Endpoint Visibility via Trusted Local OS Image
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In compromised electronic devices, malware can hinder visibility and remediation efforts by hiding information and preventing effective recovery, making it difficult to reliably restore systems without manual intervention and shared network bandwidth.
Innovation Solution
A system and method for endpoint visibility and remediation that uses a locally stored, trusted, hidden, protected image with an endpoint detection and response tool, allowing for reliable inspection and remediation despite OS kernel problems, using an out-of-band channel to bypass malware interference and provide independent inspection and repair.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized servers are used to restore electronic content, then restoration capability is provided, but network bandwidth is shared and reliability is reduced when servers are compromised
Solution Approach 1:
The patent extracts the restoration capability from centralized servers and places trusted operating system images directly on local secure storage devices at each endpoint. This allows endpoints to restore themselves independently without relying on centralized servers, thereby improving reliability while reducing server dependency.
Solution Approach 2:
The patent introduces a secure storage device as an intermediary between the endpoint and centralized servers. This intermediary holds trusted images locally and can provide restoration capability independently when servers are compromised or unavailable, resolving the contradiction between reliability and server dependency.
2Reliability
If malware runs with high privileges, then system control is gained, but visibility and remediation actions become unreliable
Solution Approach 1:
The patent segments the system into two independent parts: the potentially compromised operating system and a separate secure storage device containing trusted images. By isolating the trusted restoration images in a protected environment, the system maintains reliable visibility and remediation capabilities even when malware compromises the main OS.
Solution Approach 2:
The secure storage device acts as an intermediary that provides a trusted basis for visibility and remediation actions. It stores authenticated, untampered operating system images and can boot independently to perform reliable system inspection and restoration, bypassing malware interference in the main OS.
3Productivity
If manual restoration is performed, then customization is possible, but time consumption and labor increase
Solution Approach 1:
The patent implements preliminary action by pre-storing authenticated, trusted operating system images in secure storage devices at each endpoint before compromise occurs. When malware is detected, the system can immediately restore from these pre-prepared images without requiring manual intervention or time-consuming centralized restoration processes.
4Reliability
If offline restoration is performed, then network independence is achieved, but bandwidth sharing issues remain
Solution Approach 1:
The patent extracts restoration images from centralized network storage and places them locally in secure storage devices at each endpoint. This allows completely offline restoration that is independent of network availability and eliminates bandwidth sharing issues, while maintaining high reliability through local trusted image storage.
Data Source
AI summary
A system for securing electronic devices includes a processor, a storage medium communicatively coupled to the processor, and a monitoring application comprising computer-executable instructions on the medium. The instructions are readable by the processor. The monitoring application is configured to receive an indication that a client has been affected by malware, cause the client to boot from a trusted operating system image, cause a launch of a secured security application on the client from a trusted application image, and analyze a malware status of the client through the secured security application.


