IoT Malware Classification via Network Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices pose a challenge for traditional security measures due to their proprietary firmware and closed interfaces, making it difficult to detect and classify malware activity effectively in enterprise environments.

Innovation Solution

A network device, such as a network switch, is used to analyze and classify IoT device network traffic using pre-defined parameters and machine learning models, generating alerts for remedial actions like power shutdown or retraining the model based on deviation thresholds.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures are used on IoT devices, then security enforcement is straightforward, but IoT devices cannot be effectively secured due to proprietary firmware and closed interfaces

Engineering Contradiction:
Improvesecurity enforcementVSAvoidcompatibility with IoT devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a network device as an intermediary between the security system and IoT devices. This mediator performs malware classification by analyzing network traffic parameters from IoT devices without requiring direct access to the devices themselves, thus overcoming the closed interface limitation while maintaining security enforcement capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical security enforcement methods (which require direct device access and installation) with a network-based classification system using machine learning models that analyze traffic patterns, enabling security without physical or interface access to IoT devices

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If network traffic analysis is performed using machine learning models, then malware classification accuracy is improved, but computational resources and complexity increase

Engineering Contradiction:
Improvemalware classification accuracyVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts and analyzes only specific pre-defined network traffic parameters rather than examining all possible traffic characteristics. This partial analysis approach achieves effective malware classification while significantly reducing computational complexity compared to comprehensive traffic analysis

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent transforms raw network traffic data into specific extracted parameters that are optimized for malware classification. By changing the representation from raw traffic to curated parameters, the system achieves high classification accuracy with reduced computational burden

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12101339B2IoT malware classification at a network device
Publication Date: 2024.09.24 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12101339B2 patent drawing
  • US12101339B2 patent drawing
  • US12101339B2 patent drawing

AI summary

Some examples relate to classifying IoT malware at a network device. An example includes receiving, by a network device, network traffic from an Internet of Things (IoT) device. Network device may analyze network parameters from the network traffic with a machine learning model. In response to analyzing, network device may classify the network traffic into a category of malware activity. Network device may determine an effectiveness of network traffic classification by measuring a deviation of the network parameters from previously trained network parameters that were used for training the machine learning model. In response to a determination that the deviation of the network parameters from the trained network parameters is more than a pre-defined threshold, network device may generate an alert highlighting the deviation, which allows a user to perform a remedial action pertaining to the IoT device.