Below-OS Security Agent for System Call Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security software is hindered by operating systems in preventing malware from filtering behaviors and compromising system integrity, as malware can operate at the same level as security software, tampering with system calls and evading detection.

Innovation Solution

A system and method that employs a below-operating-system security agent to trap and authorize access to system calls, operating at a level below all operating systems to intercept and evaluate attempted accesses, using security rules to determine authorization and prevent malicious actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security software operates at the operating system level to filter behaviors, then detection capability is improved, but malware can compromise both the operating system and security software integrity

Engineering Contradiction:
Improvedetection capabilityVSAvoidsecurity software integrity
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces a new operational dimension by placing the security agent below the operating system level (in firmware or hardware). This dimensional shift allows the security agent to monitor and filter system calls at a lower layer where malware cannot reach, thereby maintaining detection capability while protecting against compromise.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The security agent acts as an intermediary layer between the hardware and the operating system. It intercepts system calls before they reach the operating system and applications, filtering malicious behaviors without being exposed to malware that operates at the application or kernel level. This intermediary position resolves the contradiction by enabling detection while maintaining integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If malware operates at the same level as security software in the operating system kernel, then malware can evade detection, but security software cannot filter all malicious actions

Engineering Contradiction:
Improvemalware evasion capabilityVSAvoidsecurity filtering effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent resolves this contradiction by moving the security agent to a different operational dimension (below the operating system). This allows the security agent to observe and filter malware behaviors without being subject to the same level where malware operates, eliminating the ability of malware to evade detection through same-level manipulation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Object-generated harmful factors

If system calls are hooked to execute malicious code, then malware can modify behavior of all software, but a below-operating-system security agent can trap and authorize access

Engineering Contradiction:
Improvemalicious code executionVSAvoidsystem call integrity
Core Design Contradiction:
Object-generated harmful factorsVSReliability

Solution Approach 1:

The security agent performs preliminary action by establishing itself below the operating system before malware can hook system calls. It proactively monitors and authorizes system call access, preventing malicious code execution before it can occur. This preliminary positioning resolves the contradiction by enabling the security agent to block harmful factors while maintaining system call integrity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8863283B2System and method for securing access to system calls
Publication Date: 2014.10.14 MCAFEE LLC
  • US8863283B2 patent drawing
  • US8863283B2 patent drawing
  • US8863283B2 patent drawing

AI summary

In one embodiment, a system for securing access to system calls includes a memory, an operating system configured to execute on an electronic device, and a below-operating-system security agent. The below-operating-system security agent is configured to identify one or more resources associated with a system call for which attempted accesses will be trapped, trap an attempted access of the one or more resources that originates from the operational level of the operating system, access one or more security rules to determine whether the attempted access is authorized, and operate at a level below all of the operating systems of the electronic device accessing the one or more resources associated with a system call.