M2M Network Security Monitoring via Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Machine to machine (M2M) and wireless sensor networks have minimal security measures, lacking higher-level security monitoring functions to detect cyber attacks or malware infections, which increases the risk of network disruptions and potential threats such as unauthorized access or false alarms.

Innovation Solution

A method and apparatus for machine to machine network security monitoring that analyzes communications traffic in a communications network to detect potential security threats like denial of service attacks, message replay attacks, malware infections, and device insertion attacks, generating alarms and notifications to subscribers when threats are identified.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If minimal security measures (transport encryption) are implemented in M2M networks, then device complexity is reduced and ease of operation is improved, but security reliability deteriorates due to lack of higher-level security monitoring functions

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security monitoring server as an intermediary component that provides higher-level security monitoring functions. This server analyzes communications traffic between M2M devices, detecting cyber attacks and malware infections without requiring the M2M devices themselves to become more complex. The server acts as a mediator that enhances security reliability while keeping device complexity low.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a new dimension to security by implementing behavioral analysis and pattern recognition capabilities in the security monitoring server. Instead of relying solely on traditional encryption at the device level, the system monitors communications traffic patterns, device behaviors, and network interactions to detect anomalies indicating attacks or malware, thereby enhancing security without increasing device complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If higher-level security monitoring functions are added to detect cyber attacks and malware infections, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security monitoring server serves as an intermediary that centralizes complex security monitoring functions. Rather than embedding complex detection algorithms in each M2M device, the server receives communications traffic from multiple devices and performs centralized analysis for detecting cyber attacks, malware infections, and unauthorized access attempts, thereby improving security reliability without increasing device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments security functions into two layers: basic security measures (transport encryption) implemented at the device level, and advanced security monitoring functions (traffic analysis, attack detection, malware detection) implemented at the server level. This segmentation allows M2M devices to remain simple while the system as a whole achieves high security reliability through the specialized security monitoring server.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9736174B2Method and apparatus for machine to machine network security monitoring in a communications network
Publication Date: 2017.08.15 AT&T INTELLECTUAL PROPERTY I L P
  • US9736174B2 patent drawing
  • US9736174B2 patent drawing
  • US9736174B2 patent drawing

AI summary

A method, non-transitory computer readable medium and apparatus for providing network security monitoring in a communications network are disclosed. For example, the method receives communications traffic associated with a sensor network from a sensor that is a member of the sensor network, analyzes the communications traffic to determine if an attack is occurring on the sensor network, and generates an alarm if the attack is occurring on the sensor network.