Unsupervised Communication Behavior Detection for Device Spoofing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems struggle to swiftly detect device spoofing and irregular communication behaviors in large networks due to the complexity of alarms and lack of understanding of device types, making it difficult for human experts to identify inconsistencies.

Innovation Solution

An unsupervised detection method using a processor to determine and assess current communication behaviors of devices relative to established regular behaviors, employing clustering algorithms to identify deviations and trigger alarms based on behavioral and device clusters, without requiring device identification or domain knowledge.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security systems are used to detect device spoofing and irregular communication behaviors, then detection capability is provided, but the complexity of alarms and network complexity make understanding the raised alarms increasingly difficult

Engineering Contradiction:
Improvedetection capabilityVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex network monitoring task into distinct phases: a training phase where regular communication behaviors are learned and stored as reference patterns, and an inference phase where current behaviors are assessed against these pre-established patterns. This segmentation simplifies the alarm understanding process by separating behavior learning from behavior assessment, making the system more manageable despite network complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary action by conducting a training phase before actual security monitoring, where regular communication behaviors are determined and stored as reference patterns. This preliminary behavior characterization enables the inference phase to quickly assess current behaviors without having to analyze complex network patterns in real-time, thereby reducing the difficulty of understanding alarms while maintaining reliable detection.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If device identification and domain knowledge are required for threat detection, then accurate detection may be achieved, but the process becomes slower and more complex

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies self-service by automatically learning and storing regular communication behaviors during a training phase without requiring human expert intervention or domain knowledge. The processor independently characterizes device behaviors and creates reference patterns, enabling swift threat detection in the inference phase without slowing down for manual analysis or device identification, thus achieving both accuracy and speed.

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive analysis of communication behaviors is performed, then irregular behaviors can be detected, but computational effort increases

Engineering Contradiction:
Improvedetection reliabilityVSAvoidcomputational effort
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs comprehensive behavior analysis in advance during the training phase, where regular communication behaviors are thoroughly characterized and stored as reference patterns. This preliminary comprehensive analysis eliminates the need to repeat computationally intensive computations during the inference phase, as the system only needs to compare current behaviors against pre-established patterns, thereby maintaining high detection reliability while significantly reducing computational effort during operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4614364A1Unsupervised detection of irregular communication behavior of communication devices
Publication Date: 2025.09.10 HUAWEI TECH CO LTD
  • EP4614364A1 patent drawingFigure 1
  • EP4614364A1 patent drawingFigure 2~3
  • EP4614364A1 patent drawingFigure 4~5

AI summary

Disclosed is a device (1) for unsupervised detection of an irregular communication behaviour of a communication device under test, DUT (2, Di, i∈[1;I]), of a plurality of communication devices (2, Di). The device (1) comprises a processor (11), in an inference phase being configured to determine a current communication behaviour of the DUT (2, Di) and to assess the current communication behaviour of the DUT (2, Di) in view of regular communication behaviours of the plurality of communication devices (2, Di), thereby enabling a swift detection of security issues like device spoofing based on an unsupervised grouping of the plurality of communication devices (2, Di) in accordance with their regular communication behaviours.