Hardware Anomaly Detection via Hypervisor Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional anti-malware solutions are ineffective against hardware-related malware that targets firmware, as it operates outside the operating system and evades detection, posing a risk of data exposure and system disruption.

Innovation Solution

A system and method for detecting potentially malicious hardware-related anomalies by profiling the computing environment, identifying anomalies through comparison with expected profiles, and correlating them with suspicious activity to determine malicious intent, using a hypervisor to monitor and remediate such threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anti-malware software is used to detect malware, then software-based malware can be detected, but hardware-related malware (firmware) cannot be detected because it operates outside the operating system

Engineering Contradiction:
Improvemalware detection capabilityVSAvoiddetection coverage against hardware-related attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from software-level detection to hardware-level detection by profiling firmware and hardware components. This dimensional shift allows detection of malware that operates outside the traditional operating system environment, addressing the limitation of conventional anti-malware solutions.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces a hypervisor as an intermediary layer between the hardware/firmware and the operating system. The hypervisor profiles hardware components and firmware, enabling detection of hardware-related malware while maintaining system operation. This intermediary approach allows security monitoring without requiring changes to the firmware itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If firmware is modified to install malware, then hardware-based attacks can be launched, but traditional security measures cannot detect or prevent these attacks

Engineering Contradiction:
Improvesecurity threat levelVSAvoiddetectability of firmware anomalies
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent performs preliminary profiling of hardware components and firmware before malware infection occurs. By establishing baseline profiles of expected hardware behavior and firmware characteristics, the system can detect deviations that indicate malware presence. This proactive approach enables detection before malware can cause significant harm.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous monitoring and comparison of hardware profiles against expected profiles, creating a feedback loop that detects anomalies in real-time. When deviations are detected, the system can alert users or take remediation actions, providing ongoing security monitoring rather than one-time detection.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10650142B1Systems and methods for detecting potentially malicious hardware-related anomalies
Publication Date: 2020.05.12 CA TECH INC
  • US10650142B1 patent drawing
  • US10650142B1 patent drawing
  • US10650142B1 patent drawing

AI summary

A computer-implemented method for detecting potentially malicious hardware-related anomalies may include (1) profiling a computing environment of at least one hardware component on a computing device, (2) detecting, by comparing the hardware component's profile with an expected profile for the hardware component, at least one anomaly in the hardware component's computing environment, (3) identifying additional suspicious activity on the computing device, and (4) determining, by correlating the additional suspicious activity on the computing device with the anomaly in the hardware component's computing environment, that the anomaly in the hardware component's computing environment is potentially malicious. Various other methods, systems, and computer-readable media are also disclosed.