Unauthorized Communication Detection Using Dynamic Correction Values

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT communication detection systems face challenges in accurately distinguishing between normal and unauthorized communication due to fluctuations in wireless environments, leading to erroneous determinations and potential data loss or infection spread.

Innovation Solution

An unauthorized communication detection apparatus that uses a reception module, transmission module, acquisition module, determination module, and transmission control module to calculate a score for determining unauthorized communication based on a learning model and correction values, adjusting for fluctuations in network feature amounts to reduce erroneous determinations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If anomaly type detection is used to handle unknown attacks without signature updates, then adaptability to new threats is improved, but measurement precision of normal vs. unauthorized communication deteriorates due to wireless environment fluctuations

Engineering Contradiction:
Improveability to handle unknown attacksVSAvoidaccuracy in distinguishing normal and unauthorized communication
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent changes the parameters used for anomaly detection from static network feature amounts to dynamic parameters that account for wireless environment fluctuations. Specifically, it introduces communication quality indicators (bandwidth, packet loss rate) as correction parameters to adjust the baseline of normal communication patterns, thereby maintaining measurement precision while preserving adaptability to new threats

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements a feedback mechanism where the system continuously monitors communication quality and adjusts its anomaly detection thresholds accordingly. By feeding back the actual wireless environment conditions (bandwidth variations, packet loss rates) into the detection algorithm, the system dynamically adapts its parameters to distinguish normal fluctuations from genuine unauthorized communications

Inventive Principle:
Principle #23Feedback

2Device complexity

If communication quality fluctuations are not considered in anomaly detection, then device complexity is reduced, but reliability of detection results deteriorates due to erroneous determination of normal communication as anomalous

Engineering Contradiction:
Improvesimplicity of detection systemVSAvoidaccuracy of unauthorized communication detection
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces communication quality metrics (bandwidth, packet loss rate) as intermediary variables that mediate between the raw network traffic data and the anomaly detection decision. These intermediaries capture the essence of wireless environment fluctuations without requiring complex modeling, thus maintaining relative system simplicity while significantly improving detection reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If strict anomaly thresholds are applied to block unauthorized communication, then security against malware is improved, but loss of information increases due to blocking of normal communication in unstable wireless environments

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidblocking of normal communication data
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent dynamically adjusts the anomaly thresholds based on actual communication quality parameters. When bandwidth is low or packet loss is high (unstable wireless conditions), the system automatically relaxes the thresholds to allow more variation in normal communication patterns, thereby reducing false positives and preventing unnecessary blocking of legitimate data

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11792650B2Unauthorized communication detection apparatus and recording medium
Publication Date: 2023.10.17 HITACHI LTD
  • US11792650B2 patent drawing
  • US11792650B2 patent drawing
  • US11792650B2 patent drawing

AI summary

An unauthorized communication detection apparatus comprises: a reception module configured to receive operational data; a transmission module configured to transmit the operational data; an acquisition module configured to acquire a correction value for correcting a determination expression for calculating a score for determining whether the operational data is involved in unauthorized communication, based on a parameter for extending an application range of a specific learning model and on a specific feature amount corresponding to the specific learning model among a plurality of feature amounts of the operational data; a determination module configured to calculate the score based on the plurality of learning models, the plurality of feature amounts, and the correction value, and determine whether the operational data is involved in unauthorized communication based on the calculated score; and a transmission control module configured to control the transmission of the operational data based on a determination result.