Security Vulnerability Detection via Network and Power Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern user end devices in telecommunication environments are vulnerable to security threats, such as data theft and being compromised into internet bots, due to insecure applications, necessitating a system to identify and mitigate these vulnerabilities.

Innovation Solution

A test system comprising a device under test, a network simulator with a penetration test module, a deep packet inspection engine, a power consumption measurement device, and an over-the-top application analyzer module, which performs penetration tests, monitors IP traffic and power consumption, and correlates data to identify abnormal behavior and security threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple monitoring components (packet inspection, power measurement) are added to detect security threats, then security detection capability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity vulnerability detection capabilityVSAvoidtest system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The test system is divided into separate functional modules: a network simulator for generating test traffic, a deep packet inspection engine for analyzing network packets, a power consumption measurement device for monitoring power usage, and an OTT application analyzer module for correlating data. Each module performs a specific function, allowing the system to achieve comprehensive security detection while maintaining modularity and manageability of complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent combines multiple monitoring functions (packet inspection, power measurement, application analysis) into a unified test system that correlates data from all sources through the OTT application analyzer module. This integration allows the system to detect security vulnerabilities by analyzing correlations between network traffic patterns and power consumption, achieving enhanced detection capability while consolidating control in a single analysis module.

Inventive Principle:
Principle #5Merging (Combining)

2Measurement precision

If comprehensive data collection from multiple sources is performed to identify security threats, then measurement precision is improved, but loss of time increases due to data correlation and analysis

Engineering Contradiction:
Improvesecurity threat identification accuracyVSAvoiddata analysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary data collection and organization by the separate monitoring components (packet inspection engine, power measurement device) before correlation analysis. Each component pre-processes and structures its data independently, preparing it for efficient correlation by the OTT application analyzer module. This preliminary organization reduces the time required for comprehensive analysis while maintaining high measurement precision.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The OTT application analyzer module correlates data from multiple sources and provides feedback on identified security threats and abnormal behaviors. This feedback mechanism allows the system to continuously refine its analysis by comparing expected behavior patterns with actual observed patterns, improving threat identification accuracy while optimizing analysis time through learned patterns.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10873594B2Test system and method for identifying security vulnerabilities of a device under test
Publication Date: 2020.12.22 ROHDE & SCHWARZ GMBH & CO KG
  • US10873594B2 patent drawing
  • US10873594B2 patent drawing

AI summary

A test system for identifying security vulnerabilities of a device under test is described, comprising a device under test and a network simulator connected to the device under test, a deep packet inspection engine connected to the network simulator for monitoring IP traffic, a power consumption measurement device connected to the device under test for monitoring the power consumption of the device under test, and a power consumption measurement device connected to the device under test for monitoring the power consumption of the device under test. The network simulator comprising at least one penetration test module for performing at least one penetration test. The over-the-top application analyzer module is adapted to correlate all information gathered to identify an abnormal behavior of the device under test from expected behavior under the conditions applied and to identify at least one security threat. Further, a method for identifying security vulnerabilities of a device under test is described.