Smart Appliance Network Security via Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart appliances lack effective protection against malicious code due to limited computing resources and inability to install anti-virus software, making them vulnerable to security breaches that can lead to unauthorized actions or data exposure.

Innovation Solution

A system that analyzes network traffic from smart appliances by routing it through a network traffic hub, collecting and aggregating data on source-destination pairs, and using a behavior analysis engine to detect anomalies indicative of malicious behavior, which can block suspicious traffic or alert users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If anti-virus software is installed on smart appliances to protect against malicious code, then security protection capability is improved, but device complexity and resource requirements increase beyond what smart appliances can support

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidsoftware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the smart appliance and the network. The gateway runs the anti-virus software and performs security analysis on network traffic, while the smart appliance itself remains simple and unchanged. This mediator approach allows security protection without increasing the complexity or resource requirements of the smart appliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security protection function is segmented from the smart appliance and placed in a separate gateway device. The system is divided into two independent parts: the simple smart appliance that generates traffic, and the sophisticated gateway that analyzes traffic for malicious code. This segmentation allows each component to be optimized independently.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If users are given full access to smart appliance functionality to detect malicious behavior, then detection capability is improved, but ease of operation deteriorates due to user's inability to understand technical details

Engineering Contradiction:
Improvemalicious behavior detection capabilityVSAvoiduser accessibility
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The gateway acts as an intermediary that performs complex security analysis and translates technical findings into user-friendly information. The gateway monitors network traffic, detects malicious behavior, and presents simplified alerts to users without exposing complex technical details, thus maintaining both detection precision and ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service security monitoring where the gateway automatically analyzes traffic and detects threats without requiring user intervention. Users receive simple notifications about security events without needing to understand the underlying technical analysis, enabling effective security monitoring while maintaining ease of operation.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If comprehensive network traffic analysis is performed to detect malicious behavior, then security detection accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvemalicious behavior detection accuracyVSAvoidtraffic analysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The gateway performs partial analysis by focusing on specific indicators of malicious behavior rather than analyzing every aspect of network traffic in detail. The system looks for particular patterns and anomalies that indicate threats, allowing effective detection without the time cost of comprehensive analysis of all traffic data.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system establishes baseline profiles of normal smart appliance behavior in advance. When analyzing traffic, the gateway compares current traffic against these pre-established baselines, enabling rapid detection of deviations that indicate malicious behavior without requiring time-consuming analysis from scratch for each traffic event.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10560280B2Network security analysis for smart appliances
Publication Date: 2020.02.11 CUJO LLC
  • US10560280B2 patent drawing
  • US10560280B2 patent drawing
  • US10560280B2 patent drawing

AI summary

A method and system for detecting malicious behavior from smart appliances within a network. Smart appliances have a certain level of intelligence that allows them to perform a specific role more effectively and conveniently. Network traffic data and appliance identification data is collected about smart appliances within a network. The data is sent to a behavior analysis engine, which computes confidence levels for anomalies within the network traffic that may be caused by malicious behavior. If the behavior analysis engine determines that malicious behavior is present in the network, it sends an instruction to a network traffic hub to block network traffic relating to the anomaly. In some embodiments, network traffic is blocked based on source-destination pairs. In some embodiments, network traffic is blocked from a device outside the network that is determined to be malicious.