Parallel Control Program for Real-Time Anomaly Detection in Critical Software
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for testing critical computer programs are inadequate as they cannot exhaustively cover all possible scenarios, leading to delayed implementation and potential serious repercussions due to undetected bugs in critical applications.
Innovation Solution
Implementing a secondary control program that runs in parallel with the main program during the production phase to continuously monitor and detect anomalies without interrupting the main program, allowing for real-time anomaly detection and swift corrective actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If exhaustive testing is performed during the test phase, then program security is improved, but the test phase duration increases significantly
Solution Approach 1:
The patent applies preliminary action by implementing a control program during the test phase that proactively monitors and detects anomalies before they cause critical failures. This allows the system to identify issues early in the development cycle, improving security without requiring exhaustive post-deployment testing.
Solution Approach 2:
The patent introduces a control program as an intermediary between the main program and the testing process. This control program intercepts and monitors program execution, comparing actual behavior against expected behavior to detect anomalies. This intermediary approach enables continuous security verification during normal operation without requiring exhaustive separate testing phases.
2Productivity
If the test phase is shortened to accelerate implementation, then productivity is improved, but program security deteriorates
Solution Approach 1:
The patent applies continuity of useful action by maintaining anomaly detection capabilities throughout the entire operational lifecycle of the program, not just during limited test phases. The control program continues to monitor and detect anomalies during production use, ensuring continuous security verification without interrupting normal operations or requiring extended testing periods.
Solution Approach 2:
The control program is implemented and activated during the test phase, performing preliminary anomaly detection before full production deployment. This preliminary action establishes a safety net that allows shorter test phases while maintaining security, as the control program will continue detecting issues during operational phases.
3Reliability
If a control program is implemented to detect anomalies, then program security is improved, but system complexity increases
Solution Approach 1:
The control program is designed with universality by implementing a standardized anomaly detection mechanism that can monitor multiple different main programs across various applications. Rather than creating specialized monitoring systems for each program, the control program provides a universal solution that detects anomalies through common patterns, reducing overall system complexity while maintaining security.
4Reliability
If permanent monitoring is implemented during production phase, then anomaly detection capability is improved, but computational resources are consumed
Solution Approach 1:
The patent applies taking out by extracting only the critical monitoring functions needed for anomaly detection from the main program execution flow. The control program focuses specifically on comparing actual program behavior against expected behavior patterns, rather than monitoring all computational activities. This selective extraction reduces computational overhead while maintaining effective anomaly detection capability during production phase.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The method involves delivering output data (31) based on input data (20) during executing of critical portions, and delivering another output data (32) based on the input data during executing a checking program. The output data are compared, and anomaly information (33) is generated when the output data are different. The anomaly information is transmitted to a remote server, and a primary computer program (11) is continued based on the output data when one of the critical portions of the program is activated. Independent claims are also included for the following: (1) a device for securing utilization of a primary computer program driving a data receiving and delivery device (2) a method for updating a computer program driving a data receiving and delivery device (3) a server for updating a computer program driving a data receiving and delivery device.