Side-Channel Malware Detection for Incompatible Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computers and embedded systems, such as medical devices, are increasingly connected to the Internet, making them vulnerable to malware, but many are incompatible with anti-malware software due to custom firmware or manufacturer restrictions, preventing users from installing updates or third-party software.
Innovation Solution
A system that monitors target devices for malicious activity using side-channel analysis, such as power consumption, which can work independently of the device's software, processing data locally or in a cloud-based server with a machine-learning engine to detect anomalies and malware, including a monitoring device with a pass-through power circuit and current sensors to analyze power consumption patterns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional anti-malware software is installed on target devices, then malware detection capability is improved, but device compatibility deteriorates due to custom firmware or manufacturer restrictions
Solution Approach 1:
The patent introduces an external monitoring device that acts as an intermediary between the power source and the target device. This monitoring device captures side-channel signals (power consumption) from the target device without requiring any software installation or modification on the target device itself, thereby resolving the compatibility issue while maintaining malware detection capability
Solution Approach 2:
The patent replaces the traditional software-based malware detection system with a hardware-based side-channel analysis system. Instead of using software agents that run on the target device, the system uses external hardware monitoring devices to capture power consumption signals and analyze them for malicious activity, thus avoiding firmware compatibility issues
2Reliability
If anti-malware software is installed on target devices, then security protection is improved, but device operations are interfered with due to system resource consumption
Solution Approach 1:
The external monitoring device serves as an intermediary that performs all security analysis operations outside the target device. The monitoring device captures power consumption signals and performs malware detection independently, eliminating the need for anti-malware software to run on the target device and thus avoiding interference with normal operations
Solution Approach 2:
The patent extracts the malware detection function from the target device and relocates it to an external monitoring device. By taking out the security analysis capability from the target device's software environment, the system avoids consuming target device resources and interfering with its normal operations
3Reliability
If traditional anti-virus software is used, then malware detection is improved, but update frequency and maintenance complexity increase
Solution Approach 1:
The patent replaces the software-based anti-virus system with a hardware-based side-channel analysis system. The hardware monitoring device captures power consumption signals and uses machine learning models to detect malware, eliminating the need for frequent software updates and signature database maintenance that characterize traditional anti-virus solutions
Solution Approach 2:
The patent changes the detection parameter from software-based signatures and heuristics to hardware-based side-channel signals (power consumption). This parameter change enables the use of machine learning techniques that can adapt to new malware variants without requiring traditional software updates, thereby reducing maintenance complexity
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Effectively detects and classifies malicious activity without interfering with normal device operations, reducing the need for traditional anti-virus software updates and ensuring continuous monitoring of devices that cannot run anti-malware software, thereby enhancing security for incompatible devices.
Implementation Method 1
The system can include a hardware monitoring device that can work in conjunction with (or independently of) a cloud-based security analytics engine. The system can detect and process anomalies and malware in target devices, which traditionally cannot be monitored by anti-virus software. Installed external to the target device, the system can monitor the activity of the target device by analyzing side-channel phenomena such as, but not limited to, power consumption of the target device.
Data Source
AI summary
The present disclosure describes systems and methods for detecting malware. More particularly, the system includes a monitoring device that monitors side-channel activity of a target device. The monitoring device that can work in conjunction with (or independently of) a cloud-based security analytics engine to perform anomaly detection and classification on the side-channel activity. For example, the monitoring device can calculate a first set of features that are then transmitted to the security analytics engine for anomaly detection and classification.


