Hierarchical Security System for IoT Network Edge
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing number of Internet-of-Things (IoT) devices with limited bandwidth and processing power poses challenges in securing data networks, as classical firewall technologies require pre-emptive knowledge of devices and cannot be updated easily, making them vulnerable to attacks like Denial of Service (DoS) and physical relocation, which classical firewalls cannot prevent without risking the devices.
Innovation Solution
A hierarchical security system is implemented within the data network, comprising network edge nodes, first and second-level analysis nodes, and a centralized entity that generate and evaluate traffic profiles using machine learning algorithms to apply dynamic firewall rules, allowing for real-time adaptation and protection without relying on device-specific updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If classical firewall technology is used to secure IoT devices, then device-specific protection rules can be implemented, but the system cannot adapt to device changes (e.g., physical relocation) and requires continuous manual updates
Solution Approach 1:
The system enables self-service by having devices automatically report their status (location, operational state) to the network edge node, which then automatically updates firewall rules without manual intervention. This resolves the contradiction by making the system both reliable (continuous protection) and adaptable (automatic response to changes).
Solution Approach 2:
The system implements feedback loops where device status changes are detected, communicated to the network edge node, and trigger automatic rule updates. This feedback mechanism ensures the firewall remains both reliable (consistent protection) and adaptable (responsive to changes).
2Reliability
If firewall rules are updated manually for each device change, then security rules can be maintained, but the operational effort becomes unsustainable with large numbers of devices
Solution Approach 1:
The automated system performs the work of monitoring and updating firewall rules without human intervention, dramatically improving productivity while maintaining reliability through continuous automatic adaptation to device changes.
Solution Approach 2:
The system replaces manual mechanical processes (human operators updating rules) with automated electronic monitoring and rule generation at the network edge, enabling scalable management of large device populations while maintaining security accuracy.
3Reliability
If security control is implemented at the device level, then device-specific threats can be addressed, but devices with limited processing power cannot run firewalling
Solution Approach 1:
The firewall functionality is extracted from the resource-constrained IoT devices and relocated to the network edge node, which has sufficient processing power. This allows devices to remain simple while still benefiting from robust security control.
Solution Approach 2:
The network edge node acts as an intermediary between the devices and the core network, providing firewall services to devices that lack the capability to run their own firewalling, thus maintaining security without increasing device complexity.
4Reliability
If comprehensive traffic monitoring is implemented to detect all attack vectors, then security coverage is improved, but bandwidth consumption increases
Solution Approach 1:
The system applies different levels of monitoring intensity to different devices and traffic patterns based on their risk profiles and behavior characteristics, optimizing security coverage while minimizing unnecessary bandwidth consumption from uniform high-intensity monitoring of all devices.
Data Source
Figure 1
AI summary
The present invention refers to a security system for a data network and for terminal devices coupled to the data network, the network comprising a network topology of a plurality of network nodes which are interconnected with each other, the security system being built-up hierarchically and implemented in the data network and comprising at least: - at least one network edge node (110) of the data network which is configured to extract and/or to generate traffic profiles from data traffic within the data network; - at least one first level analysis node (120) being connected to the at least one network edge node (110) and configured to receive the traffic profiles of the data traffic, to apply a learning algorithm to the traffic profiles, to store the learned traffic profiles locally and to forward at least some of the learned profiles which have become firmly established, to at least one second level analysis node (130), - the at least one second level analysis node (130) being connected to the at least one first level analysis node (120) and to at least one first logically centralized entity (140) and configured to receive the learned profiles from the at least one first level analysis node (120); - the at least one first logically centralized entity (140) which is configured to store rules which assign certain traffic profiles to respective actions, respectively, and to distribute, when the at least one second level analysis node (130) receives with a preconfigured frequency one of the certain traffic profiles from the at least one first level analysis node, the respective rules to the at least one second level analysis node (130) which forwards the respective rules to the at least one first level analysis node (120) for triggering execution of at least one action assigned to the received one of the certain traffic profiles.