IoT Defense Server Using Pre-Stored Attack Scenarios
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IoT devices are vulnerable to attacks due to lack of security knowledge among normal users, and existing servers struggle to effectively defend against malicious codes injected in a step-by-step manner, making it difficult for users to identify and counter such threats.
Innovation Solution
A server system that communicates with IoT devices and electronic apparatuses to receive alerts about attacks, identifies malicious codes based on pre-stored scenarios, and transmits information to user terminals or IoT devices for defense, including guide information to block network connections and defend against identified threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a server stores and analyzes detailed attack scenario information to identify malicious codes, then the accuracy of malicious code identification is improved, but the device complexity and processing time increase
Solution Approach 1:
The server pre-stores multiple attack scenarios with their characteristic patterns before actual attacks occur. When an attack is detected, the server compares the actual attack alerts against these pre-stored scenarios to quickly identify the malicious code type, avoiding the need for complex real-time analysis of all possible attack vectors.
Solution Approach 2:
The attack identification process is divided into discrete stages corresponding to different attack scenarios (e.g., initial access, credential theft, malicious code injection). Each scenario is stored as a separate structured record with specific alert patterns, allowing the server to systematically match actual attacks against individual scenario components rather than analyzing the entire attack spectrum simultaneously.
2Ease of operation
If the server provides comprehensive defense guides and attack information to users, then the ease of operation for normal users is improved, but the loss of information and data processing burden increase
Solution Approach 1:
The server acts as an intermediary between the complex attack detection system and the end user. It receives detailed attack alerts from the electronic apparatus, processes this information against pre-stored scenarios, and transforms it into simplified defense guides and actionable recommendations that normal users can easily understand and implement without needing to comprehend the underlying technical details.
Solution Approach 2:
The system automatically generates and transmits defense guides to users based on the detected attack scenarios, eliminating the need for users to manually analyze attack data or search for defense information. The server self-services by providing context-specific recommendations tailored to the actual attack being detected.
Data Source
Figure 1~2
Figure 3a~3b
Figure 4a
AI summary
A server is provided. The server includes a communication interface configured to communicate with an electronic apparatus connected to an Internet of things (IoT) device, a storage configured to store a scenario about an attack received by the IoT device from an external apparatus by stages and information relating to a malicious code corresponding to the scenario, and a processor configured to, based on the IoT device being attacked by the external apparatus over at least one step through the electronic apparatus, receive, from the electronic apparatus, an alert for an attack received by stages, and to identify information relating to a malicious code corresponding to at least one alert received from the electronic apparatus based on the pre-stored scenario.