Cognitive Protection via IoT Sensor Fusion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security software is inadequate in protecting industrial and non-industrial IoT systems from advanced malware threats, as it cannot detect or defend against these threats, which can cause significant physical damage or harm.

Innovation Solution

Implementing a cognitive protection system that uses sensor fusion by combining data from digital and analog sensors through independent channels, where analog sensor data is converted into secondary operational parameters for comparison with primary parameters to detect discrepancies indicative of malware attacks, and trigger shutdowns or alerts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional antivirus software and host-based intrusion prevention systems are used, then basic security protection is provided, but advanced malware threats can circumvent these controls and modify system behavior undetected

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidsecurity system architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments security monitoring into two independent channels: a primary channel that receives operational parameters from the control system, and a secondary channel that receives sensor data from independent sensors. This segmentation allows the system to detect discrepancies between what the control system reports and what independent sensors measure, enabling detection of advanced malware that circumvents traditional security controls.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary comparison mechanism that receives data from both primary and secondary channels and compares the operational parameters. This intermediary analysis layer detects discrepancies without requiring modifications to the control system itself, providing advanced threat detection while maintaining system integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If antivirus signatures are updated to detect new threats, then detection capability improves, but advanced malware with zero-day flaws remains undetected until signatures are available

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidtime to detect new threats
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by deploying independent sensors and establishing a secondary monitoring channel before malware attacks occur. These independent sensors continuously monitor system operations and provide baseline data that can detect anomalies caused by zero-day malware, eliminating the waiting period for signature updates.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback by comparing real-time data from the primary channel (control system reports) with data from the secondary channel (independent sensor measurements). This feedback mechanism immediately identifies discrepancies caused by malware behavior, providing timely detection without relying on delayed signature updates.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If IoT devices are connected to networks for accessibility and control, then system functionality improves, but vulnerability to malware attacks increases

Engineering Contradiction:
ImproveIoT system accessibilityVSAvoidmalware attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the monitoring function into independent sensor channels that operate separately from the networked control system. This segmentation allows the IoT devices to remain fully connected and accessible for normal operations while the independent sensors provide a separate verification path that is not vulnerable to the same network-based malware attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses a composite monitoring approach that combines data from multiple independent sources (primary control system channel and secondary independent sensor channel). This composite structure provides resilience against malware attacks, as the independent sensor data serves as a verification layer that cannot be compromised by the same attacks affecting the control system.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS9817676B2Cognitive protection of critical industrial solutions using IoT sensor fusion
Publication Date: 2017.11.14 MCAFEE LLC
  • US9817676B2 patent drawing
  • US9817676B2 patent drawing
  • US9817676B2 patent drawing

AI summary

A technique for cognitive protection of a system can include digital and analog sensors to measure or calculate operational parameters of a system. Digital sensors may be used to determine measured or primary operational parameters. The analog sensors are used to measure analog sensor information related to operation of the system. Analog sensor information that is measured may be used to calculate secondary operational parameters that includes the same operating parameters as the primary operational parameters. Lockstep analysis may be used to compare the primary operational parameters with the secondary operational parameters so as to determine a discrepancy in the operational parameters in the system.