Endpoint Visibility via Trusted Local OS Image

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In compromised electronic devices, malware can hinder visibility and remediation efforts by hiding information and preventing effective recovery, making it difficult to reliably restore systems without manual intervention and shared network bandwidth.

Innovation Solution

A system and method for endpoint visibility and remediation that uses a locally stored, trusted, hidden, protected image with an endpoint detection and response tool, allowing for reliable inspection and remediation despite OS kernel problems, using an out-of-band channel to bypass malware interference and provide independent inspection and repair.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized servers are used to restore electronic content, then restoration capability is provided, but network bandwidth is shared and reliability is reduced when servers are compromised

Engineering Contradiction:
Improverestoration reliabilityVSAvoidcentralized server dependency
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the restoration capability from centralized servers and places trusted operating system images directly on local secure storage devices at each endpoint. This allows endpoints to restore themselves independently without relying on centralized servers, thereby improving reliability while reducing server dependency.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a secure storage device as an intermediary between the endpoint and centralized servers. This intermediary holds trusted images locally and can provide restoration capability independently when servers are compromised or unavailable, resolving the contradiction between reliability and server dependency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If malware runs with high privileges, then system control is gained, but visibility and remediation actions become unreliable

Engineering Contradiction:
Improvevisibility reliabilityVSAvoidmalware interference
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the system into two independent parts: the potentially compromised operating system and a separate secure storage device containing trusted images. By isolating the trusted restoration images in a protected environment, the system maintains reliable visibility and remediation capabilities even when malware compromises the main OS.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure storage device acts as an intermediary that provides a trusted basis for visibility and remediation actions. It stores authenticated, untampered operating system images and can boot independently to perform reliable system inspection and restoration, bypassing malware interference in the main OS.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If manual restoration is performed, then customization is possible, but time consumption and labor increase

Engineering Contradiction:
Improverestoration speedVSAvoidmanual intervention requirement
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by pre-storing authenticated, trusted operating system images in secure storage devices at each endpoint before compromise occurs. When malware is detected, the system can immediately restore from these pre-prepared images without requiring manual intervention or time-consuming centralized restoration processes.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If offline restoration is performed, then network independence is achieved, but bandwidth sharing issues remain

Engineering Contradiction:
Improverestoration independenceVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts restoration images from centralized network storage and places them locally in secure storage devices at each endpoint. This allows completely offline restoration that is independent of network availability and eliminates bandwidth sharing issues, while maintaining high reliability through local trusted image storage.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11971994B2End-point visibility
Publication Date: 2024.04.30 MAGENTA SECURITY HOLDINGS LLC
  • US11971994B2 patent drawing
  • US11971994B2 patent drawing
  • US11971994B2 patent drawing

AI summary

A system for securing electronic devices includes a processor, a storage medium communicatively coupled to the processor, and a monitoring application comprising computer-executable instructions on the medium. The instructions are readable by the processor. The monitoring application is configured to receive an indication that a client has been affected by malware, cause the client to boot from a trusted operating system image, cause a launch of a secured security application on the client from a trusted application image, and analyze a malware status of the client through the secured security application.