Kill Switch Button for Suspected Malicious Code Suspension

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information security and data loss prevention technologies are inadequate for reliably suspending a computing device suspected of being infected by malicious code, particularly in terminating dependent systems, user accounts, and network connections.

Innovation Solution

A system and method utilizing a kill switch button to suspend a computing device by capturing and prioritizing the malicious code's instructions, isolating the device, and terminating network connections, thereby confining the malicious code and preventing its spread.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current information security technologies are used to terminate dependent systems from an infected computing device, then the malicious code can spread to other systems, but if traditional methods are used to isolate the device, then the process is slow and unreliable

Engineering Contradiction:
Improvereliability of suspending infected deviceVSAvoidtime to terminate dependent systems
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The kill switch button is pre-configured with prioritization logic that automatically elevates its process priority above all other running processes when triggered. This preliminary setup ensures immediate execution without waiting for system scheduling, capturing malicious code states before they can spread to dependent systems or network connections.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention extracts and isolates the malicious code by capturing its current execution states and storing them in memory. The kill switch then terminates the malicious processes and disconnects network connections, effectively separating the infected device from the network and preventing further propagation of the malware to other systems.

Inventive Principle:
Principle #2Taking out (Extraction)

2Productivity

If the kill switch button prioritizes over all other running processes, then the suspension executes without interruption and malicious code is suppressed, but the system requires a kill switch mechanism with prioritization capability

Engineering Contradiction:
Improvespeed of suspension executionVSAvoidcomplexity of kill switch mechanism
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The kill switch button changes the priority parameter of its process from a standard priority level to the highest priority level available in the operating system. This parameter change ensures that when the kill switch is triggered, its instructions are executed immediately before any other process, including malicious code, allowing rapid suspension of the infected device without requiring complex hardware modifications.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If network connections are terminated to isolate the infected device, then the malicious code cannot spread to connected systems, but the device becomes completely isolated and inaccessible for investigation

Engineering Contradiction:
Improveprevention of malicious code spreadVSAvoidaccess to infected device for investigation
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

Before terminating network connections and isolating the infected device, the kill switch button first captures the current execution states of all running processes, particularly the malicious code. These states are stored in the device's memory, preserving evidence for later investigation. Only after this preliminary evidence collection does the system proceed to disconnect network connections, ensuring that investigative capabilities are maintained despite isolation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11895147B2System and method for suspending a computing device suspected of being infected by a malicious code using a kill switch button
Publication Date: 2024.02.06 BANK OF AMERICA CORP
  • US11895147B2 patent drawing
  • US11895147B2 patent drawing

AI summary

A system for suspending a computing device suspected of being infected by a malicious code is configured to receive a signal to initiate a suspension procedure of the computing device. The system captures states of instructions that are being executed by a processor of the computing device, where the instructions comprise the malicious code. The system prioritizes the operation of a kill switch button over the instructions being executed by the processor. The system sends notification signals to servers managing a user account associated with a user currently logged in at the computing device, indicating that the computing device is suspected of having been infected by the malicious code. In response to sending the notification signals to the servers, the user account is suspended. The system terminates network connections of the computing device such that the computing device is disconnected from other devices.