Network Device APT Protection via Memory Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network-connected devices, such as bar code scanners and payment terminals, are vulnerable to Advanced Persistent Threats (APT) attacks, where malware or contaminated firmware can be loaded before shipment, allowing access to sensitive data once connected to a network.
Innovation Solution
A method and system that involves detecting rogue software in the memory instructions of network-connected devices by authenticating executable program instructions using checksum block routines and locking down communications if unauthorized instructions are found, utilizing public key and private key cryptography or two-factor authentication to protect against APT attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network-connected devices are deployed with standard software and communication capabilities, then device functionality and connectivity are improved, but vulnerability to APT attacks increases
Solution Approach 1:
The patent implements preliminary authentication of memory instructions before execution by installing checksum block routines at a low level in the operating system. These routines generate checksums of memory instructions and compare them against expected values, preventing execution of unauthorized or malicious code. This preliminary security check is performed before APT attacks can compromise the device, thereby maintaining device functionality while preventing vulnerability exploitation.
2Reliability
If checksum authentication is performed on all memory instructions, then security against APT is improved, but device performance and execution speed deteriorate
Solution Approach 1:
The patent performs checksum authentication in advance during system initialization and before memory instructions are executed. The checksum block routines are installed at a low level in the operating system and automatically authenticate memory instructions as they are loaded into memory, before malicious code can be injected or activated. This preliminary authentication approach ensures security without requiring continuous verification during execution, thus maintaining device performance.
3Difficulty of detecting and measuring
If low-level routines are installed for instruction authentication, then detection capability is improved, but device complexity increases
Solution Approach 1:
The patent implements a self-service security mechanism where the operating system itself provides authentication capabilities through checksum block routines installed at a low level. These routines are integrated into the OS kernel and automatically perform authentication of memory instructions without requiring external security software or complex additional components. The system serves its own security needs through built-in cryptographic verification, thereby improving detection capability while minimizing added complexity.
4Reliability
If communications are locked down upon detecting rogue software, then network security is improved, but device usability deteriorates
Solution Approach 1:
The patent implements preliminary anti-action by preventing rogue software execution through checksum authentication before it can compromise network security. The checksum block routines detect unauthorized memory instructions and prevent their execution, thereby neutralizing potential APT threats before they can initiate malicious communications. This preventive approach maintains network security while avoiding the need to lock down communications, thus preserving device usability.
Data Source
AI summary
A method of protecting a network-connected device from an advanced persistent threat cyber-attack is provided. A network-connected device having an operating system, a memory, memory instructions holding executable program instructions, and being communication enabled, is protected from an advanced persistent threat by steps of detecting the advanced persistent threat due to the presence of rogue software in the memory instructions of the network-connected device and locking-down the communications of the network-connected device. The network-connected device may be provided with low-level routines that are correlated to the memory instructions. Detecting the advanced persistent threat may be comprised of authenticating the memory instructions of the network-connected device by using the installed low-level routines.


