IoT Gateway Command Control for Real-Time Malicious Packet Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT sensors in open environments are vulnerable to hacking due to minimal security features, leading to potential information leakage and network disruptions, with existing solutions failing to effectively detect and block malicious commands in real-time.

Innovation Solution

A system that reads packets from IoT devices, processes them based on pattern databases, generates session tables, and blocks abnormal access, using a packet blocking rule management flow to preemptively control and learn from malicious commands, thereby minimizing information leakage and network load.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If IoT sensors are mounted with minimal security features to lower manufacturing cost, then manufacturing cost is reduced, but security vulnerability increases making them easily hackable

Engineering Contradiction:
Improvemanufacturing costVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces a gateway device as an intermediary between IoT sensors and the network/server. The gateway performs security functions including packet inspection, command filtering, and anomaly detection, thereby providing security protection without requiring expensive security features in the low-cost IoT sensors themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If software based secure OS or integrity check functions are mounted on IoT sensors to strengthen security, then security protection is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway device serves as an external intermediary that provides security functions (packet filtering, command validation, anomaly detection) without requiring these complex security mechanisms to be embedded within the IoT sensors themselves, thus maintaining sensor simplicity while achieving security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of implementing complete security solutions within each IoT sensor, the patent applies security measures partially at the gateway level, focusing on network traffic and command filtering where security is most needed, while leaving the sensors themselves simple and unburdened by complex security software.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If real-time packet inspection and command filtering are implemented to detect malicious activities, then detection capability is improved, but processing time and system complexity increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The gateway performs partial inspection of packets and commands rather than complete deep packet inspection. It focuses on filtering known malicious patterns, validating command formats, and detecting obvious anomalies, achieving effective detection without the time overhead of exhaustive analysis of every packet.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system maintains pattern databases of known malicious commands and traffic patterns in advance. When packets arrive, the gateway quickly matches them against pre-prepared patterns rather than analyzing each packet from scratch, significantly reducing processing time while maintaining detection capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10069796B2Apparatus and method for providing controlling service for IoT security
Publication Date: 2018.09.04 WINS CO LTD
  • US10069796B2 patent drawing
  • US10069796B2 patent drawing
  • US10069796B2 patent drawing

AI summary

The present invention provides a technology for controlling an IoT gateway command control based packet, preemptively blocking information leakage by detecting/blocking command not allowed through a DB updated by automatically learning new commands recognized based thereon in real-time, determining whether they correspond to each other through search/comparison in each pattern DB corresponding thereto and selectively processing the corresponding packet according to the determined result, generating a session table based on the processed result and determining whether there is an abnormal act by checking a predetermined item, and blocking access to IoT server of abnormal packet by performing a policy according to packet blocking rule management flow.