Malware Scan via Server OS During Power Change
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Malware can hide in the kernel of an operating system, making it difficult to detect, as current solutions are inadequate for effectively scanning and removing such hidden threats.
Innovation Solution
A device uses a separate operating system from a server to execute a malware scan during power change conditions like sleep mode or restart, allowing for a trusted OS to be loaded into memory or executed remotely to scan the native OS and other software applications for malware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a native operating system performs malware scans, then the scan can be executed locally, but the malware can redirect the scan away from itself by hiding in the kernel
Solution Approach 1:
The patent introduces a separate trusted operating system from a server as an intermediary to perform malware scans. This external OS acts as a mediator that can scan the native OS without being compromised by malware embedded in the native OS kernel, thereby resolving the contradiction between local scan execution and malware redirection capability
Solution Approach 2:
Instead of using the native OS to scan itself (self-scanning), the patent inverts the approach by using a separate trusted OS to scan the native OS. This inversion eliminates the ability of malware to redirect scans since the scanning process occurs in a different, trusted environment
2Reliability
If a separate operating system from a server is used to perform malware scans, then malware hiding in the native OS kernel can be detected, but the system complexity increases
Solution Approach 1:
The patent makes the server a universal resource that can provide trusted operating systems to multiple client devices for malware scanning. This multi-functionality reduces the need for each device to maintain its own separate scanning infrastructure, thereby managing system complexity while maintaining high detection reliability
Solution Approach 2:
The server acts as an intermediary that hosts trusted operating systems, reducing the complexity burden on individual client devices. Instead of each device needing to maintain a separate trusted scanning environment, the server provides this capability externally, simplifying the overall system architecture
Data Source
AI summary
In one aspect, a device includes at least one processor and storage accessible to the at least one processor. The storage includes instructions executable by the at least one processor to identify a power change condition in the device, and responsive to the power change condition, execute a scan for malware on the device using an operating system (O.S.) loaded into memory of the device from a server separate from the device.


