IoT Network Traffic Filtering for Cybersecurity Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing networks lack effective methods to monitor and manage IoT devices for cybersecurity threats, as users often lack scanners and easy ways to identify infected devices, update them, or prevent malware communication.
Innovation Solution
A network device and method that monitors message traffic, generates reports, and filters messages based on user updates to prevent undesired device activities, using a connectivity management system that includes a gateway or access point to analyze and manage network communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access networks monitor message traffic to detect infected devices, then cybersecurity threat detection is improved, but device complexity and user burden increase
Solution Approach 1:
The patent introduces an intermediary system (access network operator's monitoring infrastructure) that mediates between IoT devices and users. The system collects device information, monitors message traffic, and generates reports without requiring complex scanning software on user devices. This intermediary approach centralizes the complexity in the network infrastructure rather than distributing it to end-user devices.
Solution Approach 2:
The system enables self-service by automatically monitoring devices, generating security reports, and notifying users of potential threats without requiring manual intervention. The access network automatically performs message traffic analysis and device identification, freeing users from the burden of manual security scanning while maintaining high detection capability.
2Measurement precision
If users manually scan each IoT device for malware, then infection detection accuracy is improved, but ease of operation deteriorates
Solution Approach 1:
The patent merges multiple scanning functions into a single centralized monitoring system operated by the access network. Instead of requiring users to scan each device individually with separate tools, the system combines message traffic analysis, device identification, and threat detection into one unified service that automatically monitors all IoT devices on the network.
Solution Approach 2:
The access network operator acts as an intermediary that performs the complex scanning and analysis work on behalf of users. The system collects device information from the network, analyzes message traffic patterns, and generates comprehensive security reports, eliminating the need for users to manually operate multiple scanning tools while maintaining high detection accuracy.
3Reliability
If the network disconnects users with infected devices, then network security is improved, but loss of information and user convenience worsen
Solution Approach 1:
The system performs preliminary detection and notification before disconnection occurs. By monitoring message traffic and generating security reports in advance, the system provides users with information about potential threats, allowing them to take corrective actions (such as device updates or malware removal) before network disconnection becomes necessary, thereby preserving data accessibility while maintaining security.
Data Source
AI summary
A network device for maintaining a communication network is provided. The network device includes a transceiver configured for operable communication with at least one device. The network device also includes a processor including a memory configured to store computer-executable instructions. When executed by the processor the instructions cause the network device to store a plurality of settings for operation of the communication network, monitor message traffic to and from one or more devices on the communication network, generate a report based on the monitored message traffic, transmit, to a user via a user device, the report, receive, from the user via the user device, an update to one or more settings of the plurality of settings for operation of the communication network, monitor additional message traffic, and filter one or more messages of the additional message traffic based on the updated plurality of settings.


