Malicious Communication Detection via Dynamic Periodicity Requirements

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing malicious communication detection methods in IoT systems face challenges in accurately distinguishing normal messages from malicious ones due to the consideration of worst-case periodic errors, which can lead to false positives or false negatives, especially in networks with varying environmental conditions and application constraints.

Innovation Solution

A malicious communication detection device that assesses communication messages based on periodicity requirements set for each time-varying state, considering factors like bandwidth load, transmission count, and time interval, to determine whether a message is normal or malicious, using a communication assessment unit that classifies states and applies corresponding periodicity requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the periodicity requirement is set to consider the worst case of periodic error, then false detection is reduced, but detection accuracy deteriorates due to inability to distinguish normal messages with characteristic variations from malicious messages

Engineering Contradiction:
Improvedetection accuracyVSAvoidperiodicity error consideration
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent applies dynamics by transitioning from a static periodicity requirement to a dynamic one that adapts to different communication states. The system identifies multiple states based on transition conditions (such as bandwidth load, transmission count, or time interval) and selects the appropriate periodicity requirement for each state. This allows the detection system to accurately distinguish between normal messages with characteristic variations and actual malicious messages, resolving the contradiction between reducing false detection and maintaining detection accuracy.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of periodicity requirement from a fixed value to a variable value that depends on the communication state. By introducing state identification mechanisms that monitor transition conditions and dynamically adjust the periodicity requirement accordingly, the system can accommodate normal variations in periodic error while still detecting malicious communications. This parameter change enables the system to maintain high detection accuracy across diverse network conditions.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If a single periodicity requirement is used for all communication messages, then device complexity is reduced, but detection precision deteriorates due to inability to account for state-specific periodic variations

Engineering Contradiction:
Improvedetection precisionVSAvoidperiodicity requirement management
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the communication monitoring function into multiple state-specific sub-functions. Instead of using a single periodicity requirement for all messages, the system divides the communication states into distinct categories (e.g., based on bandwidth load, transmission count, or time interval) and maintains separate periodicity requirements for each segment. This segmentation enables precise detection for each state while managing complexity through structured organization of state identification and periodicity requirement selection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning different periodicity requirements to different communication states. Each state is characterized by specific transition conditions and receives a tailored periodicity requirement that is optimized for that particular state. This allows the system to achieve high detection precision for each local state while maintaining overall system manageability through clear state boundaries and selection logic.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240373227A1Malicious communication detection device, communication permission list generation device, malicious communication detection method, communication permission list generation method, storage medium storing malicious communication detection program, and storage medium storing communication permission list generation program
Publication Date: 2024.11.07 MITSUBISHI ELECTRIC CORP
  • US20240373227A1 patent drawing
  • US20240373227A1 patent drawing
  • US20240373227A1 patent drawing

AI summary

An objective is to obtain a malicious communication detection device that can more accurately determine whether a communication message is a normal message. The malicious communication detection device according to the present disclosure includes a communication acquisition unit to acquire a communication message, and a communication assessment unit to determine whether the communication message is a normal message on the basis of a periodicity requirement set for each time-varying state of the communication message.