Cognizant Engine Hardware Probes for Kernel Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies for kernel-mode software protection in highly interconnected systems are susceptible to over-the-wire and insider attacks due to the lack of isolation and immunity of kernel protecting functions, leading to vulnerabilities in data security and performance inefficiencies in monitoring and self-healing processes.

Innovation Solution

The Cognizant Processing Engine family employs hardware-assisted programmable probes and monitors to provide real-time, low-latency observability and controllability at the instruction level, isolating the monitoring process and allowing immediate action to halt or interrupt the processor, thereby enhancing kernel protection and reducing performance impact.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If kernel-mode protecting functions are made accessible to provide functionality, then system functionality is improved, but susceptibility to attacks increases

Engineering Contradiction:
Improvesystem functionalityVSAvoidsusceptibility to attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system is divided into distinct segments: the monitored kernel-mode code running in the guest OS and the monitoring code running in the host OS within a virtualized environment. This segmentation isolates the protecting functions from direct access by potential attackers while maintaining their functionality through controlled interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A virtualization layer acts as an intermediary between the kernel-mode code and the monitoring system. The hypervisor enables the host OS to monitor and control the guest OS kernel without direct access, providing a secure mediation layer that prevents attacks while preserving functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If pure software virtual machine is used to achieve instruction level observability, then monitoring precision is improved, but computing power requirements increase significantly

Engineering Contradiction:
Improvemonitoring precisionVSAvoidcomputing power
Core Design Contradiction:
Measurement precisionVSPower

Solution Approach 1:

The patent replaces the mechanical software-based monitoring approach with a hardware-assisted virtualization system. The hypervisor leverages hardware virtualization capabilities to provide instruction-level observability without the exponential computing overhead of pure software emulation, significantly reducing power requirements while maintaining precision.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Difficulty of detecting and measuring

If software probes are added to monitor execution at instruction level, then detection capability is improved, but performance overhead increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidperformance
Core Design Contradiction:
Difficulty of detecting and measuringVSProductivity

Solution Approach 1:

The monitoring probes are merged into the virtualization infrastructure itself rather than being separate software components. The hypervisor integrates detection capabilities directly into its execution management functions, allowing instruction-level monitoring without the performance overhead of separate probe mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The virtualization system provides self-monitoring capabilities where the hypervisor automatically tracks and analyzes its own execution state and guest OS behavior. This self-service approach eliminates the need for external monitoring software that would add performance overhead.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If kernel and protecting functions are not isolated from external environment, then ease of operation is improved, but reliability decreases

Engineering Contradiction:
Improveease of operationVSAvoidimmunity to compromise
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system employs a nested structure where the guest OS kernel and its protecting functions are nested within a virtualized environment controlled by the host OS. This nested architecture provides isolation and immunity to compromise while maintaining ease of operation through standardized virtualization interfaces.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS10810306B2Cognizant engines: systems and methods for enabling program observability and controlability at instruction level granularity
Publication Date: 2020.10.20 MERTOGUNO SUKARNO
  • US10810306B2 patent drawing
  • US10810306B2 patent drawing
  • US10810306B2 patent drawing

AI summary

The present invention is directed to system for and methods of real time observing, monitoring, and detecting anomalies in programs' behavior at instruction level. The hardware assist design in this invention provides fine grained observability, and controllability. Fine grained observability provides unprecedented opportunity for detecting anomaly. Controllability provides a powerful tool for stopping anomaly, repairing the kernel and restoring the state of processing. The performance improvement over pure software approach is estimated to be many orders of magnitudes. This invention is also effective and efficient in detecting mutating computer viruses, where normal, signature based, virus detection is under performing.