Edge Device Security Process for IoT Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security solutions for IoT devices in enterprise environments are costly and inefficient, as they primarily focus on mitigating known threats, failing to address unknown or emerging threats effectively, and can impact device performance by incorporating security features.

Innovation Solution

A security process that monitors and defines verified acceptable behaviors for edge devices, executing in kernel mode, and takes remedial actions such as notifications, shutdowns, or interface disabling when anomalies are detected, using a management service to manage and update profiles based on actual behavior data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security options (anti-virus or anti-malware) are implemented on devices communicating with IoT devices, then known threats can be mitigated, but they lag behind threats and can only mitigate predefined threats

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidability to detect unknown threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of defining threats and monitoring for them (traditional approach), the patent inverts the approach by defining verified acceptable behaviors and monitoring to ensure no deviations or anomalies from these behaviors. This allows detection of unknown threats by identifying what does not match expected behavior patterns.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system performs preliminary action by establishing a profile of acceptable behaviors before monitoring begins. This baseline profile enables the system to proactively identify deviations rather than reactively responding to known threat signatures.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security features are included on the IoT device, then security can be improved, but device speed or other functionalities are affected

Engineering Contradiction:
ImprovesecurityVSAvoiddevice speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the security monitoring function from the IoT device itself and places it on the edge device. The edge device executes a security process that monitors the IoT device's communications and behaviors without requiring security features to be embedded in the IoT device, thus maintaining IoT device performance while achieving security objectives.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The edge device serves as an intermediary between the IoT device and the network. It executes security processes that monitor and analyze communications passing through it, providing security protection without requiring modifications to the IoT device's core functionality or performance.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple edge devices are managed in an enterprise environment, then comprehensive security coverage is achieved, but providing effective security solutions becomes costly in time and effort

Engineering Contradiction:
Improvesecurity coverageVSAvoidtime and effort for security management
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security process designed for one edge device can be universally applied to multiple edge devices in the enterprise environment. The same security process and monitoring approach can be deployed across numerous devices, reducing the time and effort required to secure each individual device while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11706237B2Threat detection and security for edge devices
Publication Date: 2023.07.18 VMWARE INC
  • US11706237B2 patent drawing
  • US11706237B2 patent drawing
  • US11706237B2 patent drawing

AI summary

Disclosed are various examples for threat detection and security for edge devices in communication with Internet-of-Things (IoT) devices. In one example, a baseline behavior profile for a gateway virtual machine is transmitted from a management service to a gateway security process executed in a gateway device. The management service receives an anomaly notification including an indication of an anomaly from the baseline behavior profile. The managements service generates a user interface that shows a description of the anomaly.