Dual CPU Cross-Architecture Monitoring for Rootkit Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Rootkits and other malicious software are difficult to detect and remove from infected systems, especially in mobile devices, as they employ stealth-like mechanisms to conceal themselves, making traditional detection methods ineffective and often requiring costly repairs or reinstallation.

Innovation Solution

A system and method utilizing two distinct processing units of different architectures to monitor each other, allowing for detection of rootkits and viruses even when they attempt to hide their presence, by initializing and interrogating each other independently of the infected unit's operating environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If traditional detection methods are used within the infected operating environment, then the detection process is simple, but the detection effectiveness deteriorates because rootkits can subvert and hide their presence

Engineering Contradiction:
Improverootkit detection effectivenessVSAvoidtrustworthiness of detection environment
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent introduces a second processing unit as an intermediary that monitors the first processing unit. This mediator operates independently of the infected environment, using different architecture and operating system to detect rootkits without being compromised by them. The intermediary unit queries system information and compares it against expected values to identify malicious software presence.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is divided into two separate processing units with distinct architectures and operating environments. This segmentation isolates the detection function from the potentially infected execution environment, allowing reliable detection without relying on the trustworthiness of the infected system's software environment.

Inventive Principle:
Principle #1Segmentation

2Object-generated harmful factors

If rootkits operate at kernel mode with highest privileges, then they can intercept and subvert operating system operations, but this makes them difficult to detect and remove

Engineering Contradiction:
Improverootkit stealth capabilityVSAvoidrootkit detectability
Core Design Contradiction:
Object-generated harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The second processing unit acts as an intermediary that queries system information from the first processing unit without being affected by kernel-mode rootkits. Since the intermediary uses a different architecture and operating system, kernel-mode rootkits cannot subvert its monitoring capabilities, allowing detection even when the infected system operates at highest privilege levels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the architectural parameters of the monitoring system by using a second processing unit with a different architecture and operating system. This parameter change ensures that the monitoring function is not vulnerable to the same rootkit techniques that compromise the first processing unit, as rootkits are architecture-specific and cannot cross architectural boundaries.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If detection requires alternative trusted operating system, then detection reliability improves, but device complexity and repair cost increase

Engineering Contradiction:
Improvedetection trustworthinessVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The second processing unit is designed with universal monitoring capabilities that can detect rootkits across different operating systems and architectures. This multi-functional approach allows a single intermediary unit to perform detection functions without requiring multiple specialized systems, reducing overall complexity while maintaining high reliability through architectural diversity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2867819B1Preventing attacks on devices with multiple cpus
Publication Date: 2019.05.08 MCAFEE LLC
  • EP2867819B1 patent drawingFigure 1
  • EP2867819B1 patent drawingFigure 2
  • EP2867819B1 patent drawingFigure 3

AI summary

Disclosed are systems and methods to utilize two different processing units (e.g., CPUs) to monitor each other. The processing units may have limited visibility and/or read only access to each other to reduce the possibility that one affected processing unit could compromise the second processing unit. Devices containing multiple processing units of different architectures could be configured so that one type of processing unit monitors another type of processing unit. When the processing units are different architectures a single piece of malicious software (malware) is unlikely to affect both processing units. Each processing unit can be configured to detect rootkits and other types of malware on the other processor(s) of the system/device.