IoT Security via Behavioral Policy Grouping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security measures for IoT devices are ineffective due to their diverse configurations and lack of standardization, failing to provide a universal solution for protecting against malicious attacks.

Innovation Solution

The solution involves dynamically generating policy rules based on identified device behavior using machine learning models, grouping similar devices, and applying these policies to monitor and correct non-conforming devices, thereby enhancing security across all IoT devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures are applied to IoT devices, then some devices may be protected, but the measures fail to provide universal protection due to device diversity and lack of standardization

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidapplicability across diverse IoT devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal security policy framework that can be applied across diverse IoT devices by grouping them into categories based on shared characteristics. The system generates policies that are not device-specific but rather category-specific, allowing one policy to protect multiple device types. This resolves the contradiction by making the security solution universally applicable while maintaining effectiveness through behavioral analysis common to each device category.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the parameter of security policies from being device-specific to being behavior-pattern-specific. By using machine learning to identify behavioral trends and grouping devices by similar behaviors rather than by hardware specifications, the system transforms security measures into adaptable parameters that can be applied across diverse devices sharing similar operational patterns.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If behavioral analysis is used to identify device anomalies, then security detection accuracy improves, but the complexity of implementing and maintaining such analysis increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidsecurity system implementation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the complex task of security analysis by dividing devices into distinct groups based on behavioral characteristics. Each group receives tailored security policies generated from its specific behavioral trends. This segmentation reduces implementation complexity by breaking down the universal problem into manageable, category-specific solutions while maintaining high detection accuracy through focused behavioral analysis for each segment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs machine learning models that automatically learn behavioral patterns and generate security policies without requiring manual configuration or expert intervention. The automated policy generation and anomaly detection processes reduce operational complexity by making the system self-configuring and adaptive, allowing it to maintain high detection accuracy while minimizing the burden of implementation and maintenance.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11012476B2Protecting IOT devices by behavioural analysis of their file system
Publication Date: 2021.05.18 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11012476B2 patent drawing
  • US11012476B2 patent drawing
  • US11012476B2 patent drawing

AI summary

Techniques are provided to automatically generate and apply policy rules for IoT devices. Historical data associated with IoT behaviors is obtained, where the historical data describes the file systems and behavior trends for multiple different IoT devices. Groups of the IoT devices are generated by grouping together devices identified as being common with one another based on similarities between their identified behaviors. Policies are then automatically generated for each group, corresponding to the detected behavior trends. Each policy determines how to subsequently monitor any device categorized as belonging to that policy's group and also how to respond when a device is operating abnormally. After a device is characterized as belonging to a group, that device is monitored to determine whether it conforms with the group's policy. Optionally, mitigation operations may be performed when the device is non-conforming.