LAN Agent Device Profiling for IoT Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security solutions for home networks, particularly those involving IoT devices, are inadequate in identifying and protecting vulnerable devices due to limited processing and storage capacities, and often rely on signature-based antivirus methods that fail to detect new threats, with users being desensitized by frequent warning prompts and unable to decrypt SSL/HTTPS traffic without breaking security trust.
Innovation Solution
A system comprising a local area network (LAN) agent that monitors traffic, generates fingerprint and telemetry data for LAN devices, and sends this data to a cloud server to create device profiles, allowing for identification of anomalous behavior and configuration of firewalls to block malicious traffic, while also performing network security scans and threat detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If NAT firewall is used to block incoming connections, then network security is improved, but outgoing connections to malicious sites cannot be blocked
Solution Approach 1:
Instead of only blocking incoming connections at the network perimeter, the patent inverts the approach by monitoring and controlling outgoing connections from internal devices. The system examines outbound traffic from LAN devices to detect and block connections to malicious external sites, thereby preventing infection vectors that NAT firewalls cannot stop.
2Reliability
If antivirus software is deployed on personal computers, then device protection is improved, but it is not feasible on IoT devices with limited resources
Solution Approach 1:
The patent introduces a network-level intermediary system that performs security scanning and monitoring functions centrally, rather than requiring heavy antivirus software on each endpoint device. This mediator system analyzes traffic and device behavior to provide protection for resource-constrained IoT devices without burdening their limited processing and storage capacities.
3Reliability
If signature-based antivirus is used to detect threats, then known threats are blocked, but new/unique threats are not identified
Solution Approach 1:
The system performs preliminary scanning and behavior analysis on devices and traffic before threats can execute or spread. By continuously monitoring device behavior patterns, network traffic, and vulnerability states in advance, the system can detect and respond to both known and novel threats before they cause harm, rather than relying solely on post-infection signature matching.
4Reliability
If frequent warning prompts are displayed to users, then security awareness is improved, but users become desensitized and click allow to dismiss prompts
Solution Approach 1:
The patent implements an intelligent feedback system that adapts warning prompt frequency and intensity based on user responses and threat severity. Rather than displaying frequent generic prompts that cause desensitization, the system provides targeted alerts for high-risk situations and learns from user behavior to optimize security communications, maintaining awareness without causing alert fatigue.
Data Source
AI summary
A system includes local area network (LAN) devices in communication with network devices external to the LAN. An agent in the LAN examines traffic between LAN devices and external devices. The agent executes scans of the LAN devices, generates fingerprint and telemetry data for the LAN devices, and sends the telemetry data and the fingerprint data to a cloud server external to the LAN. The cloud server receives telemetry data and fingerprint data and updates a device attribute database with fingerprints and/or device profiles for the LAN devices to identify anomalous behavior of the LAN devices.


