Isolated Auditor System for Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing malware detection systems are vulnerable to compromise by malware, as any software running on a user system can be affected, making it difficult to effectively detect and stop unauthorized processes without disrupting the entire system.
Innovation Solution
An integrated processing unit with a user system and an auditor system, where the auditor system is isolated from the user system, allowing it to load auditing data and monitor processes independently, detect unauthorized processes, and perform security actions such as terminating malicious processes without being compromised by the user system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If anti-virus software is run on the user system to monitor for malware, then malware detection capability is improved, but the system becomes vulnerable to compromise by malware
Solution Approach 1:
The system divides the processing functions into two separate systems: a user system that runs applications and an auditor system that performs security monitoring. The auditor system includes a second processor and second computer storage medium that are physically isolated from the user system components. This segmentation allows malware detection to occur in a secure environment that cannot be compromised by malware running on the user system.
Solution Approach 2:
The auditor system acts as an intermediary between the user system and security analysis. It loads auditing data in isolation, monitors processes on the user system, and performs security analyses without being directly accessible by the user system or its potentially malicious processes. The auditor system mediates security functions while maintaining physical isolation to prevent compromise.
2Reliability
If the auditor system is physically isolated from the user system, then security reliability is improved, but device complexity increases
Solution Approach 1:
The integrated processing unit is segmented into distinct functional components: a user system with first processor and first computer storage medium, and an auditor system with second processor and second computer storage medium. The physical isolation between these components is achieved through separate processor units and storage media, creating clear security boundaries while maintaining an integrated overall system structure.
3Measurement precision
If the auditor system monitors processes independently in isolation, then detection accuracy is improved, but the system requires more resources
Solution Approach 1:
The auditor system performs multiple security functions using a single isolated infrastructure: loading auditing data, monitoring user system processes, analyzing process behavior, detecting unauthorized processes, and performing security responses. This multi-functional approach maximizes the utility of the isolated auditor system resources while maintaining high detection accuracy through independent analysis.
Data Source
AI summary
Methods, systems, and apparatus, including computer programs encoded on computer storage media, for security monitoring. In one aspect, a device includes an integrated processing unit, including a user system and an auditor system. The user system includes a first processor and a first computer storage medium. The auditor system includes a second processor that is isolated from the first processor and a second computer storage medium that is isolated from the first computer storage medium. The second computer storage medium stores instructions that cause the second processor to load auditing data in isolation from the user system, monitor processes on the user system, determine from the auditing data that one of the processes is an unauthorized process, and perform one or more security processes on the unauthorized process.


