Object Header Stamper for Brute Force Attack Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cyber-security solutions, such as antivirus and firewall systems, often cannot keep pace with new threats, making it difficult for organizations to protect their networks and systems from intrusions and data theft, especially in industrial control systems and commercial settings where user authentication parameters can be vulnerable to brute force attacks.
Innovation Solution
The implementation of a stamper and detector system that modifies the header of protected files and applications to include a list of approved programs, preventing unauthorized access by interrupting and denying access to applications not included in this list, even if user authentication parameters are compromised.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication parameters (firewalls, user authentication) are used to protect data and applications, then basic security access control is provided, but the system remains vulnerable to brute force attacks and cannot keep pace with new threats
Solution Approach 1:
The system performs preliminary actions by modifying the header of protected objects to include an approved applications list before any access attempts occur. This pre-configured security measure enables the system to proactively identify and block unauthorized applications before they can execute brute force attacks, rather than relying solely on reactive authentication mechanisms.
Solution Approach 2:
The patent introduces an intermediary security layer that operates between the application and the protected object. The detector service acts as this intermediary, intercepting access requests and verifying whether the attempting application is in the approved list within the object header, thereby blocking malicious applications before they can reach the authentication parameters.
2Reliability
If antivirus and firewall solutions are deployed to protect networks and systems, then known threats are blocked, but these solutions cannot keep pace with new and evolving threats
Solution Approach 1:
The system embeds security information directly into the object header during the preliminary setup phase, creating a self-contained approved applications list. This preliminary action ensures that when new threats emerge, the system can immediately block them by checking against the pre-configured header information without requiring updates to external antivirus databases or firewall rules.
Solution Approach 2:
The protected object essentially serves its own security verification needs through the embedded header information. The detector service reads the approved applications list directly from the object header and performs autonomous verification, eliminating the need for external security systems to continuously update their threat databases to maintain effectiveness.
3Ease of operation
If user authentication parameters are used to control access to files and applications, then authorized users can access protected resources, but the authentication parameters themselves can be compromised through brute force attacks
Solution Approach 1:
The system introduces an intermediary security check in the form of the detector service that operates between the application and the authentication mechanism. This intermediary verifies the application's legitimacy by checking against the approved applications list in the object header before allowing access to authentication parameters, thereby protecting the credentials even from authorized users' applications.
Solution Approach 2:
The approved applications list is preliminarily configured in the object header before any access attempts. This preliminary action ensures that even if authentication parameters are exposed, only pre-approved applications can utilize them, preventing brute force attacks from compromising the authentication credentials.
Data Source
AI summary
A method, an electronic device, a computer readable medium is disclosed. The method includes modifying a header of an object to include a list of applications or files. The method also includes responsive to an application attempting to access the object, interrupting access to the object. The method further includes determining whether the application that is attempting to access the object is approved based on identifying at least one application or file included in the list of the modified header that corresponds to the application. The method also includes preventing the application from accessing the object when it is determined that the application is not included in the list of the modified header.


