summary

Various embodiments of apparatuses and methods for distributed threat sensor analysis and correlation of a malware threat intelligence system are described. In some embodiments, the system comprises a plurality of threat sensors, deployed at different network addresses and physically located in different geographic regions in a provider network, which detect interactions from sources. In some embodiments, a distributed threat sensor analysis and correlation service obtains significance scores for different sources of the interactions with the plurality of threat sensors. The service determines which of the sources are malicious actors based on the significance scores. The service receives identifiers of known actors such as compute instances in the provider network, client devices in a client network, or deployed IoT devices in a remote network, and correlates the malicious actors with the known actors to identify which known actors might be infected by malware.