IoT Network Anomaly Detection Using Social Communication Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation systems face inefficiencies in detecting network anomalies due to the complexity of analyzing historical data to determine predefined network rules, which can lead to delayed updates and increased costs, making it challenging to identify and address security threats and vulnerabilities in real-time.

Innovation Solution

The implementation of an anomaly detection system that generates a network model based on communication patterns and metrics, allowing for real-time detection of anomalies without relying on historical data, using actor and social network models to identify deviations and dynamically update the state-space model to improve accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If historical data analysis is used to determine predefined network rules, then detection accuracy may be improved, but detection speed and real-time capability deteriorate

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddetection speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The system performs preliminary actions by continuously learning and updating network communication patterns in the background, building a dynamic baseline of normal behavior before anomalies occur. This allows the system to detect deviations in real-time without requiring historical data analysis at the moment of detection, thus maintaining both accuracy and speed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamics by transitioning from static predefined rules based on historical data to a dynamic model that continuously adapts to changing network patterns. The system learns and updates communication patterns ongoingly, allowing it to respond to new normal behaviors while maintaining detection accuracy without the delays associated with periodic historical analysis.

Inventive Principle:
Principle #15Dynamics

2Reliability

If complex historical data analysis is performed to establish network rules, then detection reliability may improve, but system complexity and processing costs increase

Engineering Contradiction:
Improvedetection reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies self-service by autonomously learning network communication patterns and updating its own detection model without requiring complex external configuration or manual rule establishment. The anomaly detection system automatically adapts to network changes, reducing the need for complex preprocessing and maintenance while maintaining reliable detection through continuous self-learning.

Inventive Principle:
Principle #25Self-service

3Ease of manufacture

If predefined network rules based on historical data are used, then initial detection capability is provided, but adaptability to new communication patterns deteriorates

Engineering Contradiction:
Improveinitial system setupVSAvoidadaptability to new patterns
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The system resolves this contradiction by implementing a dynamic learning mechanism that continuously adapts to new communication patterns. While the system can be initially deployed with basic functionality, it automatically learns and adapts to evolving network behaviors in real-time, maintaining ease of initial setup while achieving high adaptability through ongoing pattern learning and model updates.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3979557A1Systems and method for detecting anomalies in network communication
Publication Date: 2022.04.06 ROCKWELL AUTOMATION TECH INC
  • EP3979557A1 patent drawingFigure 1
  • EP3979557A1 patent drawingFigure 2
  • EP3979557A1 patent drawingFigure 3

AI summary

Systems and method for detecting anomalies in network communication in an industrial automation system. An anomaly detection system, a decentralized system, may identify loT devices within the network communication and corresponding communication metrics. Using the communication metrics between the identified IoT devise, the anomaly detection system may generate a social network model that is indicative of expected network communication properties. By analyzing social network metrics and the overall entropy of the network communication in real time, the anomaly detection system may identify anomalies that may be associated with potential network vulnerabilities.