Kill Switch Button for Suspected Malicious Code Suspension
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information security and data loss prevention technologies are inadequate for reliably suspending a computing device suspected of being infected by malicious code, particularly in terminating dependent systems, user accounts, and network connections.
Innovation Solution
A system and method utilizing a kill switch button to suspend a computing device by capturing and prioritizing the malicious code's instructions, isolating the device, and terminating network connections, thereby confining the malicious code and preventing its spread.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current information security technologies are used to terminate dependent systems from an infected computing device, then the malicious code can spread to other systems, but if traditional methods are used to isolate the device, then the process is slow and unreliable
Solution Approach 1:
The kill switch button is pre-configured with prioritization logic that automatically elevates its process priority above all other running processes when triggered. This preliminary setup ensures immediate execution without waiting for system scheduling, capturing malicious code states before they can spread to dependent systems or network connections.
Solution Approach 2:
The invention extracts and isolates the malicious code by capturing its current execution states and storing them in memory. The kill switch then terminates the malicious processes and disconnects network connections, effectively separating the infected device from the network and preventing further propagation of the malware to other systems.
2Productivity
If the kill switch button prioritizes over all other running processes, then the suspension executes without interruption and malicious code is suppressed, but the system requires a kill switch mechanism with prioritization capability
Solution Approach 1:
The kill switch button changes the priority parameter of its process from a standard priority level to the highest priority level available in the operating system. This parameter change ensures that when the kill switch is triggered, its instructions are executed immediately before any other process, including malicious code, allowing rapid suspension of the infected device without requiring complex hardware modifications.
3Object-affected harmful factors
If network connections are terminated to isolate the infected device, then the malicious code cannot spread to connected systems, but the device becomes completely isolated and inaccessible for investigation
Solution Approach 1:
Before terminating network connections and isolating the infected device, the kill switch button first captures the current execution states of all running processes, particularly the malicious code. These states are stored in the device's memory, preserving evidence for later investigation. Only after this preliminary evidence collection does the system proceed to disconnect network connections, ensuring that investigative capabilities are maintained despite isolation.
Data Source
AI summary
A system for suspending a computing device suspected of being infected by a malicious code is configured to receive a signal to initiate a suspension procedure of the computing device. The system captures states of instructions that are being executed by a processor of the computing device, where the instructions comprise the malicious code. The system prioritizes the operation of a kill switch button over the instructions being executed by the processor. The system sends notification signals to servers managing a user account associated with a user currently logged in at the computing device, indicating that the computing device is suspected of having been infected by the malicious code. In response to sending the notification signals to the servers, the user account is suspended. The system terminates network connections of the computing device such that the computing device is disconnected from other devices.

