Anomaly Detection Device for IoT Connection Status Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional technologies face difficulties in accurately and efficiently understanding the connection status of communication devices, particularly IoT devices, due to changes in connection points or device replacements, making it challenging to automatically identify device connections, movements, or abandonment.
Innovation Solution
An anomaly detection system that includes a device with a learning unit, anomaly detection unit, and configuration management capabilities, which calculates anomaly scores from communication feature values to determine connection status and detect changes, using machine learning to analyze communication patterns and update configuration information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional traffic monitoring devices are used to detect security failures, then security monitoring capability is provided, but it is difficult to appropriately and readily understand the connection status of communication devices
Solution Approach 1:
The patent segments the monitoring function into two parts: traffic flow analysis for security detection and connection status analysis for configuration management. The connection status is determined by analyzing communication feature values (source IP, destination IP, source port, destination port) separately from security threat detection, allowing both functions to be performed effectively without information loss
Solution Approach 2:
The patent performs preliminary analysis of communication feature values to determine connection status before security threat assessment. By pre-processing the traffic data to extract connection information (source IP, destination IP, ports), the system prepares connection status data in advance, making it readily available for configuration management while maintaining security monitoring capabilities
2Reliability
If polling is performed periodically regardless of device state, then configuration management is maintained, but monitoring efficiency decreases and resources are wasted
Solution Approach 1:
The patent uses periodic analysis of communication feature values at predetermined intervals to determine connection status. Instead of continuous polling, the system analyzes traffic patterns periodically, extracting connection information from the flowing traffic data. This periodic analysis maintains configuration management reliability while improving monitoring efficiency by avoiding constant resource consumption
Solution Approach 2:
The monitoring system leverages the existing traffic flow itself to determine connection status, rather than generating separate polling traffic. By analyzing the communication feature values of normal traffic flows, the system extracts connection information passively, allowing the traffic to serve dual purposes: data transmission and configuration management, thereby improving efficiency
3Reliability
If agents are introduced to manage configuration information, then configuration management capability is improved, but device complexity increases and resources are consumed
Solution Approach 1:
The patent extracts the configuration management function from the communication devices themselves and relocates it to an external monitoring device. The monitoring device analyzes communication feature values from traffic flowing through the network to determine connection status, eliminating the need for agents on resource-constrained devices. This extraction reduces device complexity while maintaining configuration management capability
Solution Approach 2:
The monitoring device performs multiple functions: security threat detection, connection status determination, and configuration management. By consolidating these functions in a single external device that analyzes communication feature values, the system eliminates the need for separate agents on each communication device, reducing overall system complexity while maintaining comprehensive monitoring capabilities
4Reliability
If traffic statistical analysis is performed to detect abnormal traffic, then security anomaly detection is achieved, but connection status understanding remains difficult
Solution Approach 1:
The patent segments the analysis of traffic data into two distinct processes: statistical analysis for anomaly detection and connection status determination. The connection status is derived from communication feature values (source IP, destination IP, ports) extracted from the same traffic data used for anomaly detection. This segmentation ensures that connection configuration information is captured and analyzed separately, preventing information loss while maintaining anomaly detection capabilities
Solution Approach 2:
The patent performs preliminary extraction and analysis of communication feature values to determine connection status before conducting anomaly detection. By pre-processing the traffic data to identify connection relationships (which devices are connected to which network infrastructure), the system ensures connection status information is captured and maintained, making it readily available for configuration management while proceeding with security anomaly detection
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An anomaly detection device (30) acquires communication feature values of the communication devices (10), calculates, for each transmission source MAC address included in the communication feature values, a total value of the number of transmitted and received packets or the total value of the number of bytes for each layer-2 switch (50) that is connected to a corresponding communication device (10), and determines, for each transmission source MAC address, that a communication device (10) corresponding to the transmission source MAC address is connected to the layer-2 switch (50) whose total value of the number of transmitted and received packets or total value of the number of bytes is the largest. Furthermore, the anomaly detection device (30) determines whether connection has been stopped or replacement has been performed, using the total value of the number of transmitted and received packets or the total value of the number of bytes.