Out-of-band Agent for Anti-malware Platform Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional anti-malware solutions lack secure execution environments and trusted visibility into the operating system, making them susceptible to malware attacks, as they rely on the operating system for system calls and are vulnerable to subversion by malware operating within the OS.

Innovation Solution

An out-of-band (OOB) agent is introduced to protect the platform, providing a non-TRS method to measure and secure an in-band security agent, with a manageability engine offering OOB connectivity and access to system memory resources without relying on OS services, creating a protected execution environment and enabling trusted visibility and eventing capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional anti-malware solutions rely on operating system services for system calls, then ease of operation is improved, but reliability deteriorates because the system becomes vulnerable to subversion by malware operating within the OS

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the anti-malware system into two distinct parts: an in-band agent running within the OS for ease of operation, and an out-of-band agent running outside the OS for reliability. This segmentation allows each component to fulfill its specific function without compromising the other, resolving the contradiction between ease of operation and reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The out-of-band agent acts as an intermediary that provides trusted visibility and measurement capabilities to the in-band agent. This intermediary relationship allows the in-band agent to operate within the OS for ease of operation while the out-of-band agent ensures reliability through independent verification and protection mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If tamper-resistant software mechanisms are used to protect in-band security agents, then reliability is improved, but device complexity increases and the system remains susceptible to software attacks

Engineering Contradiction:
ImprovereliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the protection and verification functions from the in-band agent and places them in the out-of-band agent. This extraction reduces the complexity burden on the in-band agent while maintaining reliability, as the out-of-band agent independently provides tamper-resistant protection without adding complexity to the in-band component.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If out-of-band agent is introduced to provide trusted visibility and protection, then reliability is improved, but device complexity increases

Engineering Contradiction:
ImprovereliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The out-of-band agent is designed as a universal protection mechanism that performs multiple functions: providing trusted visibility, measuring system state, protecting the in-band agent, and enabling remote management. This multi-functionality consolidates multiple reliability-enhancing features into a single component, reducing overall system complexity while maintaining high reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8635705B2Computer system and method with anti-malware
Publication Date: 2014.01.21 INTEL CORP
  • US8635705B2 patent drawing
  • US8635705B2 patent drawing
  • US8635705B2 patent drawing

AI summary

In some embodiments, approaches may provide an out-of-band (OOB) agent to protect a platform. The OOB agent may be able to use non-TRS methods to measure and protect an in-band security agent. In some embodiments, a manageability engine can provide out of band connectivity to the in-band and out-of-band security agents and provide access to the system memory resources without having to rely on OS services. This can be used for a trusted anti-malware and remediation service.