Below-OS Security Agent for Kernel Malware Trapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security software is limited in its ability to filter all behaviors of an electronic device, as native operating system services prevent arbitrary hooking within the kernel, allowing malware to operate at the same level as security software and compromise both the operating system and security software integrity.

Innovation Solution

A system and method that includes a below-operating-system security agent configured to identify resources for changing filters, trap attempted accesses, and determine if they are indicative of malware by accessing security rules at a level below all operating systems, thereby operating at a higher priority than the operating system to prevent malicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security software operates within the operating system kernel level, then it can filter and monitor system behaviors, but malware can operate at the same level and compromise both the operating system and security software integrity

Engineering Contradiction:
Improvesecurity software integrityVSAvoidmalware compromise capability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a new operational dimension by placing the security agent below the operating system kernel level. This dimensional shift in the system hierarchy allows the security software to operate from a privileged position that malware cannot reach, fundamentally changing the security model from same-level monitoring to hierarchical protection.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system is segmented into distinct operational levels: the operating system kernel level and the below-operating-system level. This segmentation isolates the security agent in a protected layer, creating a clear separation between security functions and potential malware threats that operate within the traditional operating system environment.

Inventive Principle:
Principle #1Segmentation

2Reliability

If native operating system services prevent arbitrary hooking within the kernel, then system stability is maintained, but security software cannot install filtering hooks to monitor all behaviors

Engineering Contradiction:
Improvesystem stabilityVSAvoidfiltering capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security agent operates in a dimension below the operating system kernel, bypassing the kernel's restrictions on arbitrary hooking. This allows the security software to install filtering hooks and monitor all system behaviors without conflicting with the operating system's stability mechanisms, as the security agent accesses resources from a lower operational level.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If malware operates at the same level as security software in the operating system kernel, then malware can compromise system integrity, but security software cannot detect below-kernel malicious activities

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidkernel-level malware threat
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

Instead of having security software try to detect malware at the same kernel level, the patent inverts the approach by placing the security agent below the kernel. This inverted hierarchy allows the security agent to monitor and detect all kernel-level activities, including malware operations, from a position of superior access and control.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS9032525B2System and method for below-operating system trapping of driver filter attachment
Publication Date: 2015.05.12 MCAFEE LLC
  • US9032525B2 patent drawing
  • US9032525B2 patent drawing
  • US9032525B2 patent drawing

AI summary

A system for protecting an electronic system against malware includes an operating system configured to execute on the electronic device, a driver coupled to the operating system, and a below-operating-system security agent. The below-operating-system security agent is configured to identify one or more resources for changing filters of the driver, trap an attempted access of the one or more resources that originates from the operational level of the operating system, access one or more security rules to determine whether the attempted access is indicative of malware, and operate at a level below all of the operating systems of the electronic system accessing the one or more resources for changing filters of the driver.