Hardware USB Threat Detection via Physical Layer ML

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current software-based solutions for protecting sensitive computing environments from insider threats, such as malicious USB devices, are inadequate as they can be circumvented by attackers and rely on untrusted hardware and operating systems, lacking effective detection and prevention mechanisms at the physical layer.

Innovation Solution

A hardware-based framework utilizing machine learning methods to analyze USB devices at the physical layer, collecting and processing data to classify devices as benign or malicious, preventing malicious devices from transmitting signals to the computing environment, and allowing benign devices to function normally, using features like key transition time and duration held.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If software-based solutions are used to protect against insider threats, then ease of implementation and maintenance are improved, but reliability and security are worsened because attackers can circumvent these defensive barriers

Engineering Contradiction:
Improveease of implementationVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent replaces software-based security mechanisms with a hardware-based system implemented on an FPGA. The USB bus interface is monitored at the hardware level, collecting raw signals before they reach the operating system. This hardware-based approach creates a trust root that cannot be compromised by software malware or attacks, as the security functions are embedded in dedicated hardware logic rather than software layers that can be modified or circumvented by attackers.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If hardware-based detection is implemented at the physical layer, then reliability and detection capability are improved, but device complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal hardware-based detection system on an FPGA that can monitor multiple USB devices simultaneously through a single bus interface. The system collects raw signals from any USB device connected to the bus and applies the same detection algorithms universally, rather than requiring separate hardware modules for each device type. This multi-functional approach achieves high detection capability while avoiding the complexity of device-specific hardware implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary hardware layer between the USB devices and the operating system. The FPGA acts as a mediator that intercepts raw USB signals, performs detection and classification, and only allows benign devices to communicate with the host system. This intermediary approach enables sophisticated detection capabilities without requiring direct integration of complex detection logic into the operating system or USB controllers, thereby managing device complexity effectively.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If machine learning methods are used to classify devices, then measurement precision and accuracy are improved, but use of energy and computational resources increase

Engineering Contradiction:
Improveclassification accuracyVSAvoidcomputational resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary classification of USB devices at the hardware level before the devices establish full communication with the host system. The FPGA collects raw USB signals and executes machine learning-based classification algorithms in real-time during the initial connection phase. By performing this classification action preliminarily, the system achieves high measurement precision in identifying malicious devices while minimizing computational resource consumption, as the classification occurs before any resource-intensive data transfer or system integration takes place.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11132441B2Systems and methods for inhibiting threats to a computing environment
Publication Date: 2021.09.28 FLORIDA INTERNATIONAL UNIVERSITY
  • US11132441B2 patent drawing
  • US11132441B2 patent drawing
  • US11132441B2 patent drawing

AI summary

Novel hardware-based frameworks and methods for the detection and inhibition or prevention of insider threats utilizing machine learning methods and data collection done at the physical layer are provided. Analysis is done on unknown USB-powered devices, such as a keyboard or mouse, introduced to a computing environment and, through the utilization of machine learning, the behavior of the unknown device is determined before it can potentially cause harm to the computing environment.