Trusted Boot Environment for Rootkit-Resistant Malware Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer security tools are ineffective against malware that uses rootkits to hide from antivirus scans, allowing infections to persist undetected.

Innovation Solution

A trusted operating environment with a trusted antivirus tool is embodied on a removable device, such as a USB drive, which boots a computing device to scan for malware, updates its components, and authenticates updates from trusted sources to ensure accurate virus detection and removal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a standard antivirus tool is used to scan for malware, then the scanning process can be performed, but the malware can hide using rootkits to intercept system calls and return false information, causing the antivirus tool to be unable to detect the infection

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidrootkit interference
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted operating environment as an intermediary layer between the antivirus tool and the compromised operating system. This trusted environment provides authentic system call interfaces that cannot be intercepted by rootkits, allowing the antivirus scanner to receive accurate file information and successfully detect malware despite rootkit interference in the standard operating system

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates an inert or protected environment through the trusted operating environment that is isolated from rootkit interference. Within this protected environment, system calls cannot be hijacked or manipulated by malware, providing a clean scanning context where antivirus operations can proceed without interference from rootkits

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

2Productivity

If the antivirus tool resides on the computer and attempts to scan, then scanning can be initiated, but the rootkit can intercept function calls and return incorrect file information, preventing successful virus detection

Engineering Contradiction:
Improvescanning capabilityVSAvoidfile access accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The trusted operating environment serves as an intermediary that provides accurate file access information to the antivirus tool. Instead of the antivirus tool directly accessing files through potentially compromised system calls, the trusted environment mediates these calls and returns authentic file information that cannot be manipulated by rootkits

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If updates are downloaded from the computing device, then the antivirus tool can be updated, but the updates may come from compromised machines, compromising the integrity of the antivirus components

Engineering Contradiction:
Improveantivirus update integrityVSAvoidcompromised update sources
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing authentication verification before accepting updates. The trusted operating environment预先 verifies the authenticity of update sources and validates update integrity, preventing compromised updates from being installed. This preliminary check blocks potential harm before it can affect the antivirus system

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent implements feedback mechanisms where the trusted operating environment continuously verifies the integrity and authenticity of update sources. By providing feedback about the trustworthiness of update sources and validating update packages, the system ensures that only genuine updates from authorized sources are accepted, maintaining update integrity

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2156357B1Trusted operating environment for malware detection
Publication Date: 2018.04.25 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2156357B1 patent drawingFigure 1
  • EP2156357B1 patent drawingFigure 2
  • EP2156357B1 patent drawingFigure 3

AI summary

Techniques and apparatuses for scanning a computing device for malware are described. In one implementation, a trusted operating environment, which includes a trusted operating system and a trusted antivirus tool, is embodied on a removable data storage medium. A computing device is then booted from the removable data storage medium using the trusted operating system. The trusted antivirus tool searches the computing device for malware definition updates (e.g., virus signature updates) and uses the trusted operating system to scan the computing device for malware. In another implementation, a computing device is booting from a trusted operating system on a removable device and a trusted antivirus tool on the removable device scans the computing device for malware. The removable device can update its own internal components (e.g., virus signatures and antivirus tool) by searching the computing device or a remote resource for updates and authenticating any updates that are located.