Dynamic Risk Assessment for Heterogeneous IoT Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current threat modeling tools are inadequate for dynamic networks, failing to capture essential security and privacy parameters, and lack a comprehensive view of information flow, especially in heterogeneous networks with growing IoT connections, leading to ineffective risk and threat analysis.

Innovation Solution

A processor-implemented method and system that receives data on information flow between network nodes, identifies affected nodes and paths, computes attack risk, and generates a mitigation plan by propagating risk to neighboring nodes, simulating attacks, and providing business impact assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional threat modeling tools are used to evaluate static network topologies, then the analysis is simple and fast, but the tools cannot capture essential security and privacy parameters in dynamic networks

Engineering Contradiction:
Improvesecurity and privacy parameter captureVSAvoidnetwork analysis complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transitions from static topology analysis to dynamic network analysis by continuously monitoring information flow between nodes. The system updates risk assessments in real-time as network conditions change, capturing security and privacy parameters that evolve over time in dynamic heterogeneous networks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent adds the information flow dimension to traditional topology-based analysis. By incorporating data about information exchange between nodes, the system creates a multi-dimensional view of network security that captures both structural relationships and dynamic data movement patterns.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If major configuration changes are made to evaluate network design changes, then the analysis can capture updated security parameters, but the process becomes time-consuming and costly

Engineering Contradiction:
Improvesecurity parameter assessmentVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system pre-establishes a comprehensive risk assessment framework that includes all necessary security parameters and relationships. When network changes occur, the system performs incremental updates rather than complete re-evaluations, saving time while maintaining assessment accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors network state and automatically updates risk assessments based on observed changes. This feedback mechanism enables the system to adapt to network design changes in real-time without requiring manual reconfiguration or time-consuming re-analysis.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If traditional risk assessment metrics are used, then the evaluation is straightforward, but the tools lack the ability to analyze inter-layer impact in heterogeneous networks

Engineering Contradiction:
Improvemulti-layer analysis capabilityVSAvoidassessment system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the heterogeneous network into multiple layers or domains, analyzing information flow and risk within each layer while also examining interactions between layers. This segmented approach enables comprehensive multi-layer analysis while managing complexity through modular processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs a universal risk assessment framework that can handle multiple network protocols, layers, and heterogeneous components through a unified methodology. This multi-functional approach enables the system to adapt to diverse network configurations without requiring separate analysis tools for each layer.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If comprehensive risk assessment across all nodes is performed, then the security coverage is complete, but the computational overhead increases significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies local quality assessment by evaluating security risks at each node based on its specific characteristics, information flow patterns, and local vulnerabilities. Rather than applying uniform assessment to all nodes, the system tailors the analysis to local conditions, improving reliability while reducing unnecessary computational overhead.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs risk assessment on affected nodes and their neighbors rather than all nodes in the network. This partial action approach maintains comprehensive security coverage for critical areas while significantly reducing computational resources required for the overall assessment.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3282668B1Comprehensive risk assessment in a heterogeneous dynamic network
Publication Date: 2020.10.21 TATA CONSULTANCY SERVICES LTD
  • EP3282668B1 patent drawingFigure 1
  • EP3282668B1 patent drawingFigure 2
  • EP3282668B1 patent drawingFigure 3A~3C

AI summary

Systems and methods of the present disclosure provide comprehensive risk assessment in a heterogeneous dynamic network. The framework enables 'view' and 'analyses' of complete architecture simultaneously in information view, deployment view, business view and security view. Fundamentally, data pertaining to information flow between a plurality of nodes within systems in a network is identified. One or more affected nodes or paths therebetween are identified and attack risk is computed. The graph based framework supports multiple threat models for threat evaluation. It also provides mitigation plans which will reflect reduced risk in the business view and incorporates attack tree simulations to evaluate dynamic behavior of a system under attack.