Security Middleware Layer for IoT Controller Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Internet of Things (IoT) devices, such as automotive controllers, are vulnerable to cyber attacks due to security bugs in their software, allowing hackers to exploit vulnerabilities and gain control over critical systems, posing risks to safety and infrastructure.

Innovation Solution

Implementing customized security policies automatically generated and enforced on controllers to restrict operations and behaviors, preventing unauthorized access and malware execution, with real-time logging and reporting to a central management system to detect and block anomalies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policies are implemented on controllers to prevent cyber attacks, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the controller architecture by introducing a separate security middleware layer that operates independently from the core control functions. This layer includes security agents, policy enforcement modules, and logging components that can be added without modifying the underlying controller software, thus improving security while minimizing impact on device complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security middleware layer as an intermediary between the controller and external systems. This middleware includes security agents that monitor and enforce security policies, acting as a mediator that prevents direct access to vulnerable controller components while maintaining normal controller operation

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If security middleware layer is added to monitor and enforce security policies, then security detection capability is improved, but processing overhead increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidprocessing overhead
Core Design Contradiction:
Difficulty of detecting and measuringVSUse of energy by moving object

Solution Approach 1:

The patent implements preliminary action by pre-defining security policies and using pattern matching to identify suspicious behaviors before they can execute malicious code. The security agents continuously monitor controller state and compare against predefined security rules, enabling early detection of potential threats without requiring complex real-time analysis

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security middleware layer is designed to be self-contained, with security agents that autonomously monitor controller operations and enforce security policies without requiring constant external intervention. The system performs self-diagnosis and self-protection, reducing the need for heavy external processing

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11616792B2Reporting and processing controller security information
Publication Date: 2023.03.28 KARAMBA SECURITY LTD
  • US11616792B2 patent drawing
  • US11616792B2 patent drawing
  • US11616792B2 patent drawing

AI summary

In one implementation, a method for providing security on externally connected controllers includes receiving, at a reporting agent that is part of a security middleware layer operating on a controller, an indication that a process has been blocked; obtaining, by the reporting agent, trace information for the blocked process; determining by the reporting agent, a code portion in an operating system of the controller that served as an exploit for the blocked process; obtaining, by the reporting agent, a copy of malware that was to be executed by the blocked process; generating, by the reporting agent, an alert for the blocked process that includes (i) the trace information, (ii) information identifying the code portion, and (iii) the copy of the malware; and providing, by the reporting agent, the alert to a network interface on the controller for immediate transmission to a backend computer system.