Network Security System for Coordinated IoT Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security technologies are inadequate in detecting malicious activity across networks and network nodes, particularly in identifying coordinated attacks from millions of IoT devices that can go undetected due to encrypted data flows and complex routing patterns.

Innovation Solution

A system that determines data originating from multiple nodes, generates identifiers for network equipment and nodes, updates data with these identifiers, and uses relation criteria to flag potentially malicious traffic by determining common destinations and patterns, employing machine learning to identify malicious data and generate warning signals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current security technologies are used to monitor network traffic, then network operation maintains normal speed and latency, but malicious coordinated traffic from multiple IoT devices goes undetected

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the detection task by assigning unique identifiers to individual data flows and grouping them into aggregate flows. This segmentation allows the system to track individual device behavior while also analyzing coordinated patterns across multiple devices, thereby improving detection accuracy without requiring a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of analysis by creating aggregate data flows that combine multiple individual data flows. This dimensional transformation enables the system to detect coordinated attacks from multiple IoT devices by analyzing patterns across aggregated traffic, rather than only examining individual flows in isolation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of information

If traditional monitoring approaches are applied, then system resources are conserved, but the ability to track coordinated attacks from encrypted data flows is insufficient

Engineering Contradiction:
Improveinformation visibilityVSAvoidprocessing overhead
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The patent creates simplified copies of data flow information in the form of identifiers and aggregate flow representations. These copies enable the system to track and analyze traffic patterns without requiring deep inspection of encrypted payloads, thereby maintaining information visibility while minimizing processing overhead and energy consumption.

Inventive Principle:
Principle #26Copying

3Reliability

If deep packet inspection is used to analyze encrypted traffic, then malicious content can be detected, but network latency and processing time increase significantly

Engineering Contradiction:
Improvemalicious traffic detectionVSAvoiddetection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by assigning identifiers to data flows and creating aggregate flow groupings before detailed analysis is needed. This preliminary structuring of traffic information enables faster subsequent detection of malicious patterns, reducing the time required for malicious traffic detection without requiring deep inspection of every packet.

Inventive Principle:
Principle #10Preliminary action

4Loss of information

If intermediate nodes perform full traffic analysis, then complete visibility into data flows is achieved, but the massive vulnerable surface of billions of connected devices becomes unmanageable

Engineering Contradiction:
Improvetraffic flow visibilityVSAvoidnetwork management complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent extracts essential identification information from complex encrypted traffic flows, creating simplified identifier tags and aggregate flow representations. This extraction process maintains visibility into traffic patterns while removing the complexity of analyzing full encrypted payloads, making network management feasible across billions of connected devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20240364716A1Massive vulnerable surface protection
Publication Date: 2024.10.31 AT&T INTELLECTUAL PROPERTY I L P
  • US20240364716A1 patent drawing
  • US20240364716A1 patent drawing
  • US20240364716A1 patent drawing

AI summary

Network security is applied to identify malicious activity occurring on a network or at network nodes from a coordinated attack. For instance, a device, comprising a memory and a processor, can generate a first flag signal representative of a first flag applicable to first data and a second flag signal representative of a second flag applicable to second data in response to the first and second data being determined to be related and directed to a common destination node using identifiers associated with network equipment.