IoT Traffic Segregation via Dual-Channel Router Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices within private networks often lack adequate security, making them vulnerable to being hijacked for DDoS attacks, which can overwhelm systems and disrupt critical infrastructure, and typical network administrators lack the technical knowledge to detect compromised devices.

Innovation Solution

A private network architecture that includes a network router with a device filter capable of identifying IoT devices through MAC addresses and other unique identifiers, segregating their traffic from non-IoT devices using distinct output channels to prevent DDoS attacks by filtering incoming requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IoT devices are deployed in private networks to provide convenience and automation, then network functionality and user convenience are improved, but network security and vulnerability to DDoS attacks worsen

Engineering Contradiction:
Improvenetwork functionalityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments network traffic into two distinct channels: an IoT channel for Internet-of-Things devices and a non-IoT channel for traditional devices. This segmentation allows the network to maintain functionality from both device types while isolating the security risks associated with IoT devices to a dedicated channel, thereby resolving the contradiction between network versatility and security reliability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary component (the dual-channel router or gateway) that mediates between IoT devices and the rest of the network. This intermediary filters and manages IoT traffic separately, preventing compromised IoT devices from directly impacting network security while still allowing them to contribute to network functionality when legitimate

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network administrators use traditional security measures like firewalls, then some attack mitigation is achieved, but the ability to detect compromised IoT devices worsens due to lack of technical knowledge

Engineering Contradiction:
Improveattack mitigationVSAvoiddetection capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service security mechanisms where the network infrastructure automatically detects and responds to threats from IoT devices without requiring administrator intervention. The system autonomously monitors traffic patterns, identifies compromised devices through anomaly detection, and isolates them to the IoT channel, making security operations effortless for non-expert administrators while maintaining effective attack mitigation

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback loops where the network continuously monitors IoT device behavior and automatically adjusts security measures based on detected patterns. When suspicious activity is detected, the system provides feedback by redirecting traffic or isolating devices, creating a self-regulating security system that operates without requiring administrator technical knowledge while effectively mitigating attacks

Inventive Principle:
Principle #23Feedback

3Productivity

If attackers leverage security vulnerabilities in IoT devices to perform DDoS attacks, then attack effectiveness is improved, but system stability and service availability worsen

Engineering Contradiction:
Improveattack effectivenessVSAvoidsystem stability
Core Design Contradiction:
ProductivityVSStability of the object's composition

Solution Approach 1:

The patent applies preliminary anti-action by proactively identifying and isolating potentially compromised IoT devices before they can be fully leveraged for DDoS attacks. The system pre-establishes separate IoT channels and implements preventive filtering rules that block malicious traffic patterns before they can overwhelm target systems, thereby neutralizing attack effectiveness while preserving system stability

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent extracts potentially harmful IoT traffic from the main network flow by directing it through a separate IoT channel. This extraction removes the harmful elements (compromised device traffic) from the stable network core, allowing the main system to maintain stability even when IoT devices are being exploited for attacks, while still permitting legitimate IoT functionality

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11539741B2Systems and methods for preventing, through machine learning and access filtering, distributed denial of service (“DDoS”) attacks originating from IoT devices
Publication Date: 2022.12.27 BANK OF AMERICA CORP
  • US11539741B2 patent drawing
  • US11539741B2 patent drawing
  • US11539741B2 patent drawing

AI summary

A method for filtering internet traffic is provided. The method may include using a private network for receiving a request message from an electronic device within the private network and identifying the type of the electronic device. When the electronic device is identified as a non-IoT type device, the method may include transmitting the request message through the non-IoT output channel and when the electronic device is identified as an IoT type device the method may include transmitting the request message through the IoT output channel. The method may further include using an IP address filter gateway for filtering incoming traffic to a web server, the filtering may include granting device access to the web server when the request message is received through the non-IoT output channel and denying access to the web server when the request message is received through the IoT output channel.