Network Security System for Coordinated IoT Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security technologies are inadequate in detecting malicious activity across networks and network nodes, particularly in identifying coordinated attacks from millions of IoT devices that can go undetected due to encrypted data flows and complex routing patterns.
Innovation Solution
A system that determines data originating from multiple nodes, generates identifiers for network equipment and nodes, updates data with these identifiers, and uses relation criteria to flag potentially malicious traffic by determining common destinations and patterns, employing machine learning to identify malicious data and generate warning signals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current security technologies are used to monitor network traffic, then network operation maintains normal speed and latency, but malicious coordinated traffic from multiple IoT devices goes undetected
Solution Approach 1:
The patent segments the detection task by assigning unique identifiers to individual data flows and grouping them into aggregate flows. This segmentation allows the system to track individual device behavior while also analyzing coordinated patterns across multiple devices, thereby improving detection accuracy without requiring a monolithic complex system.
Solution Approach 2:
The patent introduces a new dimension of analysis by creating aggregate data flows that combine multiple individual data flows. This dimensional transformation enables the system to detect coordinated attacks from multiple IoT devices by analyzing patterns across aggregated traffic, rather than only examining individual flows in isolation.
2Loss of information
If traditional monitoring approaches are applied, then system resources are conserved, but the ability to track coordinated attacks from encrypted data flows is insufficient
Solution Approach 1:
The patent creates simplified copies of data flow information in the form of identifiers and aggregate flow representations. These copies enable the system to track and analyze traffic patterns without requiring deep inspection of encrypted payloads, thereby maintaining information visibility while minimizing processing overhead and energy consumption.
3Reliability
If deep packet inspection is used to analyze encrypted traffic, then malicious content can be detected, but network latency and processing time increase significantly
Solution Approach 1:
The patent performs preliminary actions by assigning identifiers to data flows and creating aggregate flow groupings before detailed analysis is needed. This preliminary structuring of traffic information enables faster subsequent detection of malicious patterns, reducing the time required for malicious traffic detection without requiring deep inspection of every packet.
4Loss of information
If intermediate nodes perform full traffic analysis, then complete visibility into data flows is achieved, but the massive vulnerable surface of billions of connected devices becomes unmanageable
Solution Approach 1:
The patent extracts essential identification information from complex encrypted traffic flows, creating simplified identifier tags and aggregate flow representations. This extraction process maintains visibility into traffic patterns while removing the complexity of analyzing full encrypted payloads, making network management feasible across billions of connected devices.
Data Source
AI summary
Network security is applied to identify malicious activity occurring on a network or at network nodes from a coordinated attack. For instance, a device, comprising a memory and a processor, can generate a first flag signal representative of a first flag applicable to first data and a second flag signal representative of a second flag applicable to second data in response to the first and second data being determined to be related and directed to a common destination node using identifiers associated with network equipment.


