IoT Risk Scoring Framework for Scalable Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the context of enterprise systems, insider threats and the emerging Internet of Things (IoT) environment, existing technologies fail to effectively monitor and manage risks across a large number of interconnected devices, leading to potential security vulnerabilities due to the sheer volume and complexity of data generated by device-to-device interactions.

Innovation Solution

A risk scoring framework is developed that computes a risk profile and trends across devices and sensors in an IoT environment, incorporating additional risk factors to provide scalable, high-throughput risk management. This framework assigns risk scores based on baseline factors, historical usage, and anomalies, using predictive analytics and machine learning to detect anomalies and manage risks in real-time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional monitoring methods are used to track insider threats and device interactions, then security coverage is limited, but the system cannot scale to handle the huge number of IoT devices and the resulting data volume

Engineering Contradiction:
Improvesecurity monitoring effectivenessVSAvoidsystem scalability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the risk management system into multiple distributed risk computing entities, each responsible for specific devices or device groups. This segmentation allows the system to scale horizontally by adding more computing entities without increasing central system complexity, while maintaining comprehensive security monitoring across all IoT devices through distributed risk score computation and aggregation.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If comprehensive risk factors are collected from all IoT devices, then risk assessment accuracy improves, but data processing time and computational load increase significantly

Engineering Contradiction:
Improverisk assessment accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-computing risk scores for individual devices based on their historical behavior patterns and baseline risk factors. When a new event occurs, the system quickly aggregates pre-computed scores with current event data to generate updated risk assessments, rather than re-analyzing all historical data from scratch. This significantly reduces processing time while maintaining comprehensive risk factor analysis.

Inventive Principle:
Principle #10Preliminary action

3Speed

If real-time risk scoring is computed for all devices, then threat detection speed improves, but the computational resources required become unmanageable at scale

Engineering Contradiction:
Improvethreat detection speedVSAvoidcomputational resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by enabling each risk computing entity to independently compute risk scores for its assigned devices using local data and pre-configured risk models. This distributed approach allows real-time threat detection to occur locally at the edge of the network rather than requiring all devices to communicate with a centralized computing resource, significantly reducing overall computational resource consumption while maintaining fast threat detection capability.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11244270B2Systems, structures, and processes for interconnected devices and risk management
Publication Date: 2022.02.08 ALERT ENTERPRISE
  • US11244270B2 patent drawing
  • US11244270B2 patent drawing
  • US11244270B2 patent drawing

AI summary

Techniques are provided that produce a risk profile consisting of a risk score and trends of risk scores across devices and sensors in a machine-to-machine (M2M) or Internet of things (IOT) environment. For example, a device is assigned a risk score which is based on baseline factors such as expected network packets between two devices, normal network packets, access to critical devices, authorized access requests from one device to another device, normal communications to a device and the critical ports of a device; access to and conflicts across physical, logical, and operational systems; historical and current usage of these systems, data from public sites, and anomalies from normal behavior patterns. Techniques encompass risk management by computing a risk score in a timely fashion in accordance with an architecture that enables achieving the required scaling necessitated by the huge number of devices in the machine-to-machine (M2M) or Internet of things (IOT) environment.