Cloud-Based Malware Detection for IoT Edge Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IoT devices lack robust malware infection detection capabilities due to limited computational power and visibility into network activities, leading to reduced accuracy and effectiveness of existing detection methods.
Innovation Solution
A provider network-based malware infection detection service that utilizes multiple detection mechanisms, confidence levels, and accumulation methods to identify and report infected IoT devices, combining threat intelligence and behavioral patterns to enhance detection accuracy and reduce reliance on manual setup.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If malware infection detection is implemented on IoT devices, then security detection capability is provided, but computational resource consumption increases and accuracy remains insufficient due to limited device power
Solution Approach 1:
The patent introduces a hub device as an intermediary between IoT devices and the provider network. The hub device collects metrics from multiple IoT devices and forwards them to the cloud-based malware infection detection service, eliminating the need for IoT devices to perform complex detection computations locally while still enabling comprehensive security monitoring.
Solution Approach 2:
The patent shifts the detection capability from the device dimension (individual IoT device) to the network dimension (provider network-based service). By moving the detection service to the cloud, the system leverages network-level computational resources and data aggregation across multiple devices to achieve higher detection accuracy without burdening individual constrained devices.
2Measurement precision
If detection parameters are increased to improve accuracy, then detection reliability improves, but device complexity and resource requirements increase
Solution Approach 1:
The patent extracts the complex detection service from the IoT device environment and relocates it to the provider network. The complex detection logic, involving hundreds of millions of parameters and multiple detection mechanisms, is implemented in the cloud where computational resources are abundant, leaving IoT devices with only simple metric collection and transmission functions.
3Reliability
If local detection is performed on IoT devices, then real-time detection is possible, but detection reliability decreases due to limited data and parameters available
Solution Approach 1:
The patent merges data from multiple IoT devices and multiple detection mechanisms at the hub device and provider network level. By aggregating metrics from numerous devices and combining results from various detection approaches (behavioral analysis, threat intelligence, etc.), the system achieves comprehensive data availability and high detection reliability that would be impossible for individual constrained devices.
4Reliability
If multiple detection mechanisms are used to improve accuracy, then detection reliability improves, but system complexity and resource requirements increase
Solution Approach 1:
The hub device serves as an intermediary that manages the complexity of multiple detection mechanisms. It collects metrics from IoT devices, coordinates with the provider network-based detection service, and aggregates results from multiple detection approaches, thereby handling system complexity centrally rather than at each constrained IoT device.
Data Source
AI summary
Various embodiments of apparatuses and methods for malware infection detection for edge devices, such as IoT (“Internet of Things”) devices, are described. In some embodiments, a malware infection detection service receives data from a plurality of edge devices of a remote network. It can identify a variety of different detection mechanisms to detect whether an edge device is potentially infected with malware, and determine confidence levels for the different detection mechanisms. Using the detection mechanisms with the received data, it can determine one or more findings that an edge device is potentially infected with malware. It can then determine a confidence level for each finding. It can then determine an accumulated confidence, based on the confidence levels of the detection mechanisms and the findings. The malware infection detection service might then identify one or more of the edge devices as potentially being infected by malware based on the accumulated confidence.


