Ensemble Moving Target Defense Architecture for Control-Flow Attack Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security methods fail to effectively secure complex computer systems against attacks due to the impossibility of using provably secure design techniques in real-world hardware and software environments, as attackers can always find vulnerabilities and bypass protections, necessitating a new approach to defend against a broad array of attacks.
Innovation Solution
Implementing an ensemble of moving target defenses (EMTDs) with independently composable defenses that change over time, providing layered protection for attack information assets, requiring attackers to overcome multiple defenses simultaneously and within a limited time frame, thereby increasing the difficulty of successful attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security verification proofs are used to secure computer systems, then security protection is provided for constrained environments, but the approach fails for general software and hardware due to immense complexity
Solution Approach 1:
The patent divides the security protection approach into segments: instead of attempting to verify the entire complex system, it identifies and protects only the critical attack information assets (code, data, pointers) that attackers need to succeed. This segmentation allows security to be applied effectively without requiring verification of the entire system.
Solution Approach 2:
The patent extracts the essential elements required for attacks (attack information assets) from the complex system and applies targeted protection to these specific extracted elements. By taking out only the critical assets needed for vulnerability exploitation, the system achieves security without needing to protect or verify the entire complex system.
2Reliability
If multiple composable defense layers are implemented to protect against attacks, then security protection is enhanced, but the complexity of the defense system increases
Solution Approach 1:
The patent implements dynamic defense layers that change over time through churn cycles. The composable layers (encryption, disposition, domain enforcement) are not static but dynamically reconfigured, which enhances security by preventing attackers from adapting to fixed defenses while managing complexity through systematic dynamic behavior.
Solution Approach 2:
The patent nests multiple composable defense layers (encryption layer, disposition layer, domain enforcement layer) where each layer operates independently but contributes to overall security. These nested layers protect attack information assets simultaneously, with each layer adding protection without requiring the entire defense system to be redesigned.
3Reliability
If composable defense layers are changed at runtime through churn cycles, then moving target defense is achieved, but the time required for reconfiguration increases
Solution Approach 1:
The patent implements periodic churn cycles where composable defense layers are reconfigured at scheduled intervals. This periodic action creates moving target defense by systematically changing encryption keys, disposition offsets, and domain enforcement rules, while the periodic nature allows the system to manage reconfiguration time predictably and maintain operational continuity.
4Reliability
If layered composable defenses are applied to protect attack information assets, then protection against known and unknown attacks is improved, but the difficulty of system operation increases
Solution Approach 1:
The patent implements self-service mechanisms where the composable layers automatically manage their own operation. The encryption layer handles key management, the disposition layer manages offset calculations, and the domain enforcement layer handles policy verification without requiring manual intervention. This automation maintains ease of operation while providing comprehensive layered protection.
Data Source
AI summary
A computer system includes an ensemble moving target defense architecture that protects the computer system against attack using one or more composable protection layers that change each churn cycle, thereby requiring an attacker to acquire information needed for an attack (e.g., code and pointers) and successfully deploy the attack, before the layers have changed state. Each layer may deploy a respective attack information asset protection providing multiple respective attack protections each churn cycle, wherein the respective attack information asset protections may differ.


