Trusted Boot Environment for Rootkit-Resistant Malware Scanning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer security tools are ineffective against malware that uses rootkits to hide from antivirus scans, allowing infections to persist undetected.
Innovation Solution
A trusted operating environment with a trusted antivirus tool is embodied on a removable device, such as a USB drive, which boots a computing device to scan for malware, updates its components, and authenticates updates from trusted sources to ensure accurate virus detection and removal.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a standard antivirus tool is used to scan for malware, then the scanning process can be performed, but the malware can hide using rootkits to intercept system calls and return false information, causing the antivirus tool to be unable to detect the infection
Solution Approach 1:
The patent introduces a trusted operating environment as an intermediary layer between the antivirus tool and the compromised operating system. This trusted environment provides authentic system call interfaces that cannot be intercepted by rootkits, allowing the antivirus scanner to receive accurate file information and successfully detect malware despite rootkit interference in the standard operating system
Solution Approach 2:
The patent creates an inert or protected environment through the trusted operating environment that is isolated from rootkit interference. Within this protected environment, system calls cannot be hijacked or manipulated by malware, providing a clean scanning context where antivirus operations can proceed without interference from rootkits
2Productivity
If the antivirus tool resides on the computer and attempts to scan, then scanning can be initiated, but the rootkit can intercept function calls and return incorrect file information, preventing successful virus detection
Solution Approach 1:
The trusted operating environment serves as an intermediary that provides accurate file access information to the antivirus tool. Instead of the antivirus tool directly accessing files through potentially compromised system calls, the trusted environment mediates these calls and returns authentic file information that cannot be manipulated by rootkits
3Reliability
If updates are downloaded from the computing device, then the antivirus tool can be updated, but the updates may come from compromised machines, compromising the integrity of the antivirus components
Solution Approach 1:
The patent applies preliminary anti-action by implementing authentication verification before accepting updates. The trusted operating environment预先 verifies the authenticity of update sources and validates update integrity, preventing compromised updates from being installed. This preliminary check blocks potential harm before it can affect the antivirus system
Solution Approach 2:
The patent implements feedback mechanisms where the trusted operating environment continuously verifies the integrity and authenticity of update sources. By providing feedback about the trustworthiness of update sources and validating update packages, the system ensures that only genuine updates from authorized sources are accepted, maintaining update integrity
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Techniques and apparatuses for scanning a computing device for malware are described. In one implementation, a trusted operating environment, which includes a trusted operating system and a trusted antivirus tool, is embodied on a removable data storage medium. A computing device is then booted from the removable data storage medium using the trusted operating system. The trusted antivirus tool searches the computing device for malware definition updates (e.g., virus signature updates) and uses the trusted operating system to scan the computing device for malware. In another implementation, a computing device is booting from a trusted operating system on a removable device and a trusted antivirus tool on the removable device scans the computing device for malware. The removable device can update its own internal components (e.g., virus signatures and antivirus tool) by searching the computing device or a remote resource for updates and authenticating any updates that are located.