Trusted Diskless OS for Out-of-Band Security Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
User devices can become inoperable or compromised due to corrupted operating systems or malware infections, which allow attackers to gain administrator access and evade detection by antivirus systems.
Innovation Solution
A secured augmented trusted diskless operating system image is launched via device hardware components like BIOS, allowing for out-of-band security inspections and scans without executing the compromised OS, using a security agent to detect issues, hibernate the system, and boot into a trusted image for security scanning and repair.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a compromised operating system is used for security inspections, then the inspection process can be performed, but the inspection results may be inaccurate or evaded due to malware manipulation
Solution Approach 1:
The patent introduces a trusted third-party inspection system that operates independently from the compromised operating system. This intermediary system boots from external media (USB drive or network) and performs security inspections without executing code from the potentially infected local storage, thereby eliminating malware manipulation of inspection results.
Solution Approach 2:
The inspection system extracts itself from the compromised operating system environment by booting from external media. This separation removes the inspection process from the harmful context of the compromised OS, allowing unbiased security analysis without interference from malware.
2Reliability
If the operating system is hibernated or rebooted for security scanning, then malware detection can be performed, but device availability and operational continuity are reduced
Solution Approach 1:
The system performs preliminary security inspections during the boot process before the compromised operating system fully loads. By detecting threats during this preliminary phase and isolating them, the system can perform security scans without requiring full system hibernation or extended reboots, minimizing disruption to device availability.
3Reliability
If antivirus systems and security checks are used within the compromised OS, then security monitoring can be performed, but these systems can be subverted by attackers to hide from detection
Solution Approach 1:
The inspection system operates as an external intermediary that does not rely on the compromised OS's own security mechanisms. Instead, it brings its own trusted security checks from external media, eliminating the vulnerability where attackers can subvert built-in antivirus systems to hide their presence.
Solution Approach 2:
The security inspection process is segmented from the compromised operating system by booting from separate external media. This segmentation ensures that the inspection mechanisms remain independent and trusted, while the compromised OS is analyzed as an external target rather than executing its own potentially manipulated security checks.
Data Source
AI summary
In some examples, a method for performing an out-of-band security inspection of a device comprises generating a snapshot of the state of the device, storing data representing the snapshot to a non-volatile storage of the device, and storing a hash of the snapshot in a device BIOS, transitioning the power state of the device, triggering boot of a trusted diskless operating system image, providing the data representing the snapshot and the hash of the snapshot to the trusted diskless operating system image, and executing a script selected on the basis of a trigger event and the hash of the snapshot to analyse at least a portion of the non-volatile storage of the device.

