System and method for detecting malicious activities within a computerized device based on its ac power consumption
The system monitors AC power consumption to detect malicious activities in computerized devices by comparing patterns against stored signatures, addressing the vulnerability of existing cybersecurity solutions by identifying anomalies and issuing alerts, enhancing device security.
Patent Information
- Application Number
- PCT/IL2025/050294
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-03
- Filing Date
- 2025-04-03
- Publication Date
- 2025-10-09
AI Technical Summary
Existing cybersecurity solutions for computerized devices, particularly stationary and mobile devices, fail to effectively detect malicious activities through monitoring AC power consumption patterns, leaving them vulnerable to unauthorized intrusions and operational disturbances.
A system and method that monitors AC power consumption using an isolated AC supply monitoring unit, compares it against stored legitimate and illegitimate signatures, and issues alerts upon mismatches, utilizing pattern recognition and machine learning to identify anomalies indicative of cybersecurity threats.
Effectively detects and alerts users to malicious activities by analyzing power consumption patterns, providing an additional layer of security by identifying irregularities and deviations from normal usage, thereby protecting devices from unauthorized access and software errors.
Smart Images

Figure IL2025050294_09102025_PF_FP_ABST
Abstract
Description
[0001] SYSTEM AND METHOD FOR DETECTING MALICIOUS ACTIVITIES WITHIN A COMPUTERIZED DEVICE BASED ON ITS AC POWER CONSUMPTION
[0002] Field of the Invention
[0003] The present invention relates to the field of cybersecurity. More particularly, the present invention relates to a system and a method for detecting malicious activities within a computerized device, based on its AC power consumption.
[0004] Background of the Invention
[0005] Stationary or mobile computerized devices are valuable targets for skillful, sophisticated, and motivated offenders. Stationary computers (such as desktop computers and servers) are widely used for communicating and storing sensitive data, and they are also widely used for controlling the operation of essential infrastructures, such as electrical turbines, water supply systems, railroad signaling, the operation and control of vehicles, and various other tasks. Various protection techniques have been developed to protect stationary devices from malicious code, as any disturbance to their operation may result in very significant damage.
[0006] The above-mentioned security problem is also acute for mobile devices. Modern mobile devices host various gadgets and sensors, such as GPS, Wi-Fi, voice, cameras, accelerometers, etc. For example, an unauthorized intrusion that introduces malicious code may activate one or more of these sensitive components without the user's consent. This serious vulnerability is exploited by remote hostile agents to gather sensitive information through a compromised mobile phone. For this purpose, and like stationary devices, a variety of security software has been developed and is widely used for protecting mobile devices. It should be noted, however, that the security model of most mobile phone operating systems discourages some typical monitoring solutions available for stationary devices. It is therefore an object of the present invention to provide a system for detecting operational activities within a computerized device, which may be indicative of cybersecurity threats.
[0007] Other objects and advantages of the invention will become apparent as the description proceeds.
[0008] Summary of the Invention
[0009] A system for identifying and protecting a computerized device, fed from an AC power source, from malicious activities within the computerized device during operation, which comprises: a) an AC supply monitoring unit for continuously monitoring the AC power consumption of the computerized device from the AC power source during operation; and b) a database for storing one or more legitimate signatures of valid activities, each of the legitimate signatures represents a valid variation of a legitimate power consumption pattern, from the AC power source; and c) a processing and control unit consisting of at least one processor, associated memory and operating software, the processing unit is configured to: c.l) during the time period when the computerized device operates, receive data regarding the AC power consumption, from the AC supply monitoring; c.2) compare characteristics of the monitored power consumption to the one or more legitimate signatures; c.3) issue an alert upon detection of a mismatch between the characteristics and the one or more signatures.
[0010] The database may further store one or more illegitimate signatures of invalid or malicious activities, each of the illegitimate signatures represents invalid or malicious variation of power consumption pattern of the computerized device, from the AC power source, wherein during the time period when the computerized device operates, the processing unit is configured to: d) receive data regarding the AC power consumption, from the AC supply monitoring unit; e) compare characteristics of the monitored power consumption to the one or more illegitimate signatures; and f) issue an alert having one or more severity levels, upon detection of a match between the characteristics and the one or more illegitimate signatures.
[0011] The signatures may be created by: running an offline learning process on patterns of valid activities, being run one or more times, using of pattern recognition or machine learning techniques.
[0012] The AC supply monitoring unit may be separated and isolated both physically and logically in terms of connectivity from the hardware and software of the computerized device.
[0013] The AC supply monitoring unit is only physically connected to the AC power source.
[0014] The system may be implemented on a printed circuit board, which comprises a dedicated microprocessor and is separated both physically and logically from the electronic circuitry of the monitored computerized device.
[0015] The AC supply monitoring unit may comprise a dedicated microprocessor and is implemented on a separate printed circuit board, such that the dedicated microprocessor monitors the AC power consumption of the computerized device by sampling the current consumed from the AC power source.
[0016] The AC supply monitoring unit may form a trusted execution environment which is at least logically separated from the main operating system of the computerized device.
[0017] The computerized device may be a mobile device, where the battery of the mobile device functions as the AC power source, or a desktop device, where the AC power source is a power grid. Each of the signatures of valid activities may comprise marks that are introduced into the activities code, each of the marks reflecting a specific, known, and distinguishable shape of a signal in terms of power consumption from the AC power source.
[0018] The alert may be issued via a wired or wireless network interface.
[0019] The alert may be visual or audible, or a combination thereof.
[0020] The alert may be provided by alerting means that are positioned within the separate printed circuit board.
[0021] The visual means may be a light emitting diode (LED), an external screen or touch screen, and the audible means is a loudspeaker.
[0022] Raw data being monitored may be transmitted out via wired or wireless interface for further processing or future analysis.
[0023] Brief Description of the Drawings
[0024] The above and other characteristics and advantages of the invention will be better understood through the following illustrative and non-limitative detailed description of preferred embodiments thereof, with reference to the appended drawings, wherein:
[0025] - Fig. 1 shows a block diagram of a system for monitoring the AC power consumption to detect operational activities within a computerized device.
[0026] Detailed Description of the Invention
[0027] The present invention provides a system and method for monitoring AC power consumption to detect operational activities within a computerized device, which may be indicative of cybersecurity threats. By utilizing advanced signal processing techniques, the system isolates and analyzes frequency and current fluctuations to establish a detailed profile of the device's power usage. The system controls the power supply to facilitate operations and boot sequence analysis.
[0028] The system comprises a compact and integrated assembly, housing a control unit that orchestrates the overall functionality. The input voltage provides the power for the entire system, and therefore, a separate power supply is not required. The system has a built-in Data Acquisition System (DAS - a collection of hardware and software for sampling physical parameters such as voltage, current, temperature, and strain with a sensor or transducer) to allow for the measurement of electrical parameters through its interfaces with several sensors.
[0029] Fig. 1 is a block diagram of a system 100 for monitoring AC power consumption to detect operational activities within a computerized device 200, according to an embodiment of the invention.
[0030] The system 100 comprises a DAS 101 which performs signal processing, during which analog inputs from sensors are processed and converted to digital data, for analysis. Each sensor is connected to a dedicated channel, which captures power consumption data which is specific to that sensor.
[0031] Channel 1 in the DAS 101 performs voltage measurement by monitoring the AC voltage supplied to the computerized device 200, in order to calculate the power consumption of the computerized device 200 (which may be for example, a mobile device). The battery of the mobile device can function as the AC power source).
[0032] The equation governing Channel 1 is:
[0033] Pin = ^supply ■ kn 'PF[Eq. 1] where PF represents the power factor of the load. The Power Factor is the ratio of working power, measured in kilowatts (kW), to apparent power, measured in kilovolt amperes (kVA) that measures the amount of power used to run a circuit during a certain period. It is found by multiplying voltage (V) by current (A). Therefore, PF expresses the ratio of true power used in a circuit to the apparent power delivered to the circuit).
[0034] Channel 2 in the DAS 101 employs a shunt resistor R for precise measurement of the consumed current lin, following Ohm's law:
[0035] Channel 3 in the DAS 101 performs high-frequency current measurement using a Hall effect sensor 102, paired with an optional bandpass filter 106, for the detection of high- frequency current components within a designated frequency band, while utilizing a DAS with a lower sampling rate Fs where BW is the bandwidth of the bandpass filter 103, and N is an integer that ensures the aliasing of these high-frequency components into the measurable range of the DAS 101.
[0036] The system 100 also comprises a processing and control unit 105 (which consists of at least one processor, associated memory and operating software) which receives data regarding the AC power consumption, from the AC supply monitoring unit, during the time period when the computerized device 100 operates. The processing and control unit 105 compares characteristics of the monitored power consumption to the stored signatures and issues an alert upon detecting of a mismatch between the characteristics and the one or more stored signatures.
[0037] Anomaly Detection:
[0038] The system 100 is adapted to analyze and compare power consumption patterns during device operation, startup phases, and multiple boot sequences to historic data patterns that are stored in a database. As part of the system 100, there is an option to manage an input power relay 103 that can be used to control the power supplied to the computerized device 200 (for example, to terminate or interrupting the operation of the computerized device 200 upon detecting anomalies in the AC power consumption patterns.
[0039] The measured data from each channel is analyzed to identify deviations from established normal power consumption patterns, which may indicate operational anomalies. The system 100 can identify irregularities and deviations caused by hardware malfunctions, unauthorized access, or software errors by comparing real-time measurements to historical data or to expected usage profiles. Using power consumption metrics to detect anomalies offers an effective layer of security for computerized devices.
[0040] In one embodiment, the AC supply monitoring system 100 continuously monitors the power consumption from the AC power source that supplies power to the device, compares characteristics of measured power consumption patterns with valid activity signatures / patterns that are stored in a database, and is configured to generate alerts upon detection of a mismatch between measured consumption patterns and typical (normal) consumption patterns. The database stores consumption signatures and patterns of valid (normal) activities. Each signature of a valid activity of the computerized device 200 (a legitimate signature) describes a valid variation of a legitimate power consumption pattern, from the AC supply socket 104 that provides AC power from an AC power source, to the computerized device 200.
[0041] In one embodiment, the database further stores one or more illegitimate signatures of invalid or malicious activities. Each illegitimate signature represents an invalid or malicious variation of power consumption pattern of the computerized device, from the AC power source. During the time period when the computerized device 200 operates, the processing and control unit 105 is configured to receive data regarding the AC power consumption, from said AC supply monitoring unit. The processing and control unit 105 compares characteristics of the monitored power consumption to said one or more illegitimate signatures and issues an alert with one or more severity levels, upon detection of a match between the characteristics and the one or more illegitimate signatures.
[0042] The database can also store invalid or malicious activities signatures. Each invalid or malicious activity signature describes invalid or malicious variation of a power consumption pattern from the AC supply socket 104 that provides AC power to the computerized devices200.
[0043] The signatures of valid activities are created based on an offline learning process of a valid activities pattern. During the learning process, the valid activities are carried out one or more times, and features of each pattern are extracted using pattern recognition (is the ability of machines to identify patterns in data, and then use those patterns to make decisions or predictions using computer algorithms) or Machine Learning (ML) techniques.
[0044] In one embodiment, the AC supply monitoring system 100 is physically and logically separated and isolated, in terms of connectivity, from the hardware and software of the computerized environment of the device 200. In this case, the AC supply monitoring system 100 is physically connected only to the AC supply of the computerized device 200.
[0045] In one embodiment, the AC supply monitoring system 100 is implemented on a printed circuit board which comprises a dedicated microprocessor and is separated both physically and logically from the electronic circuitry of the monitored computerized device 200.
[0046] In one embodiment, the AC supply monitoring system 100 is comprises a dedicated microprocessor and is implemented on a separate printed circuit board, such that the dedicated microprocessor monitors the AC power consumption of the computerized device by sampling the current consumed from the AC power source. In one embodiment, the AC supply monitoring system 100 forms a trusted execution environment which is at least logically separated from the main operating system of the computerized device 200.
[0047] In one embodiment, the computerized device is a desktop device, which is fed from an AC a power grid.
[0048] In one embodiment, each of the signatures of valid activities comprises marks that are introduced into the activities code. Each mark reflects a specific, known, and distinguishable shape of a signal in terms of power consumption from the AC power source.
[0049] The alert (which may be visual or audible, or a combination of them, provided by alerting means that are positioned within the separate printed circuit board) is issued via a wired or wireless network interface.
[0050] The visual alert is provided by visual means, such as a Light Emitting Diode (LED), an external screen or touch screen, and the audible means is a loudspeaker.
[0051] The raw data that is monitored is transmitted out via wired or wireless interface for further processing or future analysis.
[0052] As various embodiments and examples have been described and illustrated, it should be understood that variations will be apparent to one skilled in the art without departing from the principles herein. Accordingly, the invention is not to be limited to the specific embodiments described and illustrated in the drawings.
Claims
CLAIMS1. A system for identifying and protecting a computerized device, fed from an AC power source, from malicious activities within said computerized device during operation, comprising: a) an AC supply monitoring unit for continuously monitoring the AC power consumption of said computerized device from said AC power source during operation; and b) a database for storing one or more legitimate signatures of valid activities, each of said legitimate signatures represents a valid variation of a legitimate power consumption pattern, from said AC power source; and c) a processing and control unit consisting of at least one processor, associated memory and operating software, said processing unit is configured to: c.l) during the time period when said computerized device operates, receive data regarding said AC power consumption, from said AC supply monitoring; c.2) compare characteristics of the monitored power consumption to said one or more legitimate signatures; c.3) issue an alert upon detection of a mismatch between said characteristics and said one or more signatures.
2. A system according to claim 1, wherein the database further stores one or more illegitimate signatures of invalid or malicious activities, each of said illegitimate signatures represents invalid or malicious variation of power consumption pattern of the computerized device, from the AC power source, wherein during the time period when said computerized device operates, the processing unit is configured to: a) receive data regarding said AC power consumption, from said AC supply monitoring unit; b) compare characteristics of the monitored power consumption to said one or more illegitimate signatures; and c) issue an alert having one or more severity levels, upon detection of a match between said characteristics and said one or more illegitimate signatures.
3. A system according to claim 1, in which the signatures are created by: running an offlinelearning process on patterns of valid activities, being run one or more times, using of pattern recognition or machine learning techniques.
4. A system according to claim 1, in which the AC supply monitoring unit is separated and isolated both physically and logically in terms of connectivity from the hardware and software of the computerized device.
5. A system according to claim 1, in which the AC supply monitoring unit is only physically connected to the AC power source.
6. A system according to claim 4, which is implemented on a printed circuit board which comprises a dedicated microprocessor and is being separated both physically and logically from the electronic circuitry of the monitored computerized device.
7. A system according to claim 6, in which the AC supply monitoring unit comprises a dedicated microprocessor and is implemented on a separate printed circuit board, such that said dedicated microprocessor monitors the AC power consumption of the computerized device by sampling the current consumed from said AC power source.
8. A system according to claim 1, wherein said AC supply monitoring unit forms a trusted execution environment which is at least logically separated from the main operating system of the computerized device.
9. A system according to claim 1, in which the computerized device is a mobile device, wherein the battery of said mobile device functions as the AC power source.
10. A system according to claim 1, wherein said computerized device is a desktop device, wherein the AC power source is a power grid.
11. A system according to claim 1, wherein each of the signatures of valid activities comprises marks that are introduced into the activities code, each of said marks reflecting a specific, known, and distinguishable shape of a signal in terms of power consumption from the AC power source.
12. A system according to claim 1, wherein the alert is issued via a wired or wireless network interface.
13. A system according to claim 1, wherein the alert is visual or audible, or a combination thereof.
14. A system according to claim 6, wherein the alert is provided by alerting means that are positioned within the separate printed circuit board.
15. A system according to claim 13, wherein the visual means is a light emitting diode (LED), an external screen or touch screen, and the audible means is a loudspeaker.
16. A system according to claim 1, wherein raw data being monitored is transmitted out via wired or wireless interface for further processing or future analysis.
Citation Information
Patent Citations
Detecting Software Attacks By Monitoring Electric Power Consumption Patterns
US20080276111A1
System and method for detecting energy consumption anomalies and mobile malware variants
US20100313270A1
System and method for detecting activites within a computerized device based on monitoring of its power consumption
US20180173877A1