Below-OS Security Agent for I/O Path Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security solutions are limited in filtering all behaviors of an electronic device, as native operating system services prevent security software from installing arbitrary hooking within the kernel, allowing malware to operate at the same level as security software and compromise both the operating system and security software integrity, particularly in kernel mode.
Innovation Solution
A below-operating system security agent traps and intercepts input/output operations at a level below all operating systems, modifies and analyzes the content to detect malware, ensuring secure transmission and preventing malicious activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If security software installs arbitrary hooking within the operating system kernel, then filtering capability is improved, but system reliability deteriorates due to conflicts with native operating system services
Solution Approach 1:
The patent transitions from horizontal integration (security software operating within the OS kernel at the same level) to vertical integration (security agent operating below the OS at a lower level). This dimensional change allows the security agent to intercept I/O operations before they reach the OS and applications, providing comprehensive filtering capability without conflicting with native OS services or kernel-mode malware that operate at higher levels.
2Measurement precision
If security software operates at the same level as malware in the operating system kernel, then detection capability is improved, but security software integrity deteriorates due to malware compromise
Solution Approach 1:
The patent moves the security agent to a different operational dimension - below the operating system rather than within it. This positioning creates a hierarchical advantage where the security agent can monitor and control I/O operations at a fundamental level that malware in the kernel cannot compromise. The agent operates in a protected environment (firmware or hardware module) that is inaccessible to OS-level malware, thereby maintaining both detection capability and integrity.
3Object-generated harmful factors
If malware operates in kernel mode, then malware effectiveness is improved, but security control deteriorates due to ability to compromise both OS and security software
Solution Approach 1:
The patent establishes a vertical hierarchy where the security agent operates below the OS kernel, creating an unbreachable security layer. Kernel-mode malware can still operate effectively within the OS, but it cannot reach or compromise the security agent that resides in firmware or hardware at a lower level. This dimensional separation neutralizes the advantage of kernel-mode operation for malware while preserving security control.
Solution Approach 2:
The security agent performs preliminary interception of I/O operations before they reach the OS kernel or applications. By establishing security controls at an earlier stage in the I/O path (at the firmware or hardware level rather than at the OS level), the agent can detect and block malicious activities before kernel-mode malware can execute its harmful functions, thereby maintaining security control despite malware effectiveness.
Data Source
AI summary
A system for securing an electronic device may include a memory, a processor, one or more operating systems residing in the memory for execution by the processor, an input-output (I/O) device of the electronic device coupled to the operating system; and a security agent configured to execute on the electronic device at a level below all of the operating systems of the electronic device accessing the I/O device. The security agent may be further configured to: (i) trap, at a level below all of the operating systems of the electronic device accessing an input/output (I/O) device, an attempted access of a facility for I/O operation with the I/O device; and (ii) using one or more security rules, analyze the attempted access to determine whether the attempted access is indicative of malware.


