Trusted Network Bootstrap for Secure Malware Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing malware scanning methods require a clean external storage device or media to ensure the scanner's integrity, which is inconvenient and may not guarantee the scanner's trustworthiness, as there's no assurance that the scanner itself hasn't been compromised.

Innovation Solution

Booting from a trusted network image allows a computer system to connect to a trusted server over a Wide Area Network, where a trusted network bootstrap program can be downloaded and executed for maintenance operations like malware scanning, using mechanisms like PXE boot, TPM for trust establishment, and out-of-band communication for validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a bootable external storage device is used to run an offline malware scanner, then the scanner can run from a known clean location, but the user needs additional external media and a clean computer system to create the bootable image

Engineering Contradiction:
Improvescanner integrityVSAvoidoperational convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the malware scanning functionality from the compromised system and delivers it via network bootstrap programs to a remote execution environment, eliminating the need for external storage media while maintaining scanner integrity through network-based delivery from trusted sources

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a network bootstrap program as an intermediary that facilitates the delivery and execution of malware scanning tools in a trusted remote environment, eliminating the need for local external media while ensuring scanner integrity through network-based authentication and verification mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a bootable external storage device is used to run an offline malware scanner, then the scanner runs offline, but the user must manually create and manage bootable media

Engineering Contradiction:
Improvescanner isolationVSAvoidmedia management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical system of physical external storage media with a network-based delivery mechanism, where bootstrap programs and malware scanning tools are transmitted over the network to a remote execution environment, eliminating manual media creation and management while maintaining isolation through virtualized network execution

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If the malware scanner runs from the infected computer system, then no external media is needed, but there is no way to insure that the malware scanner itself has not been compromised

Engineering Contradiction:
Improveoperational simplicityVSAvoidscanner trustworthiness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent inverts the traditional approach by not bringing the scanner to the infected system, but instead bringing the infected system's data to a remote trusted execution environment via network bootstrap programs, thereby ensuring scanner trustworthiness while maintaining operational simplicity through automated network-based execution

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces a network bootstrap program as an intermediary that establishes a trusted execution environment remotely, allowing malware scanning to occur in an isolated network-based environment rather than on the infected system itself, ensuring scanner integrity while maintaining ease of operation through automated network execution

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9535715B2Booting from a trusted network image
Publication Date: 2017.01.03 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9535715B2 patent drawing
  • US9535715B2 patent drawing
  • US9535715B2 patent drawing

AI summary

The present invention extends to methods, systems, and computer program products for booting from a trusted network image. The image can be executed from a trusted source on a Wide Area Network (“WAN”) to perform a maintenance operation, such as, for example, malware scanning, operating system repair, factory reset, etc. at the computer system. Trust can be established using a Certificate Authority or an out of band communication channel (e.g., voice communication, text message, electronic mail, etc.) to retrieve a one-time pad (“OTP”). Using the OTP the computer can validate that it is connected to the trusted source. The trusted source can chain to additional images hosted on a third-party server. The additional images can provide a user with options for various different maintenance operations or various different implementations of the same maintenance operation. For example, the trusted source can link to multiple different malware scanners.