LAN Agent Device Profiling for IoT Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions for home networks, particularly those involving IoT devices, are inadequate in identifying and protecting vulnerable devices due to limited processing and storage capacities, and often rely on signature-based antivirus methods that fail to detect new threats, with users being desensitized by frequent warning prompts and unable to decrypt SSL/HTTPS traffic without breaking security trust.

Innovation Solution

A system comprising a local area network (LAN) agent that monitors traffic, generates fingerprint and telemetry data for LAN devices, and sends this data to a cloud server to create device profiles, allowing for identification of anomalous behavior and configuration of firewalls to block malicious traffic, while also performing network security scans and threat detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If NAT firewall is used to block incoming connections, then network security is improved, but outgoing connections to malicious sites cannot be blocked

Engineering Contradiction:
Improvenetwork securityVSAvoidability to block malicious traffic
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of only blocking incoming connections at the network perimeter, the patent inverts the approach by monitoring and controlling outgoing connections from internal devices. The system examines outbound traffic from LAN devices to detect and block connections to malicious external sites, thereby preventing infection vectors that NAT firewalls cannot stop.

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If antivirus software is deployed on personal computers, then device protection is improved, but it is not feasible on IoT devices with limited resources

Engineering Contradiction:
Improvedevice protectionVSAvoidresource requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network-level intermediary system that performs security scanning and monitoring functions centrally, rather than requiring heavy antivirus software on each endpoint device. This mediator system analyzes traffic and device behavior to provide protection for resource-constrained IoT devices without burdening their limited processing and storage capacities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If signature-based antivirus is used to detect threats, then known threats are blocked, but new/unique threats are not identified

Engineering Contradiction:
Improvethreat detectionVSAvoidability to detect new threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary scanning and behavior analysis on devices and traffic before threats can execute or spread. By continuously monitoring device behavior patterns, network traffic, and vulnerability states in advance, the system can detect and respond to both known and novel threats before they cause harm, rather than relying solely on post-infection signature matching.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If frequent warning prompts are displayed to users, then security awareness is improved, but users become desensitized and click allow to dismiss prompts

Engineering Contradiction:
Improveuser security awarenessVSAvoiduser response behavior
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements an intelligent feedback system that adapts warning prompt frequency and intensity based on user responses and threat severity. Rather than displaying frequent generic prompts that cause desensitization, the system provides targeted alerts for high-risk situations and learns from user behavior to optimize security communications, maintaining awareness without causing alert fatigue.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11616793B2System and method for device context and device security
Publication Date: 2023.03.28 MINIM INC
  • US11616793B2 patent drawing
  • US11616793B2 patent drawing
  • US11616793B2 patent drawing

AI summary

A system includes local area network (LAN) devices in communication with network devices external to the LAN. An agent in the LAN examines traffic between LAN devices and external devices. The agent executes scans of the LAN devices, generates fingerprint and telemetry data for the LAN devices, and sends the telemetry data and the fingerprint data to a cloud server external to the LAN. The cloud server receives telemetry data and fingerprint data and updates a device attribute database with fingerprints and/or device profiles for the LAN devices to identify anomalous behavior of the LAN devices.