Hardware Secured Flag Mechanism for Malware Subversion Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information handling systems face challenges in effectively protecting against malware, as existing solutions like System Health Agents and anti-malware scanners are limited in their ability to prevent user exposure and device subversion, often failing to provide immediate and robust protection against malicious software.

Innovation Solution

A hardware secured flag mechanism is activated by trusted Anti-Malware software, which reduces user exposure by performing actions such as displaying warnings, shutting down I/O devices, blocking network communications, and rebooting into a read-only recovery OS, and can only be reset by user intervention or a signed unlock key, ensuring continued protection even if the Anti-Malware software is subverted.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If System Health Agents are used to assess system security and refuse connections, then system security is improved, but the protection is limited to software effects and can be subverted by malware

Engineering Contradiction:
Improvesystem securityVSAvoidmalware subversion capability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a hardware-based intermediary (secured flag mechanism in BIOS/firmware) that mediates between the software anti-malware solution and the system's security responses. This hardware layer acts as an unforgeable mediator that validates security states and prevents malware from subverting security decisions, directly resolving the contradiction between software-based security and malware subversion capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the purely software-based System Health Agent security mechanism with a hardware-based secured flag mechanism stored in BIOS or firmware. This substitution of software with hardware (mechanics substitution) creates a trusted execution environment that malware cannot subvert, while maintaining the security assessment and response functionality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Object-affected harmful factors

If hardware secured flag mechanism is activated to perform multiple protection actions, then user exposure to malware is reduced, but system complexity increases

Engineering Contradiction:
Improveuser exposure to malwareVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the malware protection functionality into distinct modular actions (displaying warnings, shutting down I/O devices, blocking network communications, rebooting to recovery OS). Each protection action is an independent module that can be individually activated by the hardware secured flag mechanism, reducing overall system complexity through functional segmentation while maintaining comprehensive protection capabilities.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8931074B2Adaptive system behavior change on malware trigger
Publication Date: 2015.01.06 DELL PROD LP
  • US8931074B2 patent drawing
  • US8931074B2 patent drawing
  • US8931074B2 patent drawing

AI summary

A hardware secured flag mechanism which is activated by trusted Anti-Malware (AM) software. Upon being activated, the information handling system takes action to reduce user exposure even if the AM software is subsequently subverted. In certain embodiments, the flag mechanism is only reset by user intervention at a BIOS or other off-line mechanism. In certain embodiments, the flag mechanism may only be reset via a signed unlock key stored on an external memory device such as a universal serial bus (USB) key.