Multi-Channel Protocol for Suspicious Operation Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques for combating ransomware and malware attacks primarily focus on detection and notification, lacking the ability to prevent suspicious computer operations unless authorized by a legitimate user.
Innovation Solution
A multi-channel protocol is implemented, where a detection and control agent on a user's device suspends suspicious activities and sends a notification to an identity system, which requests verification from a secondary user device, ensuring only authorized operations proceed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional detection and notification techniques are used to combat malware attacks, then the system can detect and report suspicious activities, but the system lacks the ability to prevent unauthorized operations in real-time
Solution Approach 1:
The system segments security functionality into distinct components: detection agents on endpoints, identity systems for verification, and control mechanisms. This modular approach enables prevention capabilities without requiring complete system redesign, resolving the contradiction between enhanced security and system complexity.
Solution Approach 2:
An identity system acts as an intermediary between detection agents and user devices, verifying user identity and authorization status. This mediator enables real-time prevention of unauthorized operations while maintaining a manageable system architecture through centralized verification.
2Reliability
If the system suspends all suspicious operations for verification, then unauthorized operations are prevented, but legitimate user operations may be delayed
Solution Approach 1:
User identity and authorization status are verified in advance through the identity system before operations are suspended. This preliminary verification ensures that legitimate operations can be quickly resumed after suspension, reducing the time loss while maintaining accurate authorization verification.
Solution Approach 2:
The system implements feedback loops where verification results are communicated back to detection agents, which then adjust their suspension decisions. This feedback mechanism ensures that only truly suspicious operations are suspended, minimizing delays for legitimate user activities.
Data Source
AI summary
Techniques are provided for preventing suspicious computer operations using a multi-channel protocol. An exemplary method includes detecting an operation comprising suspicious activity on a first device of a user; in response to the detecting, providing a control signal to suspend the operation on the first device; providing a notification of the suspicious activity to an identity system, wherein the identity system (i) provides an approval request to a distinct second device of the user to verify whether the operation is an authorized operation, (ii) receives a reply from the second device comprising an indication of whether the operation is an authorized operation, and (iii) notifies the first device of whether the operation is an authorized operation; and providing a control signal to enable the operation to proceed on the first device responsive to the reply from the second device indicating that the operation was an authorized operation.


