IoT Ephemeral-Port Monitoring for Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for detecting security attacks on IoT devices via communication fail to recognize attacks made on ephemeral ports, which are commonly used by IoT devices instead of well-known ports, leading to undetected security breaches.

Innovation Solution

A detection system that includes a monitor to track communications from terminals to client devices, a determiner to identify attacks on ephemeral ports, and an outputter to report the results, enabling detection of security attacks on IoT devices by monitoring communications to and from ephemeral ports.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional server security attack detection methods are used, then detection simplicity is maintained, but detection accuracy for IoT devices deteriorates because IoT devices use ephemeral ports instead of well-known ports

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The detection system changes the monitoring parameter from well-known ports to ephemeral ports. By detecting communication packets targeting ephemeral ports of IoT devices, the system adapts to the port usage behavior of modern IoT devices and achieves accurate detection without requiring complex analysis of multiple port types

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The detection system segments the detection function into two independent parts: (1) monitoring communication packets to/from ephemeral ports, and (2) determining whether the monitored communication constitutes an attack. This segmentation allows each part to be optimized independently, improving overall detection accuracy while maintaining system simplicity

Inventive Principle:
Principle #1Segmentation

2Reliability

If monitoring of all communications is performed to detect attacks, then detection capability improves, but system complexity and processing load increase

Engineering Contradiction:
Improveattack detection capabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The detection system extracts only the essential information needed for attack detection from the communication packets - specifically, whether the packet is directed to an ephemeral port of an IoT device. By focusing only on this critical parameter rather than analyzing all packet contents, the system achieves reliable attack detection with minimal processing complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250286901A1Detection system, detection method, and recording medium
Publication Date: 2025.09.11 PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
  • US20250286901A1 patent drawing
  • US20250286901A1 patent drawing
  • US20250286901A1 patent drawing

AI summary

A detection system includes: an internal communication monitor that at least monitors a first communication performed from a terminal to a device; a determiner that determines whether the first communication monitored by the internal communication monitor includes an attack made on the device by the terminal; and an outputter that outputs information indicating a result of the determining by the determiner. When the determiner determines that the first communication is from the terminal to an ephemeral port of the device, the determiner determines that the first communication includes the attack.