BIOS Attribute Scanning for Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information handling systems lack effective mechanisms for detecting indicators of attack, which are critical for ensuring the security and integrity of processed and stored data.

Innovation Solution

An information handling system that includes a processor capable of scanning BIOS attributes, converting changes into threat events, and matching these events against threat chain policies to provide threat state changes, thereby enabling the detection and reporting of potential attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the system scans and monitors BIOS attributes for security threats, then the detection capability of attacks is improved, but the system complexity and processing overhead increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the security monitoring function into distinct modules: BIOS attribute scanning, event generation, threat chain matching, and policy evaluation. Each module handles a specific aspect of the detection process, making the overall complex system manageable and maintainable while preserving comprehensive detection capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components such as the secure event log and threat chain policies that act as mediators between the BIOS attribute scanning and the final threat detection. These intermediaries buffer and structure the data flow, reducing the direct complexity between scanning and detection components

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If the system converts changed attributes into multiple threat events and matches against multiple threat chains, then the accuracy of threat detection is improved, but the processing time and computational resources increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-defining threat chains and their associated policies before actual threat detection occurs. The secure event log pre-records BIOS attribute changes, and threat chains are pre-configured with matching criteria, allowing for faster real-time detection without sacrificing accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes parameters by converting single attribute changes into multiple threat events with different severity levels and types. This parameter transformation allows comprehensive detection accuracy while enabling prioritized processing of critical threats, effectively managing computational resources

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the system stores changed BIOS attributes in a secure event log, then the integrity and auditability of security data is improved, but the memory usage and storage requirements increase

Engineering Contradiction:
Improvedata integrityVSAvoidmemory usage
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential security-relevant information from BIOS attribute changes and stores it in the secure event log, rather than storing complete attribute states. This selective extraction maintains data integrity for security auditing while minimizing memory consumption by storing only changed attributes with their timestamps and severity levels

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12135787B2Detection of indicators of attack
Publication Date: 2024.11.05 DELL PROD LP
  • US12135787B2 patent drawing
  • US12135787B2 patent drawing
  • US12135787B2 patent drawing

AI summary

An information handling system includes a basic input/output system (BIOS), a memory, and a processor. The processor scans a current state of each BIOS attribute in the BIOS, and stores one or more changed attributes in a secure event log in the memory. The processor converts each changed attribute into a different threat event including a first changed attribute into a first threat event. The processor provides a list of threat events to multiple threat chains, each of which determine whether the threat events match threat criteria in a threat chain policy. In response to the threat event matching a threat criterion in the threat chain policy, the threat chain provides a threat state change to the processor, which in turn provides new threat state changes to a threat state change consumer.