IoT Device Traffic Anomaly Detection in Field Area Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Field Area Networks (FANs) face challenges in detecting anomalies due to their large geographical spread, diverse devices, and lack of controlled perimeters, making them vulnerable to cyberattacks and physical tampering, as traditional security mechanisms are not viable for wireless technologies with no well-controlled signals.

Innovation Solution

A method for detecting traffic anomalies in FANs using Layer 2 traffic by generating whitelists for each device, listing expected peer devices and attributes, and monitoring traffic for discrepancies, allowing for real-time anomaly detection and alerting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional perimeter security control mechanisms (firewalls) are used, then network security is improved, but they are not viable in FANs due to wireless technologies having no well-controlled perimeter

Engineering Contradiction:
Improvenetwork securityVSAvoidapplicability to wireless FANs
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the network security approach from traditional perimeter-based firewalls to device-specific whitelists. Each device in the FAN maintains its own whitelist of authorized peer devices, transforming a centralized perimeter security model into distributed device-level security controls that adapt to wireless network characteristics

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the security parameter from perimeter location (physical/boundary-based) to device identity (logical/address-based). By using MAC address whitelists instead of perimeter firewalls, the system adapts security controls to the stateless, mobile nature of wireless devices in FANs

Inventive Principle:
Principle #35Parameter changes

2Area of stationary object

If devices are widely distributed over large geographical areas, then network coverage is improved, but vulnerability to cyberattacks and physical tampering increases

Engineering Contradiction:
Improvenetwork coverage areaVSAvoidcyberattack vulnerability
Core Design Contradiction:
Area of stationary objectVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by pre-establishing whitelists of authorized peer devices for each device in the FAN. These whitelists are configured in advance and used to validate incoming traffic before processing, enabling proactive security validation that prevents unauthorized devices from joining the distributed network

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms through anomaly detection that monitors traffic patterns and compares them against expected behavior defined in whitelists. When deviations are detected, the system generates alerts that provide feedback about potential security threats, enabling continuous security validation across the geographically distributed network

Inventive Principle:
Principle #23Feedback

3Difficulty of detecting and measuring

If Layer 2 traffic monitoring is implemented, then anomaly detection capability is improved, but complexity of the security system increases

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidsecurity system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent extracts the essential security validation function from complex security appliances and implements it through simple MAC address whitelist comparisons. By focusing only on Layer 2 MAC address validation rather than comprehensive deep packet inspection, the system achieves effective anomaly detection with minimal added complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses simple, lightweight whitelist data structures that can be quickly generated and updated without requiring complex security infrastructure. The whitelists are essentially simple lists of MAC addresses that can be stored in minimal memory and processed with basic comparison operations, avoiding the need for expensive, complex security appliances

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS11032302B2Traffic anomaly detection for IoT devices in field area network
Publication Date: 2021.06.08 PERSPECTA LABS INC
  • US11032302B2 patent drawing
  • US11032302B2 patent drawing
  • US11032302B2 patent drawing

AI summary

A method, computer system, and computer program product that generates a whitelist for each subject device in a field area network (FAN). The whitelist includes one or more whitelist entries corresponding to one or more peer devices in the same FAN communicating with the subject device. Each whitelist entry includes one or more attribute values expected in respective traffic between the subject device and each peer device that is represented by a respective whitelist entry. The traffic in the FAN is monitored at one or more points of the FAN for anomaly by use of the whitelist.