Multi-Channel Protocol for Suspicious Operation Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional techniques for combating ransomware and malware attacks primarily focus on detection and notification, lacking the ability to prevent suspicious computer operations unless authorized by a legitimate user.

Innovation Solution

A multi-channel protocol is implemented, where a detection and control agent on a user's device suspends suspicious activities and sends a notification to an identity system, which requests verification from a secondary user device, ensuring only authorized operations proceed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional detection and notification techniques are used to combat malware attacks, then the system can detect and report suspicious activities, but the system lacks the ability to prevent unauthorized operations in real-time

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments security functionality into distinct components: detection agents on endpoints, identity systems for verification, and control mechanisms. This modular approach enables prevention capabilities without requiring complete system redesign, resolving the contradiction between enhanced security and system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An identity system acts as an intermediary between detection agents and user devices, verifying user identity and authorization status. This mediator enables real-time prevention of unauthorized operations while maintaining a manageable system architecture through centralized verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system suspends all suspicious operations for verification, then unauthorized operations are prevented, but legitimate user operations may be delayed

Engineering Contradiction:
Improveauthorization verification accuracyVSAvoidoperation completion time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

User identity and authorization status are verified in advance through the identity system before operations are suspended. This preliminary verification ensures that legitimate operations can be quickly resumed after suspension, reducing the time loss while maintaining accurate authorization verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback loops where verification results are communicated back to detection agents, which then adjust their suspension decisions. This feedback mechanism ensures that only truly suspicious operations are suspended, minimizing delays for legitimate user activities.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11005859B1Methods and apparatus for protecting against suspicious computer operations using multi-channel protocol
Publication Date: 2021.05.11 EMC IP HLDG CO LLC
  • US11005859B1 patent drawing
  • US11005859B1 patent drawing
  • US11005859B1 patent drawing

AI summary

Techniques are provided for preventing suspicious computer operations using a multi-channel protocol. An exemplary method includes detecting an operation comprising suspicious activity on a first device of a user; in response to the detecting, providing a control signal to suspend the operation on the first device; providing a notification of the suspicious activity to an identity system, wherein the identity system (i) provides an approval request to a distinct second device of the user to verify whether the operation is an authorized operation, (ii) receives a reply from the second device comprising an indication of whether the operation is an authorized operation, and (iii) notifies the first device of whether the operation is an authorized operation; and providing a control signal to enable the operation to proceed on the first device responsive to the reply from the second device indicating that the operation was an authorized operation.