IoT Security via Edge-Cloud Segmentation and Lightweight ML
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IoT devices lack effective features to prevent, mitigate, or recover from cyberattacks, due to limited memory and compute resources.
Innovation Solution
A system and method utilizing machine learning and a set of rules to enhance device security, which acquires log data from IoT devices, prepares a feature set, and applies incident detection rules and ML models to detect and mitigate security incidents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If machine learning models and incident detection rules are deployed on IoT devices, then security detection and mitigation capability is improved, but device complexity increases
Solution Approach 1:
The system segments security functions by deploying lightweight ML models and detection rules specifically on edge devices, while centralizing heavy data processing and analysis in cloud servers. This segmentation allows edge devices to perform basic security detection without requiring full security operation center capabilities, thus improving security capability while managing complexity through functional division.
Solution Approach 2:
The patent introduces a cloud-based security operation center as an intermediary between edge devices and the broader security ecosystem. This intermediary receives log data from edge devices, performs comprehensive analysis using advanced ML models, and provides guidance for incident response. This mediator approach allows edge devices to maintain simplicity while gaining access to advanced security capabilities through the cloud.
2Reliability
If comprehensive security features are installed on IoT devices, then security against cyberattacks is improved, but memory and compute resources are consumed
Solution Approach 1:
The system applies partial action by implementing only the essential security functions on edge devices - lightweight ML models for anomaly detection and incident response rules - rather than deploying comprehensive security suites. This partial implementation provides sufficient security protection for most IoT devices while consuming minimal compute resources, reserving heavy processing for cloud-based systems when needed.
Solution Approach 2:
The patent employs simplified, lightweight ML models that can be easily deployed and updated on edge devices without requiring substantial computational power. These models are designed to be computationally efficient, similar to using simpler, less expensive objects that achieve the necessary function without excessive resource consumption, allowing security features to be added without proportionally increasing hardware requirements.
3Loss of time
If incident detection rules and ML models are applied locally on devices, then response time is improved, but device complexity and resource requirements increase
Solution Approach 1:
The system segments processing tasks by performing quick local evaluations using simplified detection rules and lightweight ML models on edge devices for immediate response, while reserving complex analysis and decision-making for cloud-based security operation centers. This segmentation enables fast local response to common incidents while maintaining complexity management through hierarchical processing.
Solution Approach 2:
The patent implements preliminary action by pre-deploying simplified detection rules and trained lightweight ML models on edge devices before incidents occur. These pre-configured systems can immediately detect and respond to known attack patterns without requiring complex real-time analysis, thus reducing response time while keeping processing complexity low. Complex analysis is performed preliminarily in the cloud and results are cached for future use.
Data Source
AI summary
A system and method for enhancement of device security using machine learning and a set of rules is provided. The system acquires log data from an electronic device configured to communicate data via a network. The system prepares a feature set based on the log data. The feature set corresponds to one or more parameters associated with a cybersecurity of the electronic device. The system determines security incidents associated with the electronic device based on at least one of an application of one or more incident detection rules and/or one or more ML models on the feature set. The system collects information associated with the determined security incidents and determines a set of measures to be implemented on the electronic device to mitigate or prevent issues associated with the security incidents. Thereafter, the system controls execution of the determined set of measures on the electronic device.


