IoT Edge Core-Set Generation for Cyberattack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In high-scale IoT networks, detecting cyberattacks or operational issues in a timely manner is challenging due to the large number of devices managed by a single central system, which can jeopardize network health and delay security issue detection.

Innovation Solution

Implementing a method where IoT devices and intermediate devices perform data preprocessing, anomaly detection, and outlier identification using machine learning algorithms, compressing data records, and generating a core-set to reduce network traffic and facilitate faster detection of cyberattacks or operational issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single central system manages security for a large network of IoT devices, then security management is centralized and simplified, but detection time increases and network health may be jeopardized

Engineering Contradiction:
Improvesecurity management complexityVSAvoiddetection time
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The patent segments the centralized security management system into distributed edge computing nodes deployed at network perimeters and within IoT devices. These edge nodes perform local anomaly detection and preprocessing, dividing the security management workload across multiple locations rather than relying on a single central system, thereby reducing detection time while maintaining simplified security policies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by performing anomaly detection and data preprocessing at the edge before data reaches the central system. Edge nodes continuously monitor and analyze IoT device behavior in real-time, identifying and filtering anomalies proactively. This preliminary security analysis reduces the burden on the central system and accelerates detection without requiring complex centralized processing.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a single central system monitors all IoT devices, then security policies are uniformly enforced, but the number of tasks and alerts overwhelms the system

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidsystem processing capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent divides the monitoring and enforcement tasks into segments handled by edge nodes and the central system. Edge nodes perform local anomaly detection, preliminary classification, and filtering of security events. The central system receives only processed alerts and high-priority anomalies, maintaining uniform security policy enforcement while avoiding overload from processing all raw device data centrally.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces edge computing nodes as intermediaries between IoT devices and the central security system. These intermediaries perform data preprocessing, anomaly filtering, and preliminary analysis, reducing the volume of tasks and alerts reaching the central system. The intermediaries ensure security policies are enforced consistently while protecting the central system from being overwhelmed by raw device data.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If all IoT device data is transmitted to the central system, then complete security analysis is possible, but network traffic increases significantly

Engineering Contradiction:
Improvesecurity analysis accuracyVSAvoidnetwork traffic
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The patent extracts and removes redundant, normal, or low-priority data at the edge before transmission to the central system. Edge nodes perform data filtering, aggregation, and preprocessing, extracting only meaningful anomalies and security-relevant events. This reduces network traffic significantly while preserving the precision needed for accurate security analysis at the central system.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary data processing, filtering, and anomaly detection at the edge before data leaves IoT devices. By conducting preliminary analysis locally, the system transmits only processed, high-value security data to the central system, maintaining complete security analysis capability while minimizing network traffic and energy consumption.

Inventive Principle:
Principle #10Preliminary action

4Loss of time

If multiple intermediate devices are deployed for processing, then detection speed increases, but device complexity and deployment difficulty increase

Engineering Contradiction:
Improvedetection speedVSAvoidsystem architecture complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent designs edge computing nodes with universal, multi-functional capabilities that can be deployed at various network locations (perimeters, gateways, or within IoT devices). These nodes perform multiple functions including data collection, preprocessing, anomaly detection, and local policy enforcement, reducing the need for specialized devices at each location and simplifying deployment while maintaining fast detection speed.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11570187B1Detection of cyberattacks and operational issues of internet of things devices
Publication Date: 2023.01.31 SHIELDIOT LTD
  • US11570187B1 patent drawing
  • US11570187B1 patent drawing
  • US11570187B1 patent drawing

AI summary

There may be provided a method for detecting a cyberattack or an operational issue, the method may include generating, by an IOT device or by an intermediate device located upstream to the IOT device and downstream to a computerized system, a first core-set, wherein the core-set comprises weighted records that are an approximation of a first data set related to a behavior of the IOT device; sending to the computerized system the first core-set; and finding, by the computerized system, outliers in the first core-set, and labeling the outliers as cyber attacks or operational events by the relations between the outliers and a second dataset of cluster centroid indicative of cyber attacks or operational events.