Below-OS Security Agent for I/O Path Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security solutions are limited in filtering all behaviors of an electronic device, as native operating system services prevent security software from installing arbitrary hooking within the kernel, allowing malware to operate at the same level as security software and compromise both the operating system and security software integrity, particularly in kernel mode.

Innovation Solution

A below-operating system security agent traps and intercepts input/output operations at a level below all operating systems, modifies and analyzes the content to detect malware, ensuring secure transmission and preventing malicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security software installs arbitrary hooking within the operating system kernel, then filtering capability is improved, but system reliability deteriorates due to conflicts with native operating system services

Engineering Contradiction:
Improvefiltering capabilityVSAvoidsystem stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent transitions from horizontal integration (security software operating within the OS kernel at the same level) to vertical integration (security agent operating below the OS at a lower level). This dimensional change allows the security agent to intercept I/O operations before they reach the OS and applications, providing comprehensive filtering capability without conflicting with native OS services or kernel-mode malware that operate at higher levels.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If security software operates at the same level as malware in the operating system kernel, then detection capability is improved, but security software integrity deteriorates due to malware compromise

Engineering Contradiction:
Improvedetection capabilityVSAvoidsecurity software integrity
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent moves the security agent to a different operational dimension - below the operating system rather than within it. This positioning creates a hierarchical advantage where the security agent can monitor and control I/O operations at a fundamental level that malware in the kernel cannot compromise. The agent operates in a protected environment (firmware or hardware module) that is inaccessible to OS-level malware, thereby maintaining both detection capability and integrity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Object-generated harmful factors

If malware operates in kernel mode, then malware effectiveness is improved, but security control deteriorates due to ability to compromise both OS and security software

Engineering Contradiction:
Improvemalware effectivenessVSAvoidsecurity control
Core Design Contradiction:
Object-generated harmful factorsVSReliability

Solution Approach 1:

The patent establishes a vertical hierarchy where the security agent operates below the OS kernel, creating an unbreachable security layer. Kernel-mode malware can still operate effectively within the OS, but it cannot reach or compromise the security agent that resides in firmware or hardware at a lower level. This dimensional separation neutralizes the advantage of kernel-mode operation for malware while preserving security control.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The security agent performs preliminary interception of I/O operations before they reach the OS kernel or applications. By establishing security controls at an earlier stage in the I/O path (at the firmware or hardware level rather than at the OS level), the agent can detect and block malicious activities before kernel-mode malware can execute its harmful functions, thereby maintaining security control despite malware effectiveness.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8966624B2System and method for securing an input/output path of an application against malware with a below-operating system security agent
Publication Date: 2015.02.24 MCAFEE LLC
  • US8966624B2 patent drawing
  • US8966624B2 patent drawing
  • US8966624B2 patent drawing

AI summary

A system for securing an electronic device may include a memory, a processor, one or more operating systems residing in the memory for execution by the processor, an input-output (I/O) device of the electronic device coupled to the operating system; and a security agent configured to execute on the electronic device at a level below all of the operating systems of the electronic device accessing the I/O device. The security agent may be further configured to: (i) trap, at a level below all of the operating systems of the electronic device accessing an input/output (I/O) device, an attempted access of a facility for I/O operation with the I/O device; and (ii) using one or more security rules, analyze the attempted access to determine whether the attempted access is indicative of malware.