Dual CPU Cross-Architecture Monitoring for Rootkit Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Rootkits and other malicious software are difficult to detect and remove from infected systems, especially in mobile devices, as they employ stealth-like mechanisms to conceal themselves, making traditional detection methods ineffective and often requiring costly repairs or reinstallation.
Innovation Solution
A system and method utilizing two distinct processing units of different architectures to monitor each other, allowing for detection of rootkits and viruses even when they attempt to hide their presence, by initializing and interrogating each other independently of the infected unit's operating environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If traditional detection methods are used within the infected operating environment, then the detection process is simple, but the detection effectiveness deteriorates because rootkits can subvert and hide their presence
Solution Approach 1:
The patent introduces a second processing unit as an intermediary that monitors the first processing unit. This mediator operates independently of the infected environment, using different architecture and operating system to detect rootkits without being compromised by them. The intermediary unit queries system information and compares it against expected values to identify malicious software presence.
Solution Approach 2:
The system is divided into two separate processing units with distinct architectures and operating environments. This segmentation isolates the detection function from the potentially infected execution environment, allowing reliable detection without relying on the trustworthiness of the infected system's software environment.
2Object-generated harmful factors
If rootkits operate at kernel mode with highest privileges, then they can intercept and subvert operating system operations, but this makes them difficult to detect and remove
Solution Approach 1:
The second processing unit acts as an intermediary that queries system information from the first processing unit without being affected by kernel-mode rootkits. Since the intermediary uses a different architecture and operating system, kernel-mode rootkits cannot subvert its monitoring capabilities, allowing detection even when the infected system operates at highest privilege levels.
Solution Approach 2:
The patent changes the architectural parameters of the monitoring system by using a second processing unit with a different architecture and operating system. This parameter change ensures that the monitoring function is not vulnerable to the same rootkit techniques that compromise the first processing unit, as rootkits are architecture-specific and cannot cross architectural boundaries.
3Reliability
If detection requires alternative trusted operating system, then detection reliability improves, but device complexity and repair cost increase
Solution Approach 1:
The second processing unit is designed with universal monitoring capabilities that can detect rootkits across different operating systems and architectures. This multi-functional approach allows a single intermediary unit to perform detection functions without requiring multiple specialized systems, reducing overall complexity while maintaining high reliability through architectural diversity.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Disclosed are systems and methods to utilize two different processing units (e.g., CPUs) to monitor each other. The processing units may have limited visibility and/or read only access to each other to reduce the possibility that one affected processing unit could compromise the second processing unit. Devices containing multiple processing units of different architectures could be configured so that one type of processing unit monitors another type of processing unit. When the processing units are different architectures a single piece of malicious software (malware) is unlikely to affect both processing units. Each processing unit can be configured to detect rootkits and other types of malware on the other processor(s) of the system/device.