Kernel-Resident Network Security System for Rootkit Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional malware detection and remediation techniques rely on signature-based approaches, which are ineffective against sophisticated threats like rootkits that install in the operating system kernel, bypassing current antivirus and intrusion detection systems, and fail to detect new Trojan viruses without prior signature identification.

Innovation Solution

A software-based detection and remediation system is installed in the kernel of the operating system, monitoring data packet traffic between the adaptive driver layer and protocol layer, analyzing packet contents, and executing remediation actions transparently to the user, with collaborative nodes across a network to detect and mitigate attacks without relying on traditional signature-based methods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If signature-based detection methods are used, then detection accuracy for known malware is improved, but detection capability against new and sophisticated threats deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection capability against new threats
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by installing detection software in the kernel before attacks occur, establishing observation points at the driver layer and protocol layer to monitor packet traffic proactively rather than reactively waiting for signature matches

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An intermediary detection system is introduced between the kernel and user space applications, using a driver layer and protocol layer as mediators to observe and analyze packet traffic without interfering with normal system operations, enabling detection of both known and unknown threats

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If rootkit malware is installed in the kernel, then ability to bypass traditional security sensors is improved, but detectability by advanced monitoring systems deteriorates

Engineering Contradiction:
Improvebypass capabilityVSAvoiddetectability
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The detection system operates in a different dimension by establishing observation points at multiple layers (driver layer and protocol layer) rather than relying on single-point kernel detection, creating a multi-dimensional monitoring architecture that can detect rootkits regardless of their kernel installation

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system implements continuous feedback loops where detected packets are analyzed, patterns are learned, and detection rules are updated in real-time, allowing the system to adapt to and detect rootkit behavior even when rootkits attempt to evade detection

Inventive Principle:
Principle #23Feedback

3Reliability

If transparent installation in kernel is used, then user awareness and detection of installation deteriorates, but system protection capability improves

Engineering Contradiction:
Improvesystem protection capabilityVSAvoiduser awareness
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent uses an intermediary architecture where the detection system operates through driver and protocol layers rather than directly in user space, allowing transparent monitoring of packet traffic without requiring user awareness or intervention while maintaining system protection

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8191141B2Method and system for cloaked observation and remediation of software attacks
Publication Date: 2012.05.29 RED HAT INC
  • US8191141B2 patent drawing
  • US8191141B2 patent drawing
  • US8191141B2 patent drawing

AI summary

A method and system provide security for a communication network and for one or more nodes within the network. Software can be distributed throughout the network from a centralized location or administrative console. The software can be made resident in the kernel of the operating system of a receiving node. The software can provide an observation functionality, an analysis functionality, a reporting functionality and a remediation functionality or some subset of those functionalities.