IoT Behavioral Analysis for Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices lack sufficient resources to conduct behavioral analysis, leading to difficulties in detecting malicious attacks and malfunctions, especially in environments with many simple devices that have limited capabilities, resulting in costly and time-consuming customer service processes.

Innovation Solution

A distributed architecture where more powerful IoT devices aggregate and analyze behavioral data from simpler devices, enabling detection of anomalies and potential security breaches or malfunctions, allowing for automated customer service and improved security incident responses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If IoT devices are made simpler with limited capabilities, then device complexity and cost are reduced, but the ability to conduct behavioral analysis and detect anomalies deteriorates

Engineering Contradiction:
Improvedevice complexityVSAvoidanomaly detection capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system segments the anomaly detection functionality by separating data collection (performed by simple IoT devices) from data analysis (performed by a centralized server). This allows simple devices to maintain low complexity while the server handles the sophisticated behavioral analysis needed for reliable anomaly detection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A centralized server acts as an intermediary between simple IoT devices and the anomaly detection process. The server aggregates behavioral data from multiple devices and performs comprehensive analysis, enabling simple devices to benefit from advanced detection capabilities without increasing their own complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If behavioral analysis is conducted locally at each IoT device, then detection speed and responsiveness are improved, but resource requirements and device complexity increase

Engineering Contradiction:
Improvedetection speedVSAvoidresource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system segments computational tasks by performing only lightweight data collection and transmission at the device level, while offloading intensive behavioral analysis to the centralized server. This division allows fast local response for data gathering while maintaining energy efficiency by avoiding complex local processing.

Inventive Principle:
Principle #1Segmentation

3Reliability

If more comprehensive behavioral monitoring is implemented, then security and device health detection are improved, but the cost and complexity of customer service processes increase

Engineering Contradiction:
Improvedevice health monitoringVSAvoidcustomer service process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service by implementing automated anomaly detection and alerting. When anomalies are detected through behavioral analysis, the system automatically generates notifications, reducing the need for manual customer service intervention and simplifying support processes while maintaining comprehensive monitoring.

Inventive Principle:
Principle #25Self-service

4Productivity

If automated customer service is implemented, then service speed and efficiency are improved, but the initial system complexity and development cost increase

Engineering Contradiction:
Improvecustomer service efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system implements automated customer service through self-service mechanisms where the behavioral analysis server automatically detects anomalies, generates alerts, and notifies relevant parties. This automation improves service efficiency by eliminating manual intervention while the modular architecture keeps system complexity manageable.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback loops where detected anomalies trigger automated responses and notifications. This feedback mechanism enables efficient automated customer service by continuously monitoring device behavior and automatically initiating appropriate actions or alerts without requiring complex manual service processes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3266159B1Behavioral analysis to automate direct and indirect local monitoring of internet of things device health
Publication Date: 2019.03.20 QUALCOMM INC
  • EP3266159B1 patent drawingFigure 1A
  • EP3266159B1 patent drawingFigure 1B
  • EP3266159B1 patent drawingFigure 1C

AI summary

The disclosure generally relates to behavioral analysis to automate monitoring Internet of Things (IoT) device health in a direct and/or indirect manner. In particular, normal behavior associated with an IoT device in a local IoT network may be modeled such that behaviors observed at the IoT device may be compared to the modeled normal behavior to determine whether the behaviors observed at the IoT device are normal or anomalous. Accordingly, in a distributed IoT environment, more powerful "analyzer" devices can collect behaviors locally observed at other (e.g., simpler) "observer" devices and conduct behavioral analysis across the distributed IoT environment to detect anomalies potentially indicating malicious attacks, malfunctions, or other issues that require customer service and/or further attention. Furthermore, devices with sufficient capabilities may conduct (local) on-device behavioral analysis to detect anomalous conditions without sending locally observed behaviors to another aggregator device and/or analyzer device.