Multi-Tier ML Engine Detects Unauthorized Code via RF Emanations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current monitoring systems for computing platforms, especially in IoT devices, face challenges in detecting unauthorized code and hardware without direct communication, as they struggle to accurately differentiate between authorized and unauthorized operations amidst interference and varying environmental conditions.
Innovation Solution
A modular machine learning system employing a multi-tier architecture, including frequency and time domain analysis, uses RF emanations and power consumption data to identify applications, modules, and control flow paths, while a hierarchical Dynamic Bayesian Network (DBN) curtails interference and predicts unauthorized code execution, enabling air-gapped monitoring without external shielding.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If air gapping is used to physically isolate the computing platform from unsecured networks, then security is improved, but the ability to monitor and detect unauthorized code is worsened
Solution Approach 1:
The patent introduces electromagnetic field emissions as an intermediary carrier that transmits information from the air-gapped computing platform to the monitoring system. The monitoring system captures and analyzes these electromagnetic emissions to detect unauthorized code execution, thus enabling security monitoring without direct network connection and maintaining the air gap while overcoming its detection limitations
Solution Approach 2:
The patent replaces traditional mechanical/physical connection-based monitoring (requiring direct network access) with electromagnetic field-based monitoring. By substituting the physical connection requirement with electromagnetic signal capture, the system can monitor the air-gapped platform remotely without compromising security isolation
2Difficulty of detecting and measuring
If traditional monitoring systems attempt to detect unauthorized code in air-gapped environments, then detection capability is improved, but accuracy in differentiating authorized from unauthorized operations is worsened due to interference
Solution Approach 1:
The patent extracts and removes interference signals from the electromagnetic emissions data before analysis. By separating the useful signal containing information about code execution from the interfering background noise, the system improves detection accuracy and can reliably distinguish between authorized and unauthorized operations even in noisy environments
Solution Approach 2:
The patent converts the presence of interference signals, which initially seem harmful to detection accuracy, into a beneficial feature. By analyzing the characteristics of interference and using it as part of the signal processing pipeline, the system learns to filter and differentiate between legitimate operational signals and interference, ultimately improving its ability to detect unauthorized code
Data Source
AI summary
A multi-tier machine learning engine receives signal data characterizing a monitored signal of the computing platform. The machine learning engine can include a plurality of tiers that employ frequency domain analysis on the signal data to identify an application executing on the computing platform and a module and/or loop of the identified application and employ time domain analysis on the signal data to identify timing of events within the identified module and/or loop of the identified application.


