IoT Network Traffic Filtering for Malware Communication Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing networks lack effective systems to monitor and manage IoT devices for cybersecurity threats, as users often lack scanners and easy methods to identify infected devices, update them, or prevent malware communication.

Innovation Solution

A network device and method that monitors message traffic, generates reports, allows user updates, and filters messages based on settings to prevent infected device communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access networks monitor devices to detect cybersecurity threats, then detection capability is improved, but device complexity and operational burden increase

Engineering Contradiction:
Improvecybersecurity threat detectionVSAvoidnetwork management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service by allowing users to easily identify, update, and manage their IoT devices through a user-friendly interface. The network device automatically monitors traffic, generates reports, and filters messages based on user settings, reducing the need for complex manual configuration and expert intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The network device acts as an intermediary between the access network and IoT devices. It automatically monitors message traffic, generates security reports, and filters communications based on user settings, simplifying the overall system architecture and reducing operational complexity while maintaining effective security monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If users are provided with detailed device monitoring capabilities, then detection precision is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedevice infection identificationVSAvoiduser device management
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system creates a simplified copy or representation of complex network device information through user-friendly reports. Instead of presenting raw network data, it generates summarized security reports that easily identify potential infections, making precise detection accessible to users without technical expertise.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system provides self-service capabilities by enabling users to easily monitor their own devices through automated reporting. The network device automatically collects data, generates understandable security reports, and presents them in a user-friendly format, eliminating the need for users to manually configure complex monitoring tools.

Inventive Principle:
Principle #25Self-service

3Productivity

If automatic device filtering is implemented, then productivity is improved, but device complexity increases

Engineering Contradiction:
Improvethreat response efficiencyVSAvoidmessage filtering system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary action by pre-configuring filtering rules and automatically generating security reports before threats fully manifest. The network device proactively monitors traffic patterns, identifies potential issues, and filters messages in advance, improving response efficiency without requiring complex real-time decision-making.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where security reports are generated and presented to users, who then provide guidance for filtering decisions. This feedback loop allows the system to automatically adjust filtering rules based on user input and observed behavior, improving productivity through automated responses while keeping the filtering logic simple and adaptable.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12470573B1Systems and methods for managing networks for improved device connectivity
Publication Date: 2025.11.11 CABLE TELEVISION LAB INC
  • US12470573B1 patent drawing
  • US12470573B1 patent drawing
  • US12470573B1 patent drawing

AI summary

A network device for maintaining a communication network is provided. The network device includes a transceiver configured for operable communication with at least one device. The network device also includes a processor including a memory configured to store computer-executable instructions. When executed by the processor the instructions cause the network device to store a plurality of settings for operation of the communication network, monitor message traffic to and from one or more devices on the communication network, generate a report based on the monitored message traffic, transmit, to a user via a user device, the report, receive, from the user via the user device, an update to one or more settings of the plurality of settings for operation of the communication network, monitor additional message traffic, and filter one or more messages of the additional message traffic based on the updated plurality of settings.