Hierarchical IoT Intrusion Detection via Segmented Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Internet-connected embedded devices lack robust security protocols due to limited resources, making them vulnerable to attacks, and existing cybersecurity methods are inadequate for scalable and efficient intrusion detection.
Innovation Solution
A cybersecurity framework with a hierarchical intrusion detection system (IDS) comprising local and supervisory IDS, where local IDS builds a statistical model based on device data to detect anomalies and reports to supervisory IDS for decision-making, which applies resilient policies to isolate compromised devices and maintain service continuity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If advanced security programs are implemented in embedded devices, then security reliability is improved, but device resource consumption increases beyond available capacity
Solution Approach 1:
The security system is divided into two segments: a lightweight local IDS running on the resource-constrained embedded device that performs basic anomaly detection using statistical models, and a cloud-based supervisory IDS that handles complex analysis and decision-making. This segmentation allows the embedded device to maintain security functionality without consuming excessive resources.
Solution Approach 2:
A cloud-based supervisory IDS acts as an intermediary between the embedded device and the security analysis infrastructure. The local IDS collects data and sends it to the supervisory IDS, which performs sophisticated threat analysis and returns simplified decisions to the embedded device, enabling advanced security without direct resource burden on the device.
2Difficulty of detecting and measuring
If comprehensive monitoring of all IoT devices is implemented, then intrusion detection capability is improved, but system complexity increases
Solution Approach 1:
The monitoring system is segmented into local monitoring agents on individual devices and a centralized supervisory IDS. Each local agent handles device-specific data collection using simple statistical models, while the supervisory IDS aggregates data from multiple devices and performs comprehensive intrusion detection, distributing complexity across the architecture.
Solution Approach 2:
Each embedded device maintains its own local statistical model and performs self-monitoring of its operational parameters. The device autonomously identifies anomalies in its own behavior and reports only relevant findings to the supervisory IDS, reducing the burden on the central system while maintaining comprehensive monitoring capability.
Data Source
AI summary
Methods, systems and computer program products for intrusion detection are provided. Aspects include receiving, by a processor, internet of things (IoT) device data from each of a plurality of IoT devices, wherein the IoT device data comprises operational data and non-operational data associated with each of the plurality of IoT devices. A security model is built for the plurality of IoT devices based at least in part on the IoT device data, wherein the security model comprises one or more IoT device data ranges. The plurality of IoT devices are monitored to identify a potential intrusion in any of the plurality of IoT devices based at least in part on the IoT device data exceeding any of the one or more IoT device data ranges.


