Ensemble Moving Target Defense Architecture for Control-Flow Attack Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security methods fail to effectively secure complex computer systems against attacks due to the impossibility of using provably secure design techniques in real-world hardware and software environments, as attackers can always find vulnerabilities and bypass protections, necessitating a new approach to defend against a broad array of attacks.

Innovation Solution

Implementing an ensemble of moving target defenses (EMTDs) with independently composable defenses that change over time, providing layered protection for attack information assets, requiring attackers to overcome multiple defenses simultaneously and within a limited time frame, thereby increasing the difficulty of successful attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security verification proofs are used to secure computer systems, then security protection is provided for constrained environments, but the approach fails for general software and hardware due to immense complexity

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the security protection approach into segments: instead of attempting to verify the entire complex system, it identifies and protects only the critical attack information assets (code, data, pointers) that attackers need to succeed. This segmentation allows security to be applied effectively without requiring verification of the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the essential elements required for attacks (attack information assets) from the complex system and applies targeted protection to these specific extracted elements. By taking out only the critical assets needed for vulnerability exploitation, the system achieves security without needing to protect or verify the entire complex system.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If multiple composable defense layers are implemented to protect against attacks, then security protection is enhanced, but the complexity of the defense system increases

Engineering Contradiction:
Improvesecurity protectionVSAvoiddefense system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic defense layers that change over time through churn cycles. The composable layers (encryption, disposition, domain enforcement) are not static but dynamically reconfigured, which enhances security by preventing attackers from adapting to fixed defenses while managing complexity through systematic dynamic behavior.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent nests multiple composable defense layers (encryption layer, disposition layer, domain enforcement layer) where each layer operates independently but contributes to overall security. These nested layers protect attack information assets simultaneously, with each layer adding protection without requiring the entire defense system to be redesigned.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If composable defense layers are changed at runtime through churn cycles, then moving target defense is achieved, but the time required for reconfiguration increases

Engineering Contradiction:
Improvemoving target defenseVSAvoidreconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic churn cycles where composable defense layers are reconfigured at scheduled intervals. This periodic action creates moving target defense by systematically changing encryption keys, disposition offsets, and domain enforcement rules, while the periodic nature allows the system to manage reconfiguration time predictably and maintain operational continuity.

Inventive Principle:
Principle #19Periodic action

4Reliability

If layered composable defenses are applied to protect attack information assets, then protection against known and unknown attacks is improved, but the difficulty of system operation increases

Engineering Contradiction:
Improveattack protectionVSAvoidsystem operation ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service mechanisms where the composable layers automatically manage their own operation. The encryption layer handles key management, the disposition layer manages offset calculations, and the domain enforcement layer handles policy verification without requiring manual intervention. This automation maintains ease of operation while providing comprehensive layered protection.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11748490B2Computer system with moving target defenses against vulnerability attacks
Publication Date: 2023.09.05 THE RGT UNIV OF MICHIGAN
  • US11748490B2 patent drawing
  • US11748490B2 patent drawing
  • US11748490B2 patent drawing

AI summary

A computer system includes an ensemble moving target defense architecture that protects the computer system against attack using one or more composable protection layers that change each churn cycle, thereby requiring an attacker to acquire information needed for an attack (e.g., code and pointers) and successfully deploy the attack, before the layers have changed state. Each layer may deploy a respective attack information asset protection providing multiple respective attack protections each churn cycle, wherein the respective attack information asset protections may differ.