IoT Intrusion Detection via Statistical Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mechanisms for securing connected IoT devices are inadequate, complex, and require expertise, failing to effectively detect unauthorized intrusions and provide user safety.

Innovation Solution

A method and system that analyze network traffic pattern data using statistical analysis of behavioral and volumetric attributes to detect anomalies, employing a dual path anomaly detection system with Behavioral Attribute Detector (BAD) and Volumetric Attribute Detector (VAD) to identify potential intrusions and automatically manage compromised devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manufacturer default passwords are used to control access to IoT devices, then device access control is implemented, but security effectiveness is insufficient and user safety cannot be ensured

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidaccess control simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables IoT devices to automatically monitor their own network traffic patterns and autonomously detect intrusions by comparing current patterns against established baselines, eliminating the need for complex manual security configuration by users while maintaining high security effectiveness

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors network traffic patterns, compares them against baseline behavior, and automatically responds to deviations by blocking suspicious devices. This closed-loop feedback mechanism provides adaptive security that adjusts to changing threats without requiring user intervention

Inventive Principle:
Principle #23Feedback

2Measurement precision

If statistical analysis of network traffic patterns is performed to detect intrusions, then intrusion detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system replaces complex manual security analysis with automated statistical computing, using algorithms to continuously analyze network traffic patterns and automatically identify intrusions based on deviations from baseline behavior, thereby achieving high detection accuracy without increasing user-facing system complexity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If automated anomaly detection system is implemented to monitor IoT devices, then intrusion detection capability is enhanced, but computational resources and processing time increase

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system focuses computational resources on detecting only the most significant deviations from baseline network traffic patterns, rather than analyzing every aspect of device behavior in equal detail. This selective monitoring approach maintains high intrusion detection capability while reducing overall computational resource consumption

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11848950B2Method for protecting IoT devices from intrusions by performing statistical analysis
Publication Date: 2023.12.19 GRYPHON ONLINE SAFETY INC
  • US11848950B2 patent drawing
  • US11848950B2 patent drawing
  • US11848950B2 patent drawing

AI summary

Various embodiments provide an approach to detect intrusion of connected IoT devices. In operation, features associated with behavioral attributes as well as volumetric attributes of network data patterns of different IoT devices is analyzed by means of statistical analysis to determine deviation from normal operation data traffic patterns to detect anomalous operations and possible intrusions. Data from multiple networks and devices is combined in the cloud to provide for improved base models for statistical analysis.