M2M Security System Traffic Pattern Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for Embedded Mobile (EM) or Machine to Machine (M2M) security in communications networks face challenges in identifying and mitigating compromised M2M devices, particularly due to the autonomous and unsecured nature of these devices, remote accessibility, long-term deployment, and limited software capabilities, which poses significant security threats.

Innovation Solution

A security system that captures and analyzes data traffic to dynamically identify M2M devices by examining unique identifiers and behavioral patterns, using feature extraction to differentiate between human and machine-generated traffic, and applying security measures to detect and mitigate abnormal patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If M2M devices are deployed autonomously without direct human control, then device deployment scale and productivity are improved, but security vulnerability and reliability deteriorate

Engineering Contradiction:
Improvedevice deployment scaleVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements autonomous security monitoring where the network security service automatically captures, analyzes, and responds to M2M device traffic patterns without human intervention. The system self-identifies M2M devices, detects anomalies, and triggers mitigation actions autonomously, allowing large-scale deployment while maintaining security through automated oversight.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors M2M device traffic patterns and uses this feedback to dynamically adjust security measures. By analyzing captured traffic data and comparing it against established patterns, the system can detect deviations indicating compromise and respond with appropriate mitigation actions, creating a closed-loop security system that adapts to emerging threats.

Inventive Principle:
Principle #23Feedback

2Productivity

If M2M devices are located remotely for widespread deployment, then network coverage and productivity are improved, but cost of investigation and repair increases

Engineering Contradiction:
Improvenetwork coverageVSAvoidcost of investigation and repair
Core Design Contradiction:
ProductivityVSEase of repair

Solution Approach 1:

The system performs preliminary security analysis by continuously capturing and analyzing M2M device traffic patterns before compromise occurs. By establishing baseline patterns and detecting anomalies early, the system enables proactive identification of security issues, allowing remote devices to be monitored and secured without requiring physical access for investigation or repair.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces physical inspection and manual repair mechanisms with automated electronic monitoring and analysis. By using network-based traffic capture and pattern analysis, the system can investigate and diagnose security issues with remote M2M devices without requiring physical access, significantly reducing investigation and repair costs while maintaining wide network coverage.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of manufacture

If M2M devices have limited software capability, then device simplicity and ease of manufacture are improved, but ability to embed security software deteriorates

Engineering Contradiction:
Improvedevice simplicityVSAvoidability to embed security software
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system introduces a network-based security service as an intermediary that provides security functionality external to the M2M devices themselves. Instead of requiring complex security software embedded in resource-constrained devices, the security capture, analysis, and response functions are performed by a dedicated network service that has full computational capabilities, thus maintaining device simplicity while ensuring robust security.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If static pre-configured systems are used for M2M communications, then system simplicity and ease of operation are improved, but ability to analyze and identify devices for different traffic data deteriorates

Engineering Contradiction:
Improvesystem simplicityVSAvoidability to analyze and identify devices
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system transitions from static pre-configured security rules to dynamic pattern-based identification. By continuously capturing M2M device traffic and analyzing behavioral patterns, the system adapts to different device types and communication patterns in real-time. This dynamic approach maintains operational simplicity through automated pattern recognition while significantly improving the ability to identify and analyze diverse M2M devices based on their unique traffic characteristics.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9813433B2System and method for embedded mobile (EM)/machine to machine (M2M) security, pattern detection, mitigation
Publication Date: 2017.11.07 ADAPTIVE MOBILE SECURITY
  • US9813433B2 patent drawing
  • US9813433B2 patent drawing
  • US9813433B2 patent drawing

AI summary

The invention provides a security system and method for use in a communications network, said network comprising means to allow a plurality of devices to communicate over the network wherein at least one device is a machine to machine (M2M) operated device and at least one other device is a human operated device, said security system comprising: means to capture data traffic originating from the plurality of devices on the network; means for analysing the data traffic; and means for identifying at least one of the M2M operated devices on the network wherein the system is configured to dynamically adapt to different data traffic patterns on the network.