Below-Kernel Security Agent for Malware Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing operating system security mechanisms are inadequate in preventing malware from operating at the same level as security software, allowing malware to compromise both the operating system and security software, and evade detection by tampering with user mode memory and disk sectors.

Innovation Solution

A system and method that launches a security architecture with a secured launching agent booting before the operating system, executing at a level below all operating systems to intercept resource access requests and determine if they indicate malware, using a below-operating system trapping agent and triggered event handler to enforce security rules and corrective actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security software installs hooking within the kernel of operating systems, then filtering functionality is provided, but malware operating at the same level can compromise both the operating system and the integrity of the security software itself

Engineering Contradiction:
Improvesecurity software integrityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the security architecture into multiple layers: a security manager operating below the operating system kernel and security agents operating within the kernel. This segmentation allows the security manager to protect the integrity of security agents by operating at a lower, more privileged level that cannot be compromised by kernel-level malware.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimensional layer below the operating system kernel where the security manager operates. This creates a hierarchical structure with multiple execution levels, allowing security functions to operate from a protected dimension that is inaccessible to traditional kernel-level malware attacks.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If malware operates at the same level as security software in the operating system kernel, then malware can evade detection by tampering with user mode memory and disk sectors, but security filtering functionality is limited

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidmalware impact on system
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The security manager performs preliminary actions by establishing security filters and monitoring mechanisms below the operating system kernel before malware can execute. This early establishment of security controls prevents malware from tampering with critical system components and ensures that all kernel-level operations are monitored from the outset.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security manager acts as an intermediary layer between the hardware and the operating system kernel, intercepting and monitoring all system calls and operations. This intermediary position allows the security manager to detect and block malware activities before they can affect the operating system or security agents.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Stability of the object's composition

If native operating system services prevent security software from installing arbitrary hooking within the kernel, then system stability is maintained, but security software is prevented from filtering all behaviors including potentially malicious actions

Engineering Contradiction:
Improveoperating system stabilityVSAvoidsecurity filtering capability
Core Design Contradiction:
Stability of the object's compositionVSReliability

Solution Approach 1:

The system segments security functions into two parts: a security manager operating below the kernel that maintains system stability, and security agents operating within the kernel that provide comprehensive filtering capabilities. This segmentation allows both operating system stability and enhanced security filtering to coexist.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security manager provides self-service by operating autonomously below the operating system kernel, managing its own execution environment and security policies without requiring modifications to the operating system's native services. This allows the security manager to maintain system stability while independently providing enhanced filtering capabilities.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9087199B2System and method for providing a secured operating system execution environment
Publication Date: 2015.07.21 JPMORGAN CHASE BANK N A AS ADMINISTATIVE AGENT
  • US9087199B2 patent drawing
  • US9087199B2 patent drawing
  • US9087199B2 patent drawing

AI summary

In one embodiment, a system for launching a security architecture includes an electronic device comprising a processor and one or more operating systems, a security agent, and a launching module. The launching module comprises a boot manager and a secured launching agent. The boot manager is configured to boot the secured launching agent before booting the operating systems, and the secured launching agent is configured to load a security agent. The security agent is configured to execute at a level below all operating systems of the electronic device, intercept a request to access a resource of the electronic device, the request originating from the operational level of one of one or more operating systems of the electronic device, and determine if a request is indicative of malware. In some embodiments, the secured launching agent may be configured to determine whether the security agent is infected with malware prior to loading the security agent.