Selective Feature Deprivation for Zero-Day Threat Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for addressing vulnerabilities in computing systems are inadequate, as patches are often unavailable when vulnerabilities are discovered, and compensating controls are complex and ineffective, especially when attacks occur over encrypted protocols.
Innovation Solution
Implementing a feature deprivation system where computing systems are pre-configured to temporarily disable vulnerable features via deprivation tokens, enabling quick threat prevention until a permanent solution is available, without relying on detection or analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If patches are applied to address vulnerabilities, then system security is improved, but time loss occurs due to patch development, certification and distribution cycles
Solution Approach 1:
The system performs preliminary action by proactively disabling vulnerable features before patches are available. When a vulnerability is discovered, the feature controller immediately deactivates the affected feature, preventing exploits before they can occur. This eliminates the time loss associated with patch development and distribution while maintaining security.
Solution Approach 2:
The patent applies preliminary anti-action by preemptively disabling the vulnerable feature rather than waiting for an exploit to occur or a patch to be ready. The feature controller receives vulnerability information and immediately counteracts the potential threat by deactivating the feature, creating a preventive measure that exists before the harmful action can take place.
2Reliability
If compensating controls are implemented to limit exploit reach, then system security is improved, but device complexity increases due to pattern matching and heuristics requirements
Solution Approach 1:
The patent extracts the security function from complex network-based compensating controls and relocates it to the device itself through feature deactivation. Instead of relying on complex pattern matching and heuristics in network security infrastructure, the system directly removes the vulnerable feature at its source, simplifying the overall security architecture.
Solution Approach 2:
The feature controller acts as an intermediary between the vulnerable feature and the exploit. It receives vulnerability information and mediates by deactivating the feature, providing a simple and direct security mechanism without requiring complex pattern matching or heuristics that would increase device complexity.
3Reliability
If network security infrastructure is used to prevent exploits, then system security is improved, but loss of information occurs when attacks occur over encrypted protocols like TLS
Solution Approach 1:
The feature controller serves as an intermediary that operates independently of network security infrastructure. It receives vulnerability information and deactivates features directly on the device, eliminating the need for network-based security measures that cannot inspect encrypted TLS traffic. This approach maintains security without requiring decryption operations that would result in information loss.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method of preventing exploitation of a vulnerability of a computing system includes generating a deprivation token to cause disabling of a selected one or more features of a component of the computing system to prevent an exploit of a vulnerability affecting the selected one or more features; and publishing the derivation token to at least one of a computing system manufacturer computing system and an enterprise information technology (IT) computing system for distribution to affected computing systems.