Centralized Security Threat List for IoT Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Interconnected IoT devices in homes are vulnerable to malicious attacks due to insufficient malware detection capabilities, especially in simple devices that lack the processing power for on-device detection.
Innovation Solution
A control server dynamically tracks and communicates which devices are malicious, adding them to a security threat list and blocking communications, while removing them once a security patch is applied, ensuring safe interactions among trusted devices without requiring complex on-device malware detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If on-device malware detection is implemented, then security detection capability is improved, but device processing requirements increase
Solution Approach 1:
The patent extracts the malware detection function from individual IoT devices and consolidates it into a centralized control server. The control server receives malware detection data from multiple devices, performs centralized analysis, and generates security threat lists that are distributed back to devices. This allows simple IoT devices without sufficient processing power to benefit from advanced malware detection capabilities.
Solution Approach 2:
The control server acts as an intermediary between IoT devices and the malware detection system. Instead of requiring each device to independently detect malware, the control server mediates the detection process by collecting data from devices, performing analysis, and providing security guidance back to devices. This intermediary approach resolves the contradiction by providing detection capability without increasing device complexity.
2Device complexity
If simple IoT devices are used, then device simplicity and cost are improved, but security vulnerability increases
Solution Approach 1:
The patent extracts the security management burden from simple IoT devices and places it on a centralized control server. Devices only need to communicate basic status information and receive security instructions, maintaining their simplicity while benefiting from centralized security management that protects them from vulnerabilities.
Solution Approach 2:
The control server provides universal security protection to multiple different types of IoT devices simultaneously. Instead of requiring each device to have its own security management capabilities, the control server serves multiple devices with a single multi-functional security system, protecting simple devices without adding complexity to them.
3Reliability
If centralized security management is implemented, then overall network security is improved, but communication overhead increases
Solution Approach 1:
The control server implements periodic updates of security threat lists to connected devices. Instead of continuous communication, the system uses periodic batches of security updates, which reduces communication overhead while maintaining effective security management. Devices receive updated threat lists at regular intervals and can operate autonomously between updates.
Solution Approach 2:
Once devices receive security threat lists from the control server, they autonomously filter and block communications from malicious devices without requiring further intervention. This self-service capability reduces ongoing communication overhead, as devices independently enforce security policies rather than requiring continuous centralized management.
Data Source
AI summary
Systems and methods are provided for protecting a plurality of electronic devices via a control server. The control server, for example, can receive one or more indications that a first electronic device is considered malicious and add it to a security threat list. Then the control server can communicate the security threat list to others of the electronic devices, networked for communication with each other, such that the other electronic devices reject all communication from any device listed on the security threat list. Next, upon receiving indication from an approved security patch-providing source that a security patch has been applied to the first electronic device, the control server can remove the first electronic device from the security threat list and communicate the updated security threat list to the other electronic devices indicating that it is safe for these electronic devices to again receive communication from the first electronic device.


