Information Processing for Lightweight IoT Attack Containment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security measures, such as endpoint detection and response (EDR), are ineffective against zero-day attacks using unknown vulnerabilities, and resource-constrained IoT devices lack practical solutions for functional degradation to mitigate such attacks.

Innovation Solution

An information processing apparatus and method that detects unauthorized access using unknown vulnerabilities, restricting only the functions used by attackers to prevent further unauthorized access, while maintaining overall functionality, and includes features like rebooting, functional restriction, and tampering detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If endpoint detection and response (EDR) is used to detect and isolate attacked terminals, then security against known vulnerabilities is improved, but resource consumption increases making it impractical for IoT devices

Engineering Contradiction:
ImprovesecurityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent uses lightweight, disposable security measures tailored for resource-constrained IoT devices. Instead of deploying heavy EDR agents, the system uses simple vulnerability databases, lightweight detection rules, and basic isolation mechanisms that can be implemented with minimal resources on IoT devices while still providing effective security against zero-day attacks.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The security system is segmented into multiple components: vulnerability database storage, detection rule evaluation, attack scenario matching, and isolation execution. This segmentation allows each component to be optimized independently, with the detection module using minimal resources while the isolation mechanism provides strong security when triggered.

Inventive Principle:
Principle #1Segmentation

2Reliability

If all functions are stopped to prevent unknown vulnerability attacks, then security is improved, but system functionality deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidsystem functionality
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by restricting only the specific function that was exploited for the attack rather than stopping all functions. The system identifies the vulnerable function through attack scenario matching and isolates only that specific function, allowing other functions to continue operating normally. This maintains system productivity while providing security against zero-day attacks.

Inventive Principle:
Principle #3Local quality

3Reliability

If functional degradation is implemented against unknown vulnerability attacks, then damage from attacks is minimized, but the technique does not specify how to identify which function to stop

Engineering Contradiction:
Improveattack damage mitigationVSAvoidfunction identification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses preliminary action by pre-defining attack scenarios and their corresponding coping strategies in a database before attacks occur. When an attack is detected, the system matches the detected attack pattern against predefined scenarios and automatically executes the corresponding pre-planned function restrictions. This eliminates the complexity of real-time function identification while effectively mitigating attack damage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously monitoring system behavior, comparing it against predefined attack scenarios, and adjusting function restrictions based on the matching results. When an attack pattern is detected, the system provides feedback by triggering the appropriate coping strategy from the database, creating a closed-loop security response that adapts to detected threats.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4621617A1Information processing apparatus and information processing method
Publication Date: 2025.09.24 CANON KK
  • EP4621617A1 patent drawingFigure 1
  • EP4621617A1 patent drawingFigure 2
  • EP4621617A1 patent drawingFigure 3

AI summary

An information processing apparatus collects a log of operations of a system or a program, and detects unauthorized access on the basis of the operation log and an attack scenario defined with a combination of functions which are not performed typically. When unauthorized access is detected, a function to be restricted is specified on the basis of the attack scenario used in the detection, and the specified function is restricted.