Trusted Environment Boot for Rootkit Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional antivirus software is ineffective in detecting and removing rootkit-enabled viruses, especially when virus signatures are outdated or when users fail to perform proactive scans from a clean operating system, leading to potential ongoing threats due to user interaction requirements.
Innovation Solution
The system automatically reboots from a trusted, unalterable environment upon the computing device entering a hibernated state, allowing for operations like antivirus scans to be performed without user interaction, using a component that can scan for viruses including rootkit-enabled ones without disrupting the user's session.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional antivirus software runs from within the operating system, then it can detect known viruses using signatures, but it cannot effectively detect rootkit-enabled viruses that hide themselves from the operating system
Solution Approach 1:
The patent inverts the traditional antivirus approach by booting the entire operating system from a clean, trusted image rather than running antivirus software from within the potentially compromised OS. This reversal allows detection of rootkits and hidden viruses that would otherwise remain undetected, as the trusted environment cannot be altered by malicious software running in the hibernated OS.
2Reliability
If users proactively choose to scan from a clean operating system image, then detection effectiveness improves, but user interaction requirements cause users to often not perform scans
Solution Approach 1:
The system performs self-service security scanning by automatically detecting when the OS enters a hibernated state and triggering a boot from the clean trusted image without requiring user intervention. The hibernation event itself serves as the trigger, making the security scan an automatic self-service operation rather than a manual user task.
Solution Approach 2:
The patent implements periodic security scanning by utilizing each hibernation event as an opportunity to boot from the clean image and perform detection. Since hibernation occurs periodically when the device is idle, this creates automatic periodic security checks without burdening the user with manual scan decisions.
3Ease of operation
If the system requires user interaction to initiate scans, then user control is maintained, but the computing device remains subject to attack during user inactivity
Solution Approach 1:
The system takes preliminary action by automatically initiating security scans during hibernation periods when the device would otherwise be vulnerable. Rather than waiting for user input, the system proactively performs detection and remediation actions during idle time, preventing attacks before they can exploit the inactive period.
4Productivity
If antivirus software performs periodic scans from the running operating system, then it can detect known viruses, but it cannot detect zero-day exploits or viruses with outdated signatures
Solution Approach 1:
The patent reverses the traditional approach by using a clean, trusted operating system image to boot and scan the potentially infected system, rather than running scans from within the potentially compromised OS. This inversion ensures that even zero-day exploits and viruses with outdated signatures cannot hide from the scan, as the scanning environment itself is guaranteed to be clean and unalterable.
Data Source
AI summary
Techniques described are capable of receiving an indication that an operating system of a computing device has entered a hibernated state and, in response, booting the computing device from a trusted environment that is unalterable by the hibernated operating system. A component stored on or accessible by the trusted environment may then perform an operation on the computing device. This operation may include scanning the device, performing a memory test on the device, or updating firmware on the device. In some instances, the computing device enters the hibernated state due to a predetermined length of user inactivity on the computing device. As such, the described techniques may perform an operation on the computing device without user interaction causing the operation.


