Anomaly Detection Device for IoT Connection Status Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional technologies face difficulties in accurately and efficiently understanding the connection status of communication devices, particularly IoT devices, due to changes in connection points or device replacements, making it challenging to automatically identify device connections, movements, or abandonment.

Innovation Solution

An anomaly detection system that includes a device with a learning unit, anomaly detection unit, and configuration management capabilities, which calculates anomaly scores from communication feature values to determine connection status and detect changes, using machine learning to analyze communication patterns and update configuration information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional traffic monitoring devices are used to detect security failures, then security monitoring capability is provided, but it is difficult to appropriately and readily understand the connection status of communication devices

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidconnection status information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the monitoring function into two parts: traffic flow analysis for security detection and connection status analysis for configuration management. The connection status is determined by analyzing communication feature values (source IP, destination IP, source port, destination port) separately from security threat detection, allowing both functions to be performed effectively without information loss

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary analysis of communication feature values to determine connection status before security threat assessment. By pre-processing the traffic data to extract connection information (source IP, destination IP, ports), the system prepares connection status data in advance, making it readily available for configuration management while maintaining security monitoring capabilities

Inventive Principle:
Principle #10Preliminary action

2Reliability

If polling is performed periodically regardless of device state, then configuration management is maintained, but monitoring efficiency decreases and resources are wasted

Engineering Contradiction:
Improveconfiguration managementVSAvoidmonitoring efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent uses periodic analysis of communication feature values at predetermined intervals to determine connection status. Instead of continuous polling, the system analyzes traffic patterns periodically, extracting connection information from the flowing traffic data. This periodic analysis maintains configuration management reliability while improving monitoring efficiency by avoiding constant resource consumption

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The monitoring system leverages the existing traffic flow itself to determine connection status, rather than generating separate polling traffic. By analyzing the communication feature values of normal traffic flows, the system extracts connection information passively, allowing the traffic to serve dual purposes: data transmission and configuration management, thereby improving efficiency

Inventive Principle:
Principle #25Self-service

3Reliability

If agents are introduced to manage configuration information, then configuration management capability is improved, but device complexity increases and resources are consumed

Engineering Contradiction:
Improveconfiguration management capabilityVSAvoiddevice resource consumption
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the configuration management function from the communication devices themselves and relocates it to an external monitoring device. The monitoring device analyzes communication feature values from traffic flowing through the network to determine connection status, eliminating the need for agents on resource-constrained devices. This extraction reduces device complexity while maintaining configuration management capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The monitoring device performs multiple functions: security threat detection, connection status determination, and configuration management. By consolidating these functions in a single external device that analyzes communication feature values, the system eliminates the need for separate agents on each communication device, reducing overall system complexity while maintaining comprehensive monitoring capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If traffic statistical analysis is performed to detect abnormal traffic, then security anomaly detection is achieved, but connection status understanding remains difficult

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidconnection configuration information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the analysis of traffic data into two distinct processes: statistical analysis for anomaly detection and connection status determination. The connection status is derived from communication feature values (source IP, destination IP, ports) extracted from the same traffic data used for anomaly detection. This segmentation ensures that connection configuration information is captured and analyzed separately, preventing information loss while maintaining anomaly detection capabilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary extraction and analysis of communication feature values to determine connection status before conducting anomaly detection. By pre-processing the traffic data to identify connection relationships (which devices are connected to which network infrastructure), the system ensures connection status information is captured and maintained, making it readily available for configuration management while proceeding with security anomaly detection

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3787240B1Device for anomaly detection, method and program for anomaly detection
Publication Date: 2024.01.03 NIPPON TELEGRAPH & TELEPHONE CORP
  • EP3787240B1 patent drawingFigure 1
  • EP3787240B1 patent drawingFigure 2
  • EP3787240B1 patent drawingFigure 3

AI summary

An anomaly detection device (30) acquires communication feature values of the communication devices (10), calculates, for each transmission source MAC address included in the communication feature values, a total value of the number of transmitted and received packets or the total value of the number of bytes for each layer-2 switch (50) that is connected to a corresponding communication device (10), and determines, for each transmission source MAC address, that a communication device (10) corresponding to the transmission source MAC address is connected to the layer-2 switch (50) whose total value of the number of transmitted and received packets or total value of the number of bytes is the largest. Furthermore, the anomaly detection device (30) determines whether connection has been stopped or replacement has been performed, using the total value of the number of transmitted and received packets or the total value of the number of bytes.