Compromised Device Detection via Frequency Spectrum Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for detecting compromised computer equipment in information systems are non-automatic, slow, and unable to differentiate between equipment emitting similar frequencies, leading to inefficient analysis and potential information interception.
Innovation Solution
A method that simultaneously and automatically analyzes all computer equipment by performing a frequency sweep, time envelope demodulation, transforming signals into the frequency domain, constructing a frequency spectrum, and searching for energy thresholds to identify compromised devices, using an antenna and software radio with signal processing algorithms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If sequential analysis of computer equipment is performed using controlled test signals, then high signal-to-noise ratio is achieved, but analysis time becomes very long
Solution Approach 1:
The frequency spectrum is divided into multiple frequency sub-bands, allowing parallel processing of different frequency ranges. This segmentation enables simultaneous analysis of multiple equipment across different bands, reducing total analysis time while maintaining detection precision in each sub-band
Solution Approach 2:
The method uses periodic frequency sweeps across the electromagnetic spectrum, systematically cycling through different frequency sub-bands. This periodic scanning approach allows comprehensive coverage of all equipment frequencies while enabling time-efficient sequential processing of multiple sub-bands
2Measurement precision
If narrowband analysis is performed to measure high signal-to-noise ratio, then measurement precision is improved, but analysis time increases proportionally to frequency band
Solution Approach 1:
The wide frequency spectrum is segmented into multiple narrower sub-bands. Each sub-band can be analyzed with narrowband techniques to maintain high signal-to-noise ratio, while the overall system achieves wideband coverage by processing multiple sub-bands in parallel or rapid succession
Solution Approach 2:
The analysis transitions from a single-dimensional time-domain approach to a two-dimensional frequency-time analysis by performing Fast Fourier Transform on demodulated signals. This dimensional change enables simultaneous frequency resolution and time efficiency through spectral analysis
3Productivity
If automated frequency sweep is performed across all equipment, then analysis time is reduced, but ability to discriminate between close frequencies is lost
Solution Approach 1:
The frequency spectrum is divided into sufficiently narrow sub-bands that signals from different equipment do not overlap within the same sub-band. This segmentation provides the frequency resolution needed to discriminate between close frequencies while maintaining high-speed automated processing across all sub-bands
Solution Approach 2:
The method performs analysis with finer frequency resolution than strictly necessary for each individual detection, using multiple overlapping or adjacent frequency sub-bands. This excessive precision in frequency resolution ensures that even closely spaced signals can be distinguished while maintaining overall system speed
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach significantly reduces analysis time, allows for parallel detection of compromised equipment, and provides precise identification and quantification of information leaks, enabling quick identification of security breaches without human intervention.
Implementation Method 1
Any equipment or system that processes or transmits information in electrical form produces electromagnetic interference
Implementation Method 2
Intercepting and analyzing it can allow for the reconstruction of that information
Data Source
Figure 1~2
Figure 3~5
AI summary
The invention relates to a method for detecting at least one compromised computer device (2) in an information system (1), the method comprising: performing a frequency scan involving dividing the electromagnetic spectrum into frequency sub-bands; performing, in each frequency sub-band, a time envelope demodulation in order to recover signals transmitted by at least one computer device (2) of the information system (1); converting each demodulated signal in the frequency domain; constructing a frequency spectrum on the basis of the demodulated signals in all the frequency sub-bands; finding, in each frequency sub-band of the frequency spectrum, at least one amplitude line having energy that is greater than a first predefined energy threshold; and, if at least one line having energy that is greater than the first predefined energy threshold is found, indicating the presence of at least one compromised computer device (2) transmitting compromising spurious signals.