Non-flashable Circuitry for Real-time Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current software-based security systems on networks are vulnerable to malware embedded in files and emails, as they rely on algorithms that may not detect new malware in a timely manner, leading to potential security compromises.

Innovation Solution

Implementing a hardware unit with non-flashable circuitry, such as ASICs or ROM chips, that connects to an application server and a client device, which detects and blocks data packets containing instructions for file operations like creation, insertion, deletion, or writing, thereby preventing unauthorized actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software-based security systems are used to detect malware, then the system can be updated with new malware signatures, but the system is vulnerable to unauthorized alteration and has inherent security weaknesses

Engineering Contradiction:
Improveability to update malware signaturesVSAvoidsecurity against unauthorized alteration
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system separates security functions into two distinct components: a software-based malware signature database that can be updated, and a hardware-based enforcement module with non-flashable circuitry that cannot be altered. This segmentation allows the system to maintain adaptability through software updates while ensuring reliability through immutable hardware enforcement of security policies.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If malware detection relies on comparing file content with known malware code in a database, then existing malware can be detected, but new malware during the time lapse cannot be detected

Engineering Contradiction:
Improveaccuracy of malware detectionVSAvoidtime lapse before new malware detection
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary analysis of file operations by monitoring and controlling access at the hardware level before files are fully executed or compromised. The non-flashable circuitry enforces security policies in advance, preventing unauthorized write operations, deletions, or modifications before they can execute, rather than waiting for malware signatures to be identified after the fact.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If hardware units with non-flashable circuitry are used for real-time detection, then new malware can be detected faster, but the system complexity increases

Engineering Contradiction:
Improvereal-time malware detection capabilityVSAvoidhardware circuitry implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hardware unit with non-flashable circuitry acts as an intermediary component between the software-based security system and the network resources. It serves as a dedicated enforcement module that translates security policies into hardware-level access controls, providing real-time protection without requiring complex integration throughout the entire system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12045350B1Apparatus, systems, and methods relying on non-flashable circuitry for improving security on public or private networks
Publication Date: 2024.07.23 ZECURITY LLC
  • US12045350B1 patent drawing
  • US12045350B1 patent drawing
  • US12045350B1 patent drawing

AI summary

A hardware unit relies on non-flashable circuitry for improving security on a public or private network. The hardware unit can be added to a network without substantial modifications to the other devices already connected to the network. The hardware unit detects, and sometimes blocks or drops, data packets or frames that contain an instruction of a known file-sharing protocol other than a reading instruction. Thus, potential malware may be detected instantaneously by what it attempts to do, typically the creation, insertion, deletion, update, renaming, or writing of files. The hardware unit is used for screening files or emails stored on a client device and reporting threats.