IoT Device Profiling for Network Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing and securing IoT devices in networks is challenging due to their ability to connect without permission, potential vulnerabilities, and ease of relocation, which complicates device management and increases security risks.
Innovation Solution
A system that detects and analyzes data packets to determine device profiles, identify anomalous behavior, and categorize risk, using classifiers and machine learning to filter, sort, and present device information through a graphical user interface, allowing for real-time monitoring and corrective actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If IoT devices are allowed to connect to the network without explicit permission, then network accessibility and ease of deployment are improved, but network security and device management control deteriorate
Solution Approach 1:
The system performs preliminary actions by establishing a device profile for each IoT device before security policies are enforced. The profile includes expected attributes and values that are determined in advance, allowing the system to proactively evaluate incoming devices and their behaviors against predetermined security criteria, thus maintaining security without hindering deployment ease
Solution Approach 2:
The system implements continuous feedback mechanisms by monitoring IoT device attributes and behaviors in real-time, comparing them against the established device profile. When anomalies are detected (deviations from expected behavior), the system provides feedback through alerts and notifications, enabling dynamic security adjustments while maintaining ease of device connection
2Reliability
If device monitoring and security analysis are implemented in real-time, then network security is improved, but system complexity and computational resources increase
Solution Approach 1:
The system segments the complex security monitoring task into manageable components: device detection, attribute analysis, profile creation, anomaly detection, and alert generation. Each component operates independently but contributes to the overall security function, reducing system complexity while maintaining real-time monitoring capabilities
Solution Approach 2:
The system applies partial action by focusing monitoring efforts on critical device attributes and behaviors rather than analyzing all possible device data. The device profile contains only the most relevant expected attributes, allowing efficient real-time analysis without overwhelming computational requirements
3Measurement precision
If complete device attribute information is required for security assessment, then measurement precision is improved, but processing time and productivity deteriorate
Solution Approach 1:
The system uses partial action by assessing only the most critical device attributes necessary for security evaluation. The device profile contains a selective set of expected attributes that provide sufficient security assessment accuracy without requiring complete device information, thus maintaining fast processing speeds
Solution Approach 2:
The system applies local quality by differentiating the importance of various device attributes. Critical security-related attributes are analyzed with high precision and priority, while less important attributes are either analyzed with lower precision or deferred, optimizing the balance between assessment accuracy and processing speed
Data Source
AI summary
Techniques for determining a device profile and anomalous behavior associated with a device in a network are disclosed. Attribute values associated with a target device are determined based on data packets detected from a network. A subset of a set of classifiers associated with the available attribute values are selected. The attribute values are applied to the selected classifiers to determine a respective candidate device profile. A current device profile is determined for the target device based on the candidate device profiles. The current device profile indicates expected attribute values for the target device. Current attribute values are compared to the expected attribute values to determine whether there is any anomalous behavior associated with the target device.


