Below-Kernel Security Agent for Malware Interception
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing operating system security mechanisms are inadequate in preventing malware from operating at the same level as security software, allowing malware to compromise both the operating system and security software, and evade detection by tampering with user mode memory and disk sectors.
Innovation Solution
A system and method that launches a security architecture with a secured launching agent booting before the operating system, executing at a level below all operating systems to intercept resource access requests and determine if they indicate malware, using a below-operating system trapping agent and triggered event handler to enforce security rules and corrective actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security software installs hooking within the kernel of operating systems, then filtering functionality is provided, but malware operating at the same level can compromise both the operating system and the integrity of the security software itself
Solution Approach 1:
The system divides the security architecture into multiple layers: a security manager operating below the operating system kernel and security agents operating within the kernel. This segmentation allows the security manager to protect the integrity of security agents by operating at a lower, more privileged level that cannot be compromised by kernel-level malware.
Solution Approach 2:
The patent introduces a new dimensional layer below the operating system kernel where the security manager operates. This creates a hierarchical structure with multiple execution levels, allowing security functions to operate from a protected dimension that is inaccessible to traditional kernel-level malware attacks.
2Reliability
If malware operates at the same level as security software in the operating system kernel, then malware can evade detection by tampering with user mode memory and disk sectors, but security filtering functionality is limited
Solution Approach 1:
The security manager performs preliminary actions by establishing security filters and monitoring mechanisms below the operating system kernel before malware can execute. This early establishment of security controls prevents malware from tampering with critical system components and ensures that all kernel-level operations are monitored from the outset.
Solution Approach 2:
The security manager acts as an intermediary layer between the hardware and the operating system kernel, intercepting and monitoring all system calls and operations. This intermediary position allows the security manager to detect and block malware activities before they can affect the operating system or security agents.
3Stability of the object's composition
If native operating system services prevent security software from installing arbitrary hooking within the kernel, then system stability is maintained, but security software is prevented from filtering all behaviors including potentially malicious actions
Solution Approach 1:
The system segments security functions into two parts: a security manager operating below the kernel that maintains system stability, and security agents operating within the kernel that provide comprehensive filtering capabilities. This segmentation allows both operating system stability and enhanced security filtering to coexist.
Solution Approach 2:
The security manager provides self-service by operating autonomously below the operating system kernel, managing its own execution environment and security policies without requiring modifications to the operating system's native services. This allows the security manager to maintain system stability while independently providing enhanced filtering capabilities.
Data Source
AI summary
In one embodiment, a system for launching a security architecture includes an electronic device comprising a processor and one or more operating systems, a security agent, and a launching module. The launching module comprises a boot manager and a secured launching agent. The boot manager is configured to boot the secured launching agent before booting the operating systems, and the secured launching agent is configured to load a security agent. The security agent is configured to execute at a level below all operating systems of the electronic device, intercept a request to access a resource of the electronic device, the request originating from the operational level of one of one or more operating systems of the electronic device, and determine if a request is indicative of malware. In some embodiments, the secured launching agent may be configured to determine whether the security agent is infected with malware prior to loading the security agent.


