Method, computer program product and system for protecting a computer structure

JP2024522645A5Pending Publication Date: 2025-06-0211ACTIVE GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2023576045
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2021-06-08
Filing Date
2022-05-30
Publication Date
2025-06-02

AI Technical Summary

Technical Problem

Existing computer networks are susceptible to malware attacks, which can damage the network, steal sensitive data, and spy on internal information, particularly through unsecured connections like the Internet and USB ports, posing risks of unauthorized data transmission and espionage.

Method used

A method involving a data variation unit that generates random deviation values and adds them to data streams, especially image and audio data, to prevent malware and sensitive information from reaching protected computer structures by disguising and distorting the data, while ensuring minimal impact on functionality.

Benefits of technology

This approach effectively prevents malware transmission and unauthorized data leakage by distorting data streams, ensuring that malware and sensitive information become unusable, while maintaining the functionality of the protected computer systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a method for protecting a computer structure (1) with computer units (5, 6, 7) against malware or unauthorized data transmission. The computer structure (1) is connected to an isolation structure (11), which has a processor (12) and a main memory (13) and transmits a data stream with data values ​​to the computer structure (1) or receives a data stream from the computer structure (1) via a data link (18). The object of the invention is to propose a method for data exchange using the isolation structure (11), which prevents or prevents the transmission of malware to the computer units or the leakage of data stored in the computer units. This problem is solved in that a deviation value is generated by a data variation unit (19) using a random generator (17) and is added to the data values ​​of the data stream.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a method for protecting a computer structure comprising at least one computer unit from malware or unauthorized data transmissions, the computer structure being connected via a data link to an isolated structure, the isolated structure having at least one processor and a main memory, and transmitting at least one data stream to the computer structure or receiving a data stream from the computer structure. The present invention further relates to a computer program product and a system for protecting the computer structure. [Background technology]

[0002] The method described in this specification aims to protect computer structures (such as computer networks) and computer units integrated into computer structures against both malware and unauthorized acquisition of stored data (data theft), as well as espionage of internal information of IT infrastructures, etc.

[0003] Protecting computer systems from malware is becoming increasingly important. Computer networks, where many users have terminal devices that access external content via interfaces such as the Internet, intranets, or USB ports, are particularly vulnerable to malware attacks. Examples of such networks include computer networks of companies, parliaments, governments, and government ministries. In these networks, confidential data is often stored on various computers. In addition to the risk of malware transmission damaging the network, the computers connected to the network, and the data stored on the network, or allowing espionage of internal information, there is also the risk that the confidential data stored on the network may be read by malware and transmitted to unauthorized recipients, for example, via the Internet.

[0004] In practice, a data connection is used to transmit data packets. A data packet consists of a header and a payload. The header contains, for example, information about the source and destination of the packet, as well as information about the data format of the payload. The payload contains the data values ​​to be transmitted, for example, values ​​for controlling pixels on a screen, values ​​for controlling a pointer, values ​​for generating audio signals, for example via a sound card, etc. A data connection can be a data bus or a data tunnel in a computer network. Encrypted tunnels are used to securely transmit data over insecure or untrusted communication connections in a network.

[0005] U.S. Patent Publication No. 9,391,832 B1 proposes allowing a protected computer to access the Internet through a surrogate, which converts / transcodes the received data at least once before sending it to the protected computer. U.S. Patent Application Publication No. 2020 / 0177623 A1 proposes a code modification technique for detecting anomalous behavior. The technique receives web code and generates modified web code by modifying specific program elements throughout the web code, with the aim of detecting anomalies in a terminal device based on the missing program elements. U.S. Patent Application Publication No. 2017 / 0032120 A1 describes a system for detecting program variants. The system analyzes system calls by executing the program and generates executable program code. This code is then mutated, improved, or modified to generate variations of the program that continue to function similarly to the original code. Summary of the Invention [Problem to be solved by the invention]

[0006] The object of the present invention is to propose a method, a program product and a system for data exchange between an isolation structure and a computer structure, thereby preventing or at least preventing the transmission of malware to the computer structure, the leakage of data stored in the computer structure and espionage of the internal information of the computer structure. [Means for solving the problem]

[0007] According to the present invention, in order to solve the above problem, at least one data variation unit generates a deviation value through a random generator, and the deviation value is added to a data value of the data stream, and the data value is: - image data, -digital audio signal, -Pointer position data, Represents the content of at least one of the following:

[0008] That is, a transmitting unit transmitting a data stream via a data connection comprises a data variation unit, which generates allowable deviation values, e.g., -2, -1, 0, 1, 2, in a random order via a random generator and adds them to discrete data values ​​in the payload of the data stream. By adding small deviation values ​​to the data values ​​of the data stream in this way, it is possible to prevent steganographically disguised data, in particular malware or transmitted confidential information, that may have been added or superimposed on the data stream from reaching the receiving unit undamaged. The content of the added, superimposed, or transmitted data stream is corrupted by the deviation values, so that the added data or steganographically camouflaged data superimposed on the data stream and the transmitted confidential information become unusable.

[0009] According to the present invention, programs such as web code, macros, Java scripts, etc. are executed on an isolated structure, not on the protected computer structure. Image data, audio signals, pointer position data generated on the isolated structure are transferred to the computer structure via the data stream, so that by adding a deviation value, further protection is achieved against superimposed data, especially malware.

[0010] In practice, the isolation structure exchanges data with insecure data sources via an interface, for example the Internet, a mail server, or a USB interface with an external data storage device such as a USB stick. Computers connected to the Internet are at risk of malware. The same is true for computers to which external data storage devices are connected via an interface. The computer units in the protected computer structure perform all access to the data sources connected via the interface or to the Internet via the isolation structure, and process the data acquired from the data sources or the Internet in the isolation structure. The data acquired from the Internet or external devices is processed in the isolation structure, and only the optical and acoustic output signals resulting from this processing are sent via the data connection to the computer of the protected computer structure, so that this data stream is distorted by the superimposed deviation values.

[0011] In practice, data streams are transmitted as a series of data packets containing a header and a payload. The header is used to determine the data values ​​to which deviations are permitted. As mentioned earlier, the header contains not only information about the source and destination, but also information about the data packet's payload. Data packets with unacceptable headers are discarded and not forwarded. Certain data streams, such as keyboard data, text data, and addresses or control commands such as hyperlinks, require the transmission of discrete data values ​​identically to achieve the desired expression or function. These data values ​​should not be altered, as transmitting different characters or functions would cause significant interference or render the transmitted data values ​​unusable. The same is true for the header itself. Meanwhile, other data types in the payload are insensitive to slight deviations. For example, if the data values ​​are image data from a graphics card representing pixels on a screen, the viewer will barely notice small deviations, or will not notice them at all. The same is true for digital audio signals. Slight fluctuations and deviations from the actual transmitted data values ​​are barely audible to the viewer and do not alter the perceived audio signal. The pointer position data also does not respond to small fluctuations.

[0012] In other words, the data values ​​that are allowed to have deviation values ​​added are: - image data, -digital audio signal, -Represents one of the contents of the pointer position data.

[0013] In principle, to effectively prevent the transfer of malware to the protected computer and the unauthorized exfiltration of data from the protected computer, all data values ​​should be modified by adding deviations. Adding deviations to the payload is only not permitted if minimal changes to the payload do not trigger the desired functionality or if the content is distorted.

[0014] The addition of deviation values ​​may be disabled for specific data, such as uploaded or downloaded data and programs, or encrypted data. Encrypted data, files, or programs cannot be decrypted to the original data due to the addition of deviation values, making them unusable. Therefore, for specific data streams, the addition of deviation values ​​can be disabled, for example, by a system administrator, who can then make the decision as the security officer of the computer system or someone authorized by the officer.

[0015] Data from the Internet or other insecure data sources is transferred only indirectly (not directly) to computers in the protected computer structure, and the data stream is transcoded before being sent over the data connection.

[0016] In other words, communications from the isolated structure to the computers of the protected computing structure are largely limited to the transmission of sound and image data in transcoded form. Application software runs on the isolated structure, for example, running accessed websites and applications located on those websites. Malware contained on websites or other malware transmitted over the Internet connection is intercepted and stopped at the isolated structure and never reaches the computers of the protected computing structure.

[0017] The display and sound reproduction of content accessed over the Internet are transmitted to the protected computer in this manner, so that they are perceived by the computer user without the data stream from the Internet itself reaching the protected computer. The functional elements of websites accessed over the Internet and the software applications they host are not transmitted; only the screen displays and audio signals generated by accessing the websites are transmitted. This information is what the user sees and hears, and its meaning is harmlessly distorted by small, incremental changes due to the superimposed deviations. Small deviations in the brightness or color of an image are corrected by the human eye and do not interfere with the visual perception of the displayed information. The same applies to gradual changes in the pitch or volume of sound data.

[0018] User inputs, such as keyboard inputs and mouse position data and mouse control commands, mouse click information, and other information, such as Internet addresses (URLs or IP addresses), are sequentially transmitted from the protected computer structure to the isolated structure. In this way, users of computers in the protected computer structure remotely control software (Internet browsers, email, video conferencing, etc.) running on the isolated structure. By analyzing the header data, it is possible to identify data values ​​in data packets transmitted to the isolated structure that are permissible to be deviated from. An example is pointer position information. On the other hand, control commands, such as keystrokes, network addresses or URLs, or string variables (character strings) in general, are not altered to prevent loss of functionality.

[0019] Data added or superimposed onto the data stream between the isolation structure and the protected computer, for example malware intended to damage the protected computer or sensitive data on the protected computer steganographically superimposed onto the data stream, is corrupted and rendered unusable by the data variation unit generating deviation values ​​via a random generator and imprinting them onto the transmitted data values.

[0020] The range of deviation values ​​generated by the data variation unit via the random generator is selected depending on the type of data. For example, a larger deviation value can be applied to a video signal without perceptually distorting the overall impression of the video signal to the user. For pointer position data, the deviation can be kept small so as not to impair the functionality of the system. However, small deviation values, such as, for example, slight jittering of the displayed pointer, can be tolerated without impairing functionality.

[0021] In practice, pixel data for each image (frame) stored in the graphics card's frame buffer is transmitted over the data connection. The image data values ​​assigned to each pixel can be distorted within a certain range, for example, between -2 and +2, without significantly distorting the image seen by the viewer. The same applies to sound data generated by the isolation structure from data obtained from an insecure source, such as the Internet. Instead of transmitting the data stream received from the Internet, the sound data transcoded by the sound card is transmitted to the protected computer.

[0022] Content accessed over the Internet is typically provided on websites. Websites typically consist of structured text interspersed with images and other multimedia elements. Websites contain static (fixed) content and dynamic content. Dynamic content is generated anew each time it is accessed, preferably based on the results of database queries. As previously mentioned, the functional elements of the website are processed only in the isolated structure and are not transferred to the protected computer.

[0023] Transcoding data received from the internet already significantly reduces the risk of malware being transferred to the protected computer, and further distorting the data stream of the transcoded data with small deviations ensures that the isolation structure cannot be infected with malware.

[0024] In the other direction, i.e., from the protected computer to the isolated computer structure, pointer position data, e.g., data streams from a computer mouse or touchpad or touchscreen, can be distorted by superimposition. Generally, a slight shift of the pointer, on the order of one or two pixels, does not adversely affect the function of the pointer. While data stream distortion does not prevent unwanted transmission of data superimposed or added to the data stream onto the Internet, it does corrupt or render unintentionally leaked data unusable by the recipient.

[0025] If the protected computer is, for example, a smartphone, image or sound data is transmitted to the isolated structure via a data connection, for example, during a video call, when what is recorded by the smartphone's camera and microphone is transmitted through a data stream to the isolated structure and from there to the Internet.

[0026] In practice, a data stream that is not impaired by small variances is distorted by applying a deviation value, so that any data superimposed or added to the data stream becomes ineffective or unusable.

[0027] The protected computer structure comprises the following computer units for data exchange: -Physical servers, -Virtual servers, -Cloud interfaces (usually with unknown structures behind them), -PC, -Laptop computer, -tablet computers, -Smartphone, -Smart object processor, It may be a computer network to which one or more computer units are connected.

[0028] The isolation structure connected to the Internet and protecting the computer structure is itself a computer, other data processing device with a powerful CPU and the necessary interfaces, a virtualized computer or a server.

[0029] Furthermore, the protocol filter checks the acceptability of the communication protocol for the transmission of data streams between the isolation structure and the computer structure, thereby ensuring that only acceptable data streams, modified as much as possible, are transmitted over the data connection between the computer structure and the isolation structure. Unintentional transmission of other data streams, such as malware data or unauthorized acquisition of confidential data, is blocked by the protocol filter.

[0030] The above-described methods are embodied by a computer program product for execution on a processor. In particular, the computer program product comprises: - a processor of a separate structure, - separate unit processor for deviation value generation, imprinting, -computer processor, One of these is executed by the processor.

[0031] In other words, the internet-connected isolation computer may have a software routine that selectively imposes a deviation value on the data stream before it is sent to the computer structure. The computer unit of the computer structure may also have a software application that applies the deviation value. Preferably, however, a separate unit configured to generate and apply the deviation value is provided between the isolation structure and the computer structure. This unit is preferably hard-wired and cannot be reprogrammed, or if it can, it is limited in scope. This ensures that malware cannot affect elements that distort the data stream.

[0032] Finally, the invention is embodied by a system including a data variation unit of the type described above.

[0033] Further advantages of the present invention will be explained below in conjunction with the drawings. [Brief explanation of the drawings]

[0034] [Figure 1] FIG. 1 is a schematic diagram of a protected computer structure and an isolation structure that protects the computer structure from insecure data sources. DETAILED DESCRIPTION OF THE INVENTION

[0035] 1 shows a schematic representation of a computer structure 1, which is protected from unwanted transmission of data, such as malware, from unsecured data sources, and is intended to prevent unauthorized data streams from being obtained from the computer structure 1 or from being transmitted by malware already present in the computer structure.

[0036] A computer structure 1 is typically a corporate network, in particular an intranet, and must be configured to have access not only to a local data storage device 2 but also to external data sources 10 and the Internet 9. In the example shown in FIG. 1 , the computer structure 1 comprises both a local network 3 (local area network LAN) and a wireless network 4 (e.g., WLAN or WiFi). Mobile IT devices (computer units), such as a smartphone 5 or a tablet computer 6, are integrated into the computer structure 1 via the wireless network 4. A local data storage device 2 and a personal computer 7 (a laptop in this case) are integrated into the computer structure 1 via the local network 3. A server 8 is also assigned to the computer structure 1. The server controls communication and provides software and storage space for the integrated computer units 5, 6, and 7.

[0037] The various IT devices and their connection to the computer structure are shown only as examples. Of course, mobile devices may also be connected to the local network 3, for example, via a docking station. Alternatively, a PC may be connected to a wireless network via a WLAN interface. The computer structure is not limited to the illustrated embodiment with a physical server 8. The server 8 may also be an emulated server. The illustrated components of the computer structure 1 may be present in multiple places. Finally, the computer structure may also include further digital devices, such as so-called smart objects, i.e., sensors, automatically functioning objects with data processing capabilities and communication interfaces. The complexity of the protected computer structure 1 does not matter. The elements may be integrated via a virtual private communication network VPN. However, the protected computer structure 1 may also have a simpler design. The simplest cases are standalone computers and smartphones.

[0038] In order to protect the computer structure 1, it is not directly connected to the Internet 9 or to an insecure data source 10. An isolation structure 11 is used to access the Internet 9 or other insecure data sources 10, such as a USB stick. The isolation structure 11 comprises a CPU 12 and a local data storage device 13. Furthermore, it has a graphics card 14, a sound card 15 and a data interface 16, in particular a USB interface, an Ethernet interface, a WLAN interface or another communication interface. The data interface 16 may have several individual interfaces that can be used for data exchange with different data sources. A data connection 18 allows two-way data communication between the isolation structure 11 and the computer structure 1.

[0039] The isolation structure 11 therefore comprises all data processing and peripheral devices and interfaces required to retrieve and process data and software applications from the insecure data sources 10 and the Internet 9. The data and software applications retrieved from the Internet 9 and other insecure data sources 10 run on or are stored in the isolation structure 11. The results of the data processing, e.g., the executed software applications, are transferred via data connections to the computer units (smartphone 5, tablet computer 6, PC 7) of the protected computer structure 1. Wherever possible, only sound and image data generated by the isolation structure 11 are transferred to the computer units 5, 6, 7 for playback.

[0040] Data values ​​sent to the computer architecture 1 are distorted as far as possible by a data variation unit 19. The data variation unit 19 with the random number generator (random generator 17) is shown schematically in FIG. 1 as a separate hardware element. This embodiment provides a high level of security. The data variation unit 19 is a separate hardware element with a CPU and main memory, in which runs a program that is permanently programmed or that cannot be changed without significant technical effort. This program analyzes the incoming and outgoing data streams and distorts them (as far as possible). The headers of the received data packets are used to determine whether the data values ​​of the payload can be changed without them becoming unusable. This is possible, for example, for image data, sound data, and to some extent for position data from a pointer, such as a mouse pointer. If a particular data packet is determined to be suitable for such distortion, the data variation unit 19 generates, via a random generator 17, a deviation value within acceptable limits (e.g., between -2 and +2). The acceptable limits vary depending on the type of data (sound data, image data, position data). The generation (also by random determination) of a non-negative deviation value (e.g., 0, 1, 2) that is subsequently added or subtracted is equivalent to the solution described herein of generating and adding positive and negative deviation values.

[0041] These computers 5, 6, 7 of the protected computer structure 1 are protected from malware by ensuring that data originating from the Internet 9 or other insecure data structures 10 is not stored on the computers (smartphone 5, tablet computer 6, PC 7) of the protected computer structure 1 and that software obtained from the Internet 9 or other insecure data structures 10 is not executed. The additional imprint of the deviation value prevents steganographically false data added or superimposed on the data stream from damaging the computers 5, 6, 7 of the protected computer structure 1.

[0042] The other data stream, i.e., the data stream from the computers 5, 6, and 7 of the protected computer structure 1 to the isolation structure 11, is routed via the data variation unit 19. The data stream transmits the user's data of the computers 5, 6, and 7 to the outside, i.e., the Internet 9 or an unsecured data source 10. Furthermore, the data stream is used to remotely control the user program running in the isolation structure 11. The user of the computers 5, 6, and 7 views images generated by the isolation structure 11's Internet access and the software running thereon on a display. Input devices connected to the computers 5, 6, and 7, such as a keyboard, mouse, touchpad, or touchscreen, are used to generate the control commands and data streams sent to the isolation structure 11. In principle, all data streams are corrected by the data variation unit 19 by applying deviation values. This applies in particular to image data, sound data, position data from pointers, and data streams sent to the outside by malware that may already be present in the computer structure to undetectably leak confidential company information. Corporate information that may be leaked unnoticed by malware is destroyed or rendered unusable by the deviation imprint.

[0043] Data values ​​that are sensitive to small variations, i.e. data values ​​whose small variations do not trigger the desired function or result in meaningless content, pass unchanged through the data variation unit 19. The same applies to encrypted data: the system administrator of the protected computer structure 1 configures for which data types or data sources the variation imprint is to be disabled.

[0044] As mentioned above, the data variation unit 19 is designed as a separate hardware component with its own CPU and data storage for storing the executed software and other data that may be generated. In particular, the data variation unit 19 is designed to be unchangeable or to require significant technical effort to change. Protection against changes to the configuration of the data variation unit 19 and its IT elements prevents unauthorized persons from disabling or compromising the security features provided by the data variation unit 19.

[0045] However, in practice the data variation unit 19 may be emulated as a software module running on the CPU 12 of the isolation structure 11. The software module may have elements running on the server 8 of the protected computing structure 1 or on an end device of the protected computing structure 1 (smartphone 5, tablet 6, PC 7).

[0046] The features of the invention disclosed in the specification, drawings, and claims may be essential, individually or in any combination, for the implementation of the invention in its various embodiments. The invention is not limited to the described embodiments. Various modifications are possible within the scope of the claims, taking into account the knowledge of those skilled in the art. [Explanation of symbols]

[0047] 1: Computer Structure 2: Local data storage device 3: Local network 4: Wireless network 5. Smartphone 6: Tablet computer 7: Personal computer (PC) 8: Server 9: Internet 10: Data source, USB stick 11: Separation structure 12:CPU 13: Local data storage device 14: Graphics card 15: Sound card 16: Data interface 17: Random Generator 18: Data connection 19: Data Variation Unit

Claims

1. A method for protecting a computer structure (1) having at least one computer unit (5, 6, 7) from malware or unauthorized data transmission, comprising: The computer structure (1) is connected to a separated structure (11) via a data link (18), and the separated structure (11) has at least one processor (12) and a main memory (13), and transmits at least one data stream including a series of data values to the computer structure (1) or receives the data stream from the computer structure (1), At least one data variation unit (19) generates a deviation value using a random generator (17), and the deviation value is added to the data values of the data stream, The data values - Image data, - Digital audio signals, - Pointer position data characterize the method by indicating at least one of the contents.

2. The method according to claim 1, characterized in that the data values further indicate a transmission data stream transmitted by malware present in the computer structure (1).

3. The method according to claim 1, characterized in that the separated structure (11) communicates via an interface (16) with potentially unsafe data sources (9, 10), in particular the Internet (9).

4. The data stream is transmitted as a series of data packets having a header and a payload, The method according to claim 1, characterized in that the header is used to determine the data values to which the addition of the deviation value is allowed.

5. The method according to claim 4, characterized in that when the change in the payload is minimal and the content is distorted or the desired function is not induced, the addition of the deviation value to the payload is not allowed.

6. The method according to claim 1, characterized in that the addition of the deviation value is invalidated for a specific data stream, in particular for an uploaded or downloaded data file or program, or for encrypted data.

7. The method according to claim 1, characterized in that the data stream is transcoded before being transmitted to the computer structure (1) via the data link (18).

8. The computer structure (1) is a network that interconnects with one or more of the following computer units for data exchange: - Physical server, - Virtual server, - Cloud interface, - PC (7), - Laptop, - Tablet computer (6), - Smartphone (5), - Processor of a smart object The method according to claim 1, characterized in that it is a network that interconnects with one or more of the above.

9. The separation structure (11) is at least one of a computer, another data processing device having a powerful CPU and necessary interfaces, a virtualized computer, and a virtualized server. The method according to claim 1, characterized in that it is.

10. The protocol filter checks the acceptability of the communication protocol for transmitting the data stream between the separation structure (11) and the computer structure (1). The method according to claim 1, characterized in that it is.

11. A computer program product for transmitting a data stream including a series of data values via a data link between a computer structure (1) having at least one computer unit (5, 6, 7) and a separation structure (11) having at least one processor (12) and a main memory (13), A data variation unit (19) that generates a deviation value using a random generator (17) and adds the deviation value to the data values of the data stream when executed by a processor. A computer program product characterized by that.

12. The computer program product according to claim 11, characterized in that when the change in the payload is minimal and the content is distorted or the desired function is not induced, the addition of the deviation value to the payload is disabled.

13. The computer program product according to claim 11, characterized in that the data stream is transcoded before being transmitted from the separation structure (11) to the computer structure (1) via the data link (18).

14. - The processor (12) of the separation structure (11), - The processor of the data variation unit (19) provided as a separate hardware element for generating and imprinting the deviation value, - The processor (5, 6, 7) of the computer, A computer program product according to claim 11, configured to be executed in at least one of the processors.

15. A system for protecting against malware or unauthorized data transmission, having at least one computer unit (5, 6, 7) and a computer structure (1) connected to a separate structure (11) via a data link (18), wherein the separate structure (11) has at least one processor (12) and a main memory (13), and transmits at least one data stream containing a series of data values to the computer structure (1) via the data link (18) or receives the data stream from the computer structure (1), characterized in that at least one data variation unit (19) generates a deviation value using a random generator (17), and the deviation value is added to the data values of the data stream.

16. The data variation unit (19) - is designed as a separate hardware element, - is designed as a software element executed in the processor of the separate structure (11), - is designed as a software element executed in the processor of at least one computer unit (5, 6, 7) or in a server (8) within the computer structure (1), characterized by having at least one of the above, of the system according to claim 15.