Home Network Intrusion Detection System for Smart Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Home networks, particularly those with smart devices, lack sophisticated Intrusion Detection and Prevention Systems (IDPS) to effectively secure both wired and wireless connections, making them vulnerable to cyber threats that can quickly propagate across devices.

Innovation Solution

A network-based IDPS system that includes a software agent for threat detection, blocking, penetration testing, and vulnerability scanning, with a management and notification system, analytics, and databases to analyze and update security measures across both wired and wireless networks, including smart devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a software agent is installed on each smart device to provide intrusion detection and prevention, then security coverage is improved, but device complexity and resource requirements increase

Engineering Contradiction:
Improvesecurity coverageVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized IDPS server as an intermediary that performs intrusion detection and prevention functions remotely. Instead of installing complex security software on each smart device, the system uses a server-based approach where the IDPS server communicates with devices through network protocols, providing security services without increasing on-device complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional mechanical approach of installing local security software on each device with a network-based software agent system. The security functions are moved from individual devices to a centralized server, using network communication to substitute for direct local installation and execution of security mechanisms

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If antivirus applications are installed on each device to remediate threats, then threat remediation capability is improved, but device resource consumption increases

Engineering Contradiction:
Improvethreat remediation capabilityVSAvoiddevice resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent uses a centralized IDPS server as an intermediary that provides threat remediation services remotely. Instead of each device running its own resource-intensive antivirus application, the system uses network-based communication to deliver security updates and remediation actions from the server, significantly reducing on-device resource consumption while maintaining effective threat remediation capability

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If firewall capability is included within the internet access point using outdated technology, then device complexity is reduced, but security effectiveness deteriorates

Engineering Contradiction:
Improvedevice complexityVSAvoidsecurity effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent replaces outdated firewall technology with a modern network-based intrusion detection and prevention system. Instead of relying on legacy firewall mechanisms, the system uses network protocols and a centralized server to provide advanced security functions, improving security effectiveness while maintaining acceptable system complexity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the technological parameters of the security system by transitioning from outdated firewall technology to a modern IDPS architecture. This involves changing the underlying technology stack, communication protocols, and security mechanisms to achieve current security standards while managing system complexity through centralized management

Inventive Principle:
Principle #35Parameter changes

4Object-affected harmful factors

If wireless cyber threats can be launched directly at wireless devices, then network security boundaries are weakened, but the need for sophisticated IDPS increases

Engineering Contradiction:
Improvenetwork security boundariesVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent introduces a centralized IDPS server as an intermediary that monitors and protects wireless network traffic. This server acts as a security mediator between network segments, enabling detection and prevention of wireless cyber threats without requiring complex security measures on individual wireless devices, thus strengthening network security boundaries while managing overall system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10542020B2Home network intrusion detection and prevention system and method
Publication Date: 2020.01.21 TYCO FIRE & SECURITY GMBH
  • US10542020B2 patent drawing
  • US10542020B2 patent drawing
  • US10542020B2 patent drawing

AI summary

A home network Intrusion and Detect on Protection System (IDPS) is described. The Home Network IPDS provides a managed client solution that secures client home networks including both wired and wireless networks. The home networks can include not only computer devices and mobile devices, but also can include other connected devices such as smart devices. In embodiments, a software agent hosted on devices within the client's home network detects and scans for threats and provides remediation for the threats including blacklisting and placing compromised devices in a quarantined state. Logs created in response to threats are compared against known threats, and device reputation databases in a service network are maintained for the devices in each managed client network.