Kernel Driver Dynamic Protection Levels for Cyberattack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security systems are unable to dynamically adjust protection levels during a cyberattack, often resulting in either inadequate protection or overly restrictive lockdown modes that are not sustainable.

Innovation Solution

A method that utilizes a kernel driver to monitor for cyberattacks, dynamically adjusting access restrictions by configuring different protection levels based on system metadata, including the use of machine learning algorithms to identify affected kernel control paths and hashes, and temporarily increasing security measures to mitigate damage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security systems increase protection levels during a cyberattack, then security effectiveness is improved, but system usability deteriorates due to overly restrictive lockdown modes

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsystem usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic protection level adjustment by transitioning from static conventional security modes to a multi-level dynamic system. The kernel driver continuously monitors system state and adjusts protection levels in real-time, allowing the system to adapt between normal operation, elevated protection, and lockdown modes based on actual threat conditions, thereby resolving the contradiction between security effectiveness and usability

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of protection level from fixed to variable. By introducing multiple protection levels (normal, elevated, lockdown) and dynamically adjusting which level is active based on detected cyberattack conditions, the system optimizes both security effectiveness and usability by applying restrictive measures only when and where needed

Inventive Principle:
Principle #35Parameter changes

2Reliability

If conventional security systems maintain constant high protection levels, then security effectiveness is improved, but system productivity deteriorates due to continuous restrictions

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsystem productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements periodic monitoring and evaluation of protection level requirements. The kernel driver continuously assesses system state and periodically adjusts protection levels, maintaining high security only during actual attack periods while returning to normal operation when threats are neutralized, thus preserving productivity during safe periods

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

By making protection levels dynamic rather than constant, the system ensures high security effectiveness during cyberattacks while maintaining normal productivity during safe operation periods. The automatic transition between protection levels eliminates the need for constant high-level restrictions

Inventive Principle:
Principle #15Dynamics

3Reliability

If conventional security systems implement lockdown mode, then security effectiveness is improved, but ease of operation deteriorates due to excessive access restrictions

Engineering Contradiction:
Improvesecurity effectivenessVSAvoiduser-friendliness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by implementing protection level adjustments in specific kernel control paths and software objects rather than system-wide lockdown. The kernel driver identifies and restricts access only to the specific paths and objects affected by the cyberattack, leaving other system functions operating normally, thus maintaining user-friendliness while improving security effectiveness

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system segments the protection mechanism into multiple independent protection levels and applies them selectively to different kernel control paths and software objects. This segmentation allows lockdown measures to be applied locally to affected areas rather than globally, preserving ease of operation for unaffected system functions

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11914724B2Systems and methods for adjusting data protection levels based on system metadata
Publication Date: 2024.02.27 ACRONIS INT
  • US11914724B2 patent drawing
  • US11914724B2 patent drawing
  • US11914724B2 patent drawing

AI summary

Disclosed herein are systems and method for adjusting data protection levels based on system metadata. A method may include monitoring a computing device for a cyberattack, wherein a kernel driver of the computing device is configured to allow access to kernel control paths and hash tables in accordance with a first protection level, and detecting that the cyberattack is in progress. While the cyberattack is in progress, the method may include identifying kernel control paths and hashes of software objects that will be affected by the cyberattack, and configuring the kernel driver to disable access to the identified kernel control paths and hashes of the software objects in accordance with a second protection level, wherein the second protection level includes greater access restrictions to the computing device than the first protection level.