IoT Network Anomaly Detection Using Social Network Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation systems face inefficiencies in detecting network vulnerabilities and security threats due to the complexity of analyzing historical data to determine predefined network rules, which are not updated in real-time, leading to potential data breaches and security threats.

Innovation Solution

An anomaly detection system that generates a network model based on communication metrics to identify anomalies in real-time, using actor and social network models, and entropy calculations, allowing for continuous learning and adaptation without relying on historical data, and providing proactive measures to secure the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If historical data analysis is used to determine predefined network rules, then network security detection capability is improved, but system complexity and processing time increase significantly

Engineering Contradiction:
Improvenetwork security detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by continuously learning and updating network communication patterns in the background before actual security threats occur. The network model is proactively trained on historical traffic data and continuously adapted, so that when anomalies need detection, the system already has an updated baseline to compare against, eliminating the need for complex real-time historical analysis during security events.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a simplified copy or representation of the network - specifically, a learned network model that captures essential communication patterns. Instead of analyzing raw historical data directly during security detection, the system uses this pre-processed model copy, which contains distilled patterns and behaviors, making detection faster and less complex while maintaining reliability.

Inventive Principle:
Principle #26Copying

2Speed

If predefined network rules are used for anomaly detection, then detection speed is improved, but adaptability to new threats deteriorates

Engineering Contradiction:
Improvedetection speedVSAvoidadaptability to new threats
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

The system implements dynamics by making the network model continuously adaptive rather than static. The model is regularly retrained on new network traffic data, allowing it to evolve and adapt to new communication patterns and threats. This dynamic updating enables the system to maintain both fast detection speeds (by using the current model) and high adaptability (by continuously learning new patterns).

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where detected anomalies and new network traffic continuously feed back into the model training process. This feedback loop allows the network model to learn from actual network behavior and adjust its patterns accordingly, ensuring both rapid detection of current threats and adaptability to emerging threat types.

Inventive Principle:
Principle #23Feedback

3Loss of time

If real-time anomaly detection is implemented, then security response time is improved, but computational resource consumption increases

Engineering Contradiction:
Improvesecurity response timeVSAvoidcomputational resource consumption
Core Design Contradiction:
Loss of timeVSUse of energy by moving object

Solution Approach 1:

The system performs computationally intensive work in advance by continuously training and updating the network model in the background using historical and current traffic data. This preliminary action ensures that when real-time anomaly detection is needed, the model is already prepared, and detection can proceed efficiently by comparing current traffic against the pre-trained model, significantly reducing real-time computational requirements.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses a learned network model as a simplified copy that encapsulates complex patterns. Instead of performing complex real-time analysis of raw network traffic, the system compares traffic against this pre-processed model copy, which contains distilled patterns and relationships. This copying approach enables fast real-time detection with minimal computational resources.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12088614B2Systems and methods for detecting anomalies in network communication
Publication Date: 2024.09.10 ROCKWELL AUTOMATION TECH INC
  • US12088614B2 patent drawing
  • US12088614B2 patent drawing
  • US12088614B2 patent drawing

AI summary

Systems and methods for detecting anomalies in network communication in an industrial automation system. An anomaly detection system, a decentralized system, may identify IoT devices within the network communication and corresponding communication metrics. Using the communication metrics between the identified IoT devices, the anomaly detection system may generate a social network model that is indicative of expected network communication properties. By analyzing social network metrics and overall entropy of the network communication in real time, the anomaly detection system may identify anomalies that may be associated with potential network vulnerabilities.