IoT Memory Extraction for Cloud Forensics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices are vulnerable to malicious code due to limited processing power, proprietary operating systems, and high costs associated with developing dedicated protection software, making existing protection methods impractical and ineffective in detecting and removing malicious code, especially when attacks occur within encrypted traffic.

Innovation Solution

A system comprising a memory extraction module at each IoT device that sends memory content to an in-cloud server for analysis using static and behavioral methods, performing integrity checks, and providing alerts or updates, which can handle multiple devices efficiently and reduce costs by leveraging cloud resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anti-virus software is used on IoT devices, then protection against malicious code is improved, but device complexity and cost increase significantly

Engineering Contradiction:
Improveprotection against malicious codeVSAvoidcomplexity of protection software
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security analysis function from the IoT device itself and relocates it to a remote server. The memory extraction module retrieves memory content from the IoT device, and the server performs the intensive anti-virus analysis remotely, returning only results to the device. This resolves the contradiction by removing complex protection software from the constrained IoT device while maintaining reliable protection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a remote server as an intermediary between the IoT device and the security analysis process. The server acts as a mediator that receives memory content from the device, performs comprehensive anti-virus scanning, and returns protection results. This intermediary handles the complexity of protection software externally, allowing the IoT device to remain simple while achieving reliable security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dedicated protection software is developed for each proprietary operating system, then protection effectiveness is improved, but development cost and time increase

Engineering Contradiction:
Improveprotection effectivenessVSAvoiddevelopment cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements a universal protection system where a single remote server handles security analysis for multiple proprietary operating systems. The server's anti-virus software is designed to work across different OS types (Android, iOS, proprietary systems), eliminating the need to develop separate protection software for each OS. This resolves the contradiction by providing effective protection across diverse platforms through a single multi-functional solution.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses memory copying as a technique to extract a complete copy of the device's memory state and analyze it remotely. This copy allows the server to simulate and analyze the proprietary operating system environment without needing native software for each OS. The memory copy serves as a portable representation that can be analyzed universally, reducing development costs while maintaining protection effectiveness.

Inventive Principle:
Principle #26Copying

3Speed

If memory analysis is performed locally on IoT devices, then detection speed is improved, but processing power requirements increase beyond device capabilities

Engineering Contradiction:
Improvedetection speedVSAvoidprocessing power
Core Design Contradiction:
SpeedVSPower

Solution Approach 1:

The patent extracts the computationally intensive memory analysis function from the IoT device and relocates it to a remote server with sufficient processing power. The device only performs lightweight memory extraction and transmits data to the server, which handles the heavy lifting of anti-virus scanning. This resolves the contradiction by maintaining fast detection through server-side processing while avoiding the need for high processing power on the constrained IoT device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent shifts the security analysis from the device dimension (local processing) to the network dimension (remote server processing). By moving the analysis to another dimension (the cloud), the system leverages the server's abundant processing power without burdening the IoT device. This dimensional shift resolves the contradiction between detection speed and processing power requirements.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11086993B2System and method for performing on-cloud memory analysis, forensic and security operations on connected devices
Publication Date: 2021.08.10 BG NEGEV TECHNOLOGIES & APPLICATIONS LTD
  • US11086993B2 patent drawing

AI summary

The invention relates to a system for protecting IoT devices from malicious code, which comprises: (a) a memory extracting module at each of said IoT devices, for extracting a copy of at least a portion of the memory content from the IoT device, and sending the same to an in-cloud server; and (b) an in-cloud server for receiving said memory content, and performing an integrity check for a possible existance of malicious code within said memory content.