Below-OS Security Agent for System Call Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security software is hindered by operating systems in preventing malware from filtering behaviors and compromising system integrity, as malware can operate at the same level as security software, tampering with system calls and evading detection.
Innovation Solution
A system and method that employs a below-operating-system security agent to trap and authorize access to system calls, operating at a level below all operating systems to intercept and evaluate attempted accesses, using security rules to determine authorization and prevent malicious actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If security software operates at the operating system level to filter behaviors, then detection capability is improved, but malware can compromise both the operating system and security software integrity
Solution Approach 1:
The patent introduces a new operational dimension by placing the security agent below the operating system level (in firmware or hardware). This dimensional shift allows the security agent to monitor and filter system calls at a lower layer where malware cannot reach, thereby maintaining detection capability while protecting against compromise.
Solution Approach 2:
The security agent acts as an intermediary layer between the hardware and the operating system. It intercepts system calls before they reach the operating system and applications, filtering malicious behaviors without being exposed to malware that operates at the application or kernel level. This intermediary position resolves the contradiction by enabling detection while maintaining integrity.
2Adaptability or versatility
If malware operates at the same level as security software in the operating system kernel, then malware can evade detection, but security software cannot filter all malicious actions
Solution Approach 1:
The patent resolves this contradiction by moving the security agent to a different operational dimension (below the operating system). This allows the security agent to observe and filter malware behaviors without being subject to the same level where malware operates, eliminating the ability of malware to evade detection through same-level manipulation.
3Object-generated harmful factors
If system calls are hooked to execute malicious code, then malware can modify behavior of all software, but a below-operating-system security agent can trap and authorize access
Solution Approach 1:
The security agent performs preliminary action by establishing itself below the operating system before malware can hook system calls. It proactively monitors and authorizes system call access, preventing malicious code execution before it can occur. This preliminary positioning resolves the contradiction by enabling the security agent to block harmful factors while maintaining system call integrity.
Data Source
AI summary
In one embodiment, a system for securing access to system calls includes a memory, an operating system configured to execute on an electronic device, and a below-operating-system security agent. The below-operating-system security agent is configured to identify one or more resources associated with a system call for which attempted accesses will be trapped, trap an attempted access of the one or more resources that originates from the operational level of the operating system, access one or more security rules to determine whether the attempted access is authorized, and operate at a level below all of the operating systems of the electronic device accessing the one or more resources associated with a system call.


