IoT Defense Server Using Pre-Stored Attack Scenarios

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices are vulnerable to attacks due to lack of security knowledge among normal users, and existing servers struggle to effectively defend against malicious codes injected in a step-by-step manner, making it difficult for users to identify and counter such threats.

Innovation Solution

A server system that communicates with IoT devices and electronic apparatuses to receive alerts about attacks, identifies malicious codes based on pre-stored scenarios, and transmits information to user terminals or IoT devices for defense, including guide information to block network connections and defend against identified threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a server stores and analyzes detailed attack scenario information to identify malicious codes, then the accuracy of malicious code identification is improved, but the device complexity and processing time increase

Engineering Contradiction:
Improvemalicious code identification accuracyVSAvoidserver system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The server pre-stores multiple attack scenarios with their characteristic patterns before actual attacks occur. When an attack is detected, the server compares the actual attack alerts against these pre-stored scenarios to quickly identify the malicious code type, avoiding the need for complex real-time analysis of all possible attack vectors.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The attack identification process is divided into discrete stages corresponding to different attack scenarios (e.g., initial access, credential theft, malicious code injection). Each scenario is stored as a separate structured record with specific alert patterns, allowing the server to systematically match actual attacks against individual scenario components rather than analyzing the entire attack spectrum simultaneously.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If the server provides comprehensive defense guides and attack information to users, then the ease of operation for normal users is improved, but the loss of information and data processing burden increase

Engineering Contradiction:
Improveuser defense capabilityVSAvoidinformation processing load
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The server acts as an intermediary between the complex attack detection system and the end user. It receives detailed attack alerts from the electronic apparatus, processes this information against pre-stored scenarios, and transforms it into simplified defense guides and actionable recommendations that normal users can easily understand and implement without needing to comprehend the underlying technical details.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system automatically generates and transmits defense guides to users based on the detected attack scenarios, eliminating the need for users to manually analyze attack data or search for defense information. The server self-services by providing context-specific recommendations tailored to the actual attack being detected.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3649569B1Server and method for defending malicious code using same
Publication Date: 2023.01.11 SAMSUNG ELECTRONICS CO LTD
  • EP3649569B1 patent drawingFigure 1~2
  • EP3649569B1 patent drawingFigure 3a~3b
  • EP3649569B1 patent drawingFigure 4a

AI summary

A server is provided. The server includes a communication interface configured to communicate with an electronic apparatus connected to an Internet of things (IoT) device, a storage configured to store a scenario about an attack received by the IoT device from an external apparatus by stages and information relating to a malicious code corresponding to the scenario, and a processor configured to, based on the IoT device being attacked by the external apparatus over at least one step through the electronic apparatus, receive, from the electronic apparatus, an alert for an attack received by stages, and to identify information relating to a malicious code corresponding to at least one alert received from the electronic apparatus based on the pre-stored scenario.