Cognizant Engine Hardware Probes for Kernel Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies for kernel-mode software protection in highly interconnected systems are susceptible to over-the-wire and insider attacks due to the lack of isolation and immunity of kernel protecting functions, leading to vulnerabilities in data security and performance inefficiencies in monitoring and self-healing processes.
Innovation Solution
The Cognizant Processing Engine family employs hardware-assisted programmable probes and monitors to provide real-time, low-latency observability and controllability at the instruction level, isolating the monitoring process and allowing immediate action to halt or interrupt the processor, thereby enhancing kernel protection and reducing performance impact.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If kernel-mode protecting functions are made accessible to provide functionality, then system functionality is improved, but susceptibility to attacks increases
Solution Approach 1:
The system is divided into distinct segments: the monitored kernel-mode code running in the guest OS and the monitoring code running in the host OS within a virtualized environment. This segmentation isolates the protecting functions from direct access by potential attackers while maintaining their functionality through controlled interfaces.
Solution Approach 2:
A virtualization layer acts as an intermediary between the kernel-mode code and the monitoring system. The hypervisor enables the host OS to monitor and control the guest OS kernel without direct access, providing a secure mediation layer that prevents attacks while preserving functionality.
2Measurement precision
If pure software virtual machine is used to achieve instruction level observability, then monitoring precision is improved, but computing power requirements increase significantly
Solution Approach 1:
The patent replaces the mechanical software-based monitoring approach with a hardware-assisted virtualization system. The hypervisor leverages hardware virtualization capabilities to provide instruction-level observability without the exponential computing overhead of pure software emulation, significantly reducing power requirements while maintaining precision.
3Difficulty of detecting and measuring
If software probes are added to monitor execution at instruction level, then detection capability is improved, but performance overhead increases
Solution Approach 1:
The monitoring probes are merged into the virtualization infrastructure itself rather than being separate software components. The hypervisor integrates detection capabilities directly into its execution management functions, allowing instruction-level monitoring without the performance overhead of separate probe mechanisms.
Solution Approach 2:
The virtualization system provides self-monitoring capabilities where the hypervisor automatically tracks and analyzes its own execution state and guest OS behavior. This self-service approach eliminates the need for external monitoring software that would add performance overhead.
4Ease of operation
If kernel and protecting functions are not isolated from external environment, then ease of operation is improved, but reliability decreases
Solution Approach 1:
The system employs a nested structure where the guest OS kernel and its protecting functions are nested within a virtualized environment controlled by the host OS. This nested architecture provides isolation and immunity to compromise while maintaining ease of operation through standardized virtualization interfaces.
Data Source
AI summary
The present invention is directed to system for and methods of real time observing, monitoring, and detecting anomalies in programs' behavior at instruction level. The hardware assist design in this invention provides fine grained observability, and controllability. Fine grained observability provides unprecedented opportunity for detecting anomaly. Controllability provides a powerful tool for stopping anomaly, repairing the kernel and restoring the state of processing. The performance improvement over pure software approach is estimated to be many orders of magnitudes. This invention is also effective and efficient in detecting mutating computer viruses, where normal, signature based, virus detection is under performing.


