Below-OS Security Agent for Kernel Malware Trapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security software is limited in its ability to filter all behaviors of an electronic device, as native operating system services prevent arbitrary hooking within the kernel, allowing malware to operate at the same level as security software and compromise both the operating system and security software integrity.
Innovation Solution
A system and method that includes a below-operating-system security agent configured to identify resources for changing filters, trap attempted accesses, and determine if they are indicative of malware by accessing security rules at a level below all operating systems, thereby operating at a higher priority than the operating system to prevent malicious activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security software operates within the operating system kernel level, then it can filter and monitor system behaviors, but malware can operate at the same level and compromise both the operating system and security software integrity
Solution Approach 1:
The patent introduces a new operational dimension by placing the security agent below the operating system kernel level. This dimensional shift in the system hierarchy allows the security software to operate from a privileged position that malware cannot reach, fundamentally changing the security model from same-level monitoring to hierarchical protection.
Solution Approach 2:
The system is segmented into distinct operational levels: the operating system kernel level and the below-operating-system level. This segmentation isolates the security agent in a protected layer, creating a clear separation between security functions and potential malware threats that operate within the traditional operating system environment.
2Reliability
If native operating system services prevent arbitrary hooking within the kernel, then system stability is maintained, but security software cannot install filtering hooks to monitor all behaviors
Solution Approach 1:
The security agent operates in a dimension below the operating system kernel, bypassing the kernel's restrictions on arbitrary hooking. This allows the security software to install filtering hooks and monitor all system behaviors without conflicting with the operating system's stability mechanisms, as the security agent accesses resources from a lower operational level.
3Measurement precision
If malware operates at the same level as security software in the operating system kernel, then malware can compromise system integrity, but security software cannot detect below-kernel malicious activities
Solution Approach 1:
Instead of having security software try to detect malware at the same kernel level, the patent inverts the approach by placing the security agent below the kernel. This inverted hierarchy allows the security agent to monitor and detect all kernel-level activities, including malware operations, from a position of superior access and control.
Data Source
AI summary
A system for protecting an electronic system against malware includes an operating system configured to execute on the electronic device, a driver coupled to the operating system, and a below-operating-system security agent. The below-operating-system security agent is configured to identify one or more resources for changing filters of the driver, trap an attempted access of the one or more resources that originates from the operational level of the operating system, access one or more security rules to determine whether the attempted access is indicative of malware, and operate at a level below all of the operating systems of the electronic system accessing the one or more resources for changing filters of the driver.


