System and method for network intrusion detection based on physical measurements

US11683341B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11683341-B2
Application numberUS-201916723861-A
CountryUS
Kind codeB2
Filing dateDec 20, 2019
Priority dateDec 20, 2019
Publication dateJun 20, 2023
Grant dateJun 20, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system includes a memory and a processor in communication with the memory. The processor is programmed to receive a runtime measurement from a sensor regarding the physical attribute of at least the separate processor during runtime; compare the runtime measurement of the physical attribute to a fingerprint that includes a baseline measurement of a physical attribute of at least a separate processor during an evaluation period of the system, and in response to the measurement exceeding a threshold, executing a countermeasure operation against software ran by the separate processor.

First claim

Opening claim text (preview).

What is claimed is: 1. A system comprising: memory; a processor in communication with the memory and programmed to: during an enrollment period, define a fingerprint that includes a baseline measurement of a physical attribute of at least a separate processor during the enrollment period of the system in a secured environment using Original Equipment Manufacturer (OEM) components to establish normalized measurements, wherein the enrollment period includes measuring the physical attribute of the separate processor prior to runtime operation; receive, from a sensor, a runtime measurement of the physical attribute of at least the separate processor during runtime; compare the runtime measurement of the physical attribute to the fingerprint; and in response to the runtime measurement exceeding a threshold, executing a countermeasure operation against software ran by the separate processor. 2. The system of claim 1 , wherein the physical attribute includes a power consumption. 3. The system of claim 1 , wherein the physical attribute includes a time interval between message communications of the separate processor. 4. The system of claim 1 , wherein the physical attribute includes a sound emitted from the separate processor. 5. The system of claim 1 , wherein the physical attribute includes a temperature. 6. The system of claim 1 , wherein the physical attribute includes a vibration. 7. The system of claim 1 , wherein the memory is configured to store the fingerprint. 8. The system of claim 1 , wherein the processor is further programmed to, in response to the measurement exceeding a threshold, log the measurement and store the log in the memory. 9. The system of claim 1 , wherein the sensor is a shunt resistor. 10. The system of claim 1 , wherein the fingerprint includes two or more physical attributes of at least the separate processor during the enrollment period of the system. 11. A computer-implement method, comprising: defining a fingerprint that includes a baseline measurement of one or more physical attributes of at least a separate processor during an enrollment period of a system in a secured environment using Original Equipment Manufacturer (OEM) components to establish normalized measurements, wherein the fingerprint includes code utilized to identify normal operation of the system utilizing one or more measurements of the one or more physical attributes; receiving a runtime measurement from a sensor regarding the one or more physical attributes of at least the separate processor during runtime; comparing the runtime measurement of the physical attribute to the fingerprint; and in response to the runtime measurement exceeding a threshold, executing a countermeasure operation against software ran by the separate processor. 12. The computer-implemented method of claim 11 , wherein the threshold is updated in response to the comparing the runtime measurement of the physical attribute to the fingerprint. 13. A system comprising: memory; a processor in communication with the memory and programmed to: receive a runtime measurement from a sensor regarding the physical attribute of at least the separate processor during runtime; compare the runtime measurement of the physical attribute to a fingerprint, wherein the fingerprint includes a baseline measurement of a physical attribute of at least a separate processor, wherein the baseline measurement is determined during an enrollment period of the system in a secured environment using Original Equipment Manufacturer (OEM) components to establish normalized measurements; and in response to the runtime measurement exceeding a threshold, executing a countermeasure operation against software ran by the separate processor. 14. The system of claim 13 , wherein the processor is further programmed to, in response to the measurement exceeding a threshold, log the measurement and store the log in the memory. 15. The system of claim 13 , wherein the countermeasure operation includes killing the software ran by the separate processor. 16. The system of claim 13 , wherein the countermeasure operation includes rebooting the system. 17. The system of claim 13 , wherein the countermeasure operation includes reprogramming the software ran by the separate processor to original code. 18. The system of claim 13 , wherein the countermeasure operation includes reprogramming the software ran by the separate processor. 19. The system of claim 13 , wherein the physical attribute includes a temperature. 20. The system of claim 13 , wherein the physical attribute includes a vibration.

Assignees

Inventors

Classifications

  • Passive attacks, e.g. eavesdropping or listening without modification of the traffic monitored · CPC title

  • Version control (security arrangements therefor G06F21/57); Configuration management · CPC title

  • Updates (security arrangements therefor G06F21/57) · CPC title

  • Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title

  • Providing cryptographic facilities or services · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11683341B2 cover?
A system includes a memory and a processor in communication with the memory. The processor is programmed to receive a runtime measurement from a sensor regarding the physical attribute of at least the separate processor during runtime; compare the runtime measurement of the physical attribute to a fingerprint that includes a baseline measurement of a physical attribute of at least a separate pr…
Who is the assignee on this patent?
Bosch Gmbh Robert
What technology area does this patent fall under?
Primary CPC classification H04L63/1475. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jun 20 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 11 related publications on this page (citations in our corpus or others sharing the same primary CPC).