Multi-Tier ML Engine Detects Unauthorized Code via RF Emanations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current monitoring systems for computing platforms, especially in IoT devices, face challenges in detecting unauthorized code and hardware without direct communication, as they struggle to accurately differentiate between authorized and unauthorized operations amidst interference and varying environmental conditions.

Innovation Solution

A modular machine learning system employing a multi-tier architecture, including frequency and time domain analysis, uses RF emanations and power consumption data to identify applications, modules, and control flow paths, while a hierarchical Dynamic Bayesian Network (DBN) curtails interference and predicts unauthorized code execution, enabling air-gapped monitoring without external shielding.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If air gapping is used to physically isolate the computing platform from unsecured networks, then security is improved, but the ability to monitor and detect unauthorized code is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddetection capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces electromagnetic field emissions as an intermediary carrier that transmits information from the air-gapped computing platform to the monitoring system. The monitoring system captures and analyzes these electromagnetic emissions to detect unauthorized code execution, thus enabling security monitoring without direct network connection and maintaining the air gap while overcoming its detection limitations

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical/physical connection-based monitoring (requiring direct network access) with electromagnetic field-based monitoring. By substituting the physical connection requirement with electromagnetic signal capture, the system can monitor the air-gapped platform remotely without compromising security isolation

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Difficulty of detecting and measuring

If traditional monitoring systems attempt to detect unauthorized code in air-gapped environments, then detection capability is improved, but accuracy in differentiating authorized from unauthorized operations is worsened due to interference

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetection accuracy
Core Design Contradiction:
Difficulty of detecting and measuringVSMeasurement precision

Solution Approach 1:

The patent extracts and removes interference signals from the electromagnetic emissions data before analysis. By separating the useful signal containing information about code execution from the interfering background noise, the system improves detection accuracy and can reliably distinguish between authorized and unauthorized operations even in noisy environments

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent converts the presence of interference signals, which initially seem harmful to detection accuracy, into a beneficial feature. By analyzing the characteristics of interference and using it as part of the signal processing pipeline, the system learns to filter and differentiate between legitimate operational signals and interference, ultimately improving its ability to detect unauthorized code

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS11625633B2Machine learning to monitor operations of a device
Publication Date: 2023.04.11 NORTHROP GRUMMAN SYSTEMS CORP
  • US11625633B2 patent drawing
  • US11625633B2 patent drawing
  • US11625633B2 patent drawing

AI summary

A multi-tier machine learning engine receives signal data characterizing a monitored signal of the computing platform. The machine learning engine can include a plurality of tiers that employ frequency domain analysis on the signal data to identify an application executing on the computing platform and a module and/or loop of the identified application and employ time domain analysis on the signal data to identify timing of events within the identified module and/or loop of the identified application.