Edge Device Security Process for IoT Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security solutions for IoT devices in enterprise environments are costly and inefficient, as they primarily focus on mitigating known threats, failing to address unknown or emerging threats effectively, and can impact device performance by incorporating security features.
Innovation Solution
A security process that monitors and defines verified acceptable behaviors for edge devices, executing in kernel mode, and takes remedial actions such as notifications, shutdowns, or interface disabling when anomalies are detected, using a management service to manage and update profiles based on actual behavior data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing security options (anti-virus or anti-malware) are implemented on devices communicating with IoT devices, then known threats can be mitigated, but they lag behind threats and can only mitigate predefined threats
Solution Approach 1:
Instead of defining threats and monitoring for them (traditional approach), the patent inverts the approach by defining verified acceptable behaviors and monitoring to ensure no deviations or anomalies from these behaviors. This allows detection of unknown threats by identifying what does not match expected behavior patterns.
Solution Approach 2:
The system performs preliminary action by establishing a profile of acceptable behaviors before monitoring begins. This baseline profile enables the system to proactively identify deviations rather than reactively responding to known threat signatures.
2Reliability
If security features are included on the IoT device, then security can be improved, but device speed or other functionalities are affected
Solution Approach 1:
The patent extracts the security monitoring function from the IoT device itself and places it on the edge device. The edge device executes a security process that monitors the IoT device's communications and behaviors without requiring security features to be embedded in the IoT device, thus maintaining IoT device performance while achieving security objectives.
Solution Approach 2:
The edge device serves as an intermediary between the IoT device and the network. It executes security processes that monitor and analyze communications passing through it, providing security protection without requiring modifications to the IoT device's core functionality or performance.
3Reliability
If multiple edge devices are managed in an enterprise environment, then comprehensive security coverage is achieved, but providing effective security solutions becomes costly in time and effort
Solution Approach 1:
The security process designed for one edge device can be universally applied to multiple edge devices in the enterprise environment. The same security process and monitoring approach can be deployed across numerous devices, reducing the time and effort required to secure each individual device while maintaining comprehensive security coverage.
Data Source
AI summary
Disclosed are various examples for threat detection and security for edge devices in communication with Internet-of-Things (IoT) devices. In one example, a baseline behavior profile for a gateway virtual machine is transmitted from a management service to a gateway security process executed in a gateway device. The management service receives an anomaly notification including an indication of an anomaly from the baseline behavior profile. The managements service generates a user interface that shows a description of the anomaly.


