Trusted Network Bootstrap for Secure Malware Scanning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing malware scanning methods require a clean external storage device or media to ensure the scanner's integrity, which is inconvenient and may not guarantee the scanner's trustworthiness, as there's no assurance that the scanner itself hasn't been compromised.
Innovation Solution
Booting from a trusted network image allows a computer system to connect to a trusted server over a Wide Area Network, where a trusted network bootstrap program can be downloaded and executed for maintenance operations like malware scanning, using mechanisms like PXE boot, TPM for trust establishment, and out-of-band communication for validation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a bootable external storage device is used to run an offline malware scanner, then the scanner can run from a known clean location, but the user needs additional external media and a clean computer system to create the bootable image
Solution Approach 1:
The patent extracts the malware scanning functionality from the compromised system and delivers it via network bootstrap programs to a remote execution environment, eliminating the need for external storage media while maintaining scanner integrity through network-based delivery from trusted sources
Solution Approach 2:
The patent introduces a network bootstrap program as an intermediary that facilitates the delivery and execution of malware scanning tools in a trusted remote environment, eliminating the need for local external media while ensuring scanner integrity through network-based authentication and verification mechanisms
2Reliability
If a bootable external storage device is used to run an offline malware scanner, then the scanner runs offline, but the user must manually create and manage bootable media
Solution Approach 1:
The patent replaces the mechanical system of physical external storage media with a network-based delivery mechanism, where bootstrap programs and malware scanning tools are transmitted over the network to a remote execution environment, eliminating manual media creation and management while maintaining isolation through virtualized network execution
3Ease of operation
If the malware scanner runs from the infected computer system, then no external media is needed, but there is no way to insure that the malware scanner itself has not been compromised
Solution Approach 1:
The patent inverts the traditional approach by not bringing the scanner to the infected system, but instead bringing the infected system's data to a remote trusted execution environment via network bootstrap programs, thereby ensuring scanner trustworthiness while maintaining operational simplicity through automated network-based execution
Solution Approach 2:
The patent introduces a network bootstrap program as an intermediary that establishes a trusted execution environment remotely, allowing malware scanning to occur in an isolated network-based environment rather than on the infected system itself, ensuring scanner integrity while maintaining ease of operation through automated network execution
Data Source
AI summary
The present invention extends to methods, systems, and computer program products for booting from a trusted network image. The image can be executed from a trusted source on a Wide Area Network (“WAN”) to perform a maintenance operation, such as, for example, malware scanning, operating system repair, factory reset, etc. at the computer system. Trust can be established using a Certificate Authority or an out of band communication channel (e.g., voice communication, text message, electronic mail, etc.) to retrieve a one-time pad (“OTP”). Using the OTP the computer can validate that it is connected to the trusted source. The trusted source can chain to additional images hosted on a third-party server. The additional images can provide a user with options for various different maintenance operations or various different implementations of the same maintenance operation. For example, the trusted source can link to multiple different malware scanners.


