Dynamic Processing Resource Reconfiguration for Malware Defense
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer network security measures are inadequate in detecting and preventing highly sophisticated malicious software attacks, which can evade traditional antivirus systems and compromise network security by learning hardware and software structures, leading to data extraction and system disruption.
Innovation Solution
Implementing a security control module that routinely changes software applications and processing resources, using software creation tools to generate new versions quickly, and managing memory to render learned malicious software ineffective, thereby maintaining a dynamic and secure environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional antivirus software and security modules are used to detect and prevent malicious software, then low to moderate sophistication attacks can be detected and prevented, but highly sophisticated attacks can evade detection and compromise system security
Solution Approach 1:
The patent implements dynamic reconfiguration of processing resources by randomly assigning applications to different processing resources at each execution. This creates a moving target architecture where the mapping between applications and processing resources changes over time, preventing sophisticated malware from establishing stable exploitation paths or learning fixed hardware-software interaction patterns.
Solution Approach 2:
The patent creates a composite security architecture that combines multiple processing resources with different instruction sets (x86, ARM, MIPS, RISC-V) and multiple versions of the same application. This composite approach ensures that even if malware compromises one processing resource or application version, the system maintains security through diversity and can switch to alternative configurations.
2Reliability
If multiple versions of applications and operating systems are maintained to thwart malware learning, then security against sophisticated attacks is improved, but device complexity increases
Solution Approach 1:
The security control module automatically manages the complexity of maintaining multiple application versions and processing resource configurations. It performs random assignment of applications to processing resources, monitors for malware behavior, and dynamically reconfigures the system without requiring manual intervention. This self-service approach handles the complexity internally while presenting a simplified interface to users and administrators.
3Reliability
If processing resources are routinely changed to render learned malware ineffective, then the ability of malware to exploit vulnerabilities is reduced, but system performance and stability may be affected
Solution Approach 1:
The system implements periodic reconfiguration of processing resources at scheduled intervals or after a threshold number of executions. This periodic action balances security needs with performance considerations by maintaining stable configurations long enough to ensure system performance while periodically changing assignments to prevent malware learning. The security control module monitors system state and adjusts reconfiguration timing to optimize both security and performance.
Data Source
AI summary
A computing device includes central processing resources, memory, a network interface, and a security control module. The security control module determines when to change operation of a program of the computing device. When the operation of the program is to be changed, the security control module identifies a first processing resource of the central processing resources that is currently assigned to execute the program and selects a second processing resource of the central processing resources for subsequent execution the program. The security control module then ascertains first execution settings of the program as used by the first processing resource and facilitates conversion of the first execution settings into second execution settings for the second processing resource. The security control module then de-assigns the first processing resource from executing the program and assigns the second processing resource to execute the program.


