Unauthorized Communication Detection Using Dynamic Correction Values
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT communication detection systems face challenges in accurately distinguishing between normal and unauthorized communication due to fluctuations in wireless environments, leading to erroneous determinations and potential data loss or infection spread.
Innovation Solution
An unauthorized communication detection apparatus that uses a reception module, transmission module, acquisition module, determination module, and transmission control module to calculate a score for determining unauthorized communication based on a learning model and correction values, adjusting for fluctuations in network feature amounts to reduce erroneous determinations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If anomaly type detection is used to handle unknown attacks without signature updates, then adaptability to new threats is improved, but measurement precision of normal vs. unauthorized communication deteriorates due to wireless environment fluctuations
Solution Approach 1:
The patent changes the parameters used for anomaly detection from static network feature amounts to dynamic parameters that account for wireless environment fluctuations. Specifically, it introduces communication quality indicators (bandwidth, packet loss rate) as correction parameters to adjust the baseline of normal communication patterns, thereby maintaining measurement precision while preserving adaptability to new threats
Solution Approach 2:
The patent implements a feedback mechanism where the system continuously monitors communication quality and adjusts its anomaly detection thresholds accordingly. By feeding back the actual wireless environment conditions (bandwidth variations, packet loss rates) into the detection algorithm, the system dynamically adapts its parameters to distinguish normal fluctuations from genuine unauthorized communications
2Device complexity
If communication quality fluctuations are not considered in anomaly detection, then device complexity is reduced, but reliability of detection results deteriorates due to erroneous determination of normal communication as anomalous
Solution Approach 1:
The patent introduces communication quality metrics (bandwidth, packet loss rate) as intermediary variables that mediate between the raw network traffic data and the anomaly detection decision. These intermediaries capture the essence of wireless environment fluctuations without requiring complex modeling, thus maintaining relative system simplicity while significantly improving detection reliability
3Reliability
If strict anomaly thresholds are applied to block unauthorized communication, then security against malware is improved, but loss of information increases due to blocking of normal communication in unstable wireless environments
Solution Approach 1:
The patent dynamically adjusts the anomaly thresholds based on actual communication quality parameters. When bandwidth is low or packet loss is high (unstable wireless conditions), the system automatically relaxes the thresholds to allow more variation in normal communication patterns, thereby reducing false positives and preventing unnecessary blocking of legitimate data
Data Source
AI summary
An unauthorized communication detection apparatus comprises: a reception module configured to receive operational data; a transmission module configured to transmit the operational data; an acquisition module configured to acquire a correction value for correcting a determination expression for calculating a score for determining whether the operational data is involved in unauthorized communication, based on a parameter for extending an application range of a specific learning model and on a specific feature amount corresponding to the specific learning model among a plurality of feature amounts of the operational data; a determination module configured to calculate the score based on the plurality of learning models, the plurality of feature amounts, and the correction value, and determine whether the operational data is involved in unauthorized communication based on the calculated score; and a transmission control module configured to control the transmission of the operational data based on a determination result.


