Update Rollback Prevention Mechanism for System Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing systems face exploitation through rolling back to previous configurations, which allows hackers to bypass software updates and security patches, posing a risk to security and functionality.

Innovation Solution

Implementing a mechanism that queries the system's update status and compares it to expected responses to detect rollback attempts, taking appropriate actions such as warnings, disabling features, or updating the system if rollback is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software patches are provided to update systems, then security issues and software bugs are resolved, but hackers can roll back the system to exploit previous vulnerabilities

Engineering Contradiction:
Improvesystem securityVSAvoidrollback exploitation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by implementing a rollback prevention mechanism that is activated before the system can be rolled back. The mechanism includes a prevention module that monitors system configuration changes and detects rollback attempts before they can compromise security. This proactive approach ensures that even if hackers attempt to roll back to exploit vulnerabilities, the prevention mechanism is already in place to block such attempts.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback through a continuous monitoring system that tracks system configuration states and provides real-time information about potential rollback attempts. The prevention module receives feedback from system sensors and configuration monitors, analyzes this information to detect rollback patterns, and responds by blocking unauthorized changes. This closed-loop feedback mechanism ensures that security threats are identified and neutralized promptly.

Inventive Principle:
Principle #23Feedback

2Ease of repair

If the system allows rollback to previous configurations, then system flexibility and ease of repair are improved, but security patches become ineffective and system integrity is compromised

Engineering Contradiction:
Improvesystem configurabilityVSAvoidpatch effectiveness
Core Design Contradiction:
Ease of repairVSReliability

Solution Approach 1:

The patent applies segmentation by dividing the system configuration management into distinct segments: authorized configuration changes and unauthorized rollback attempts. The prevention module segments the configuration space by maintaining a record of legitimate update states and identifying any deviations from these states as potential rollbacks. This segmentation allows the system to permit necessary repairs and updates while blocking security-compromising rollbacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different rules to different system configuration states. Legitimate configuration changes and approved updates are permitted to maintain system flexibility and ease of repair, while suspected rollback attempts are blocked to preserve security. The prevention module evaluates each configuration change locally against security criteria, allowing beneficial changes while preventing harmful ones.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8756694B2Prevention of exploitation of update rollback
Publication Date: 2014.06.17 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8756694B2 patent drawing
  • US8756694B2 patent drawing
  • US8756694B2 patent drawing

AI summary

The exploitation of rolling back a system configuration to a previous system configuration is prevented by querying the update status of the system and comparing the received response with an expected response. If the comparison indicates that the update version of the system is older than the expected update version, the system is determined to have been rolled back. Accordingly, appropriate action is taken, such as sending a warning to the system, stopping the system from operating, disabling selected features, disconnecting the system from a network, banning the system from future connections to the network, and/or installing an update. The query can include a request for update version numbers of updates, times when updates were applied, predetermined questions, and an indication of the system (e.g., machine serial number, unique ID value).