Bayesian Firmware Security via Data Recombination

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems, particularly those based on databases and anomaly detection, are ineffective in detecting and preventing unknown cyber threats and malfunctions that can originate from firmware, as they often require the operating system to be loaded and can allow threats to spread before being recognized and eradicated, especially when the firmware is infected.

Innovation Solution

A method utilizing Bayesian statistical techniques to de-structure and recombine empirical data, assigning probabilities to determine the likelihood of cyber threats, allowing for the detection and prevention of threats before they cause harm, even when the operating system is not loaded, by creating a dynamic system that can identify unknown threats and manage firmware-related risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If database-based antivirus methods are used to detect cyber threats, then known threats can be identified and blocked, but unknown threats and zero-day attacks cannot be detected

Engineering Contradiction:
Improvedetection accuracy for known threatsVSAvoiddetection capability for unknown threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by de-structuring known threat data into components and recombining them to generate hypothetical unknown threats before actual attacks occur. This proactive generation of threat scenarios enables the system to detect zero-day attacks and unknown threats that database-based methods cannot identify.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies segmentation by breaking down known threat data into smaller components or features, then recombining these segments in various ways to create representations of unknown threats. This segmentation approach allows the system to analyze threat patterns at a granular level and detect novel threats that don't match complete known signatures.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If anomaly detection systems are used to identify cyber threats, then unknown threats can be detected, but detection occurs only after the threat has infected at least one component

Engineering Contradiction:
Improvedetection capability for unknown threatsVSAvoidtime between attack and detection
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary analysis by de-structuring and recombining threat data to create predictive models of potential attacks before they occur. This allows the system to detect and block threats at the network perimeter or entry point, preventing infection of system components entirely, rather than detecting anomalies after infection has already occurred.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a dynamic threat detection system that continuously adapts by generating new threat hypotheses through data recombination. This dynamic approach allows the system to evolve its detection capabilities in real-time, maintaining sensitivity to novel threats while reducing the time between attack and detection through continuous learning and adaptation.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If firmware management programs are executed without security control, then device functionality is maintained, but firmware can be infected and threats can bypass the operating system

Engineering Contradiction:
Improvefirmware execution functionalityVSAvoidfirmware infection risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary security program that acts as a mediator between the firmware management program and the operating system. This security program verifies the integrity of firmware, blocks harmful instructions, and allows legitimate management instructions to pass through, thereby maintaining device functionality while preventing firmware infections from bypassing security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system applies preliminary anti-action by implementing security controls that prevent firmware infections before they can execute harmful actions. The security program proactively blocks harmful instructions in the firmware management program and verifies firmware integrity, countering potential threats before they can compromise the operating system or bypass security measures.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS12174945B2Method for securing an electronic device
Publication Date: 2024.12.24 SURIANO VALERIA
  • US12174945B2 patent drawing
  • US12174945B2 patent drawing
  • US12174945B2 patent drawing

AI summary

A method for securing the functioning of an electronic device, by using Bayesian statistics techniques.