Proxy Gateway Side Attack Detection via File Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote desktop and SSH protocols are vulnerable to side security attacks, which can expose target systems to breaches by creating privileged accounts, necessitating improved security measures to protect sensitive configuration files.

Innovation Solution

A method and system for detecting side attacks by recording and verifying the integrity of sensitive configuration files through a proxy gateway, which establishes a primary connection, verifies file integrity post-secondary connection, and alerts administrators upon compromise, potentially replacing compromised files and notifying them of detected threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a user connects directly to the target system, then authentication is simplified, but the target becomes vulnerable to side security attacks

Engineering Contradiction:
Improveauthentication processVSAvoidside security attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a proxy gateway as an intermediary system between the user and the target system. The gateway establishes a primary connection to the target and a secondary connection to the user, acting as a mediator that enables authentication while preventing direct access. This resolves the contradiction by maintaining ease of authentication through the proxy while blocking direct side attacks on the target system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If privileged access is granted to serve user requests, then service capability is improved, but the target is exposed to side security attacks

Engineering Contradiction:
Improveservice capabilityVSAvoidside security attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the connection into two separate channels: a primary connection from the gateway to the target system with privileged access, and a secondary connection from the gateway to the user. This segmentation allows the target to maintain privileged service capabilities while the gateway controls and monitors all user interactions, preventing direct side attacks even when privileged access is active.

Inventive Principle:
Principle #1Segmentation

3Reliability

If file integrity verification is implemented, then security against side attacks is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity against side attacksVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by recording hash values of sensitive configuration files on the target system before the user connection is established. The proxy gateway stores these baseline hash values and uses them for subsequent integrity verification. This preliminary recording simplifies the verification process compared to other integrity check methods, as it only requires hash comparison rather than full file analysis, thus improving security while limiting the increase in system complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12069068B2Method and device for detecting compromise of a target by a side attack
Publication Date: 2024.08.20 WALLIX
  • US12069068B2 patent drawing
  • US12069068B2 patent drawing

AI summary

A method for detecting a side attack of a target by a user comprising a step of recording data relating to a so-called sensitive file, the sensitive file being a configuration file of the target; a step of primary connection of the user on a proxy gateway to establish a secondary connection of the proxy gateway on the target; a step of verification of the integrity of the sensitive file, subsequently to the step of secondary connection of the proxy gateway on the target and when the integrity of the sensitive tile is determined as compromised by the step of verification of the integrity of the sensitive file, and a step of detection of a side attack of the target by the user.