Learning Machine Attack Mitigation in Low Power Lossy Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Low Power and Lossy Networks (LLNs), such as IoT networks, face challenges in routing, Quality of Service (QoS), security, network management, and traffic engineering due to their complex nature, including lossy links, low bandwidth, and limited resources, making it difficult to efficiently manage and predict network behavior using traditional approaches.

Innovation Solution

The implementation of learning machines that can analyze network traffic data to predict the probability of nodes under attack and mitigate such attacks by rerouting traffic through alternative paths without altering the existing routing topology, using a closed-loop control mechanism and machine learning algorithms like Artificial Neural Networks (ANNs) to detect and respond to subtle changes in network behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional routing approaches are used in LLNs, then the routing topology remains simple and manageable, but the network cannot effectively predict or respond to attacks and exhibits routing oscillations under attack conditions

Engineering Contradiction:
Improvenetwork stability under attackVSAvoidrouting management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The learning machine performs preliminary analysis of network traffic data to predict potential attacks before they cause routing oscillations. By continuously monitoring traffic patterns and predicting attack probabilities, the system prepares alternative routes in advance, enabling proactive mitigation rather than reactive response to routing failures

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A learning machine acts as an intermediary between network traffic monitoring and routing decisions. The learning machine analyzes traffic data, predicts attacks, and generates predictions that guide routing adjustments, serving as an intelligent mediator that translates raw traffic data into actionable routing intelligence without requiring direct complex interactions between monitoring and routing functions

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If learning machines are deployed to predict attacks in real-time, then attack detection accuracy improves, but the processing requirements and energy consumption increase

Engineering Contradiction:
Improveattack prediction accuracyVSAvoidnode processing energy
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The learning machine focuses on analyzing only the most relevant traffic features and parameters necessary for attack prediction, rather than processing all possible network data. This selective analysis approach achieves sufficient prediction accuracy while minimizing the computational load and energy consumption at network nodes

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The learning machine is deployed in a distributed manner across network nodes, enabling each node to independently perform local traffic analysis and attack prediction. This self-service approach eliminates the need for centralized processing, reducing overall network energy consumption while maintaining prediction capabilities at the edge of the network

Inventive Principle:
Principle #25Self-service

3Reliability

If alternative routes are dynamically selected to mitigate attacks, then network resilience improves, but routing oscillations may occur without proper control

Engineering Contradiction:
Improvenetwork resilienceVSAvoidrouting topology stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The system implements continuous feedback loops where the learning machine monitors network traffic, predicts attacks, and adjusts routing decisions in real-time. The routing adjustments are fed back into the learning machine for continuous validation and refinement, creating a closed-loop control system that maintains network resilience while preventing routing oscillations through adaptive stabilization

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The routing topology is made dynamic and adaptive, allowing the network to transition between different routing states based on predicted attack conditions. The learning machine enables the routing structure to flexibly adjust to threats while maintaining overall stability through controlled transitions, preventing rigid topology changes that could cause oscillations

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2890079B1Attack mitigation using learning machines
Publication Date: 2021.03.17 CISCO TECHNOLOGY INC
  • EP2890079B1 patent drawingFigure 1
  • EP2890079B1 patent drawingFigure 2
  • EP2890079B1 patent drawingFigure 3

AI summary

In one embodiment, techniques are shown and described relating to attack mitigation using learning machines. A node may receive network traffic data for a computer network, and then predict a probability that one or more nodes are under attack based on the network traffic data. The node may then decide to mitigate a predicted attack by instructing nodes to forward network traffic on an alternative route without altering an existing routing topology of the computer network to reroute network communication around the one or more nodes under attack, and in response, the node may communicate an attack notification message to the one or more nodes under attack.