Trusted OS Malware Detection via Kernel Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security tools are ineffective against malware that uses rootkits to hide from antivirus scans, allowing infections to persist undetected.
Innovation Solution
A trusted operating environment, comprising a trusted operating system and antivirus tool, is created to boot and scan a computing device, using authentication protocols and microcontrollers to ensure accurate detection and removal of malware, even if rootkits are present.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional antivirus tools are used to scan for malware, then basic virus detection is possible, but malware using rootkits can hide and remain undetected
Solution Approach 1:
The patent inverts the traditional scanning approach by having the operating system kernel provide authentication information to the antivirus tool, rather than the antivirus tool attempting to query hidden files. This reversal allows the trusted OS to reveal what files actually exist, bypassing rootkit deception.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism where the OS kernel acts as a mediator between the antivirus tool and the file system. The kernel's authentication layer verifies file existence and provides accurate information to the antivirus tool, preventing rootkits from intercepting or falsifying file access requests.
2Object-affected harmful factors
If rootkits intercept function calls to hide files, then malware can conceal itself, but security tools cannot access the requested files to check for infections
Solution Approach 1:
The patent applies preliminary anti-action by having the OS kernel pre-authenticate and validate file access requests before they reach potential rootkit interceptors. This advance authentication ensures that only legitimate file access operations proceed, preventing malware from concealing files through intercepted function calls.
3Reliability
If a trusted operating environment is implemented to ensure accurate malware detection, then detection reliability improves, but system complexity increases
Solution Approach 1:
The patent segments the authentication function into a separate kernel module that works alongside the existing OS. This modular approach allows trusted authentication mechanisms to be added without completely redesigning the operating system, thereby reducing the increase in system complexity while maintaining detection reliability.
Data Source
AI summary
Described herein are techniques and apparatuses for scanning a computing device for malware and/or viruses. In various embodiments, a trusted operating environment, which may include a trusted operating system and/or a trusted antivirus tool, may be utilized with respect to a computing device. More particularly, the trusted operating system may be used to boot the computing device. Moreover, the trusted antivirus tool may search the computing device for malware definition updates (e.g., virus signature updates) and use the trusted operating system to scan the computing device for malware. In other embodiments, the trusted antivirus tool may scan the computing device and remove any viruses detected by the trusted antivirus tool. The trusted operating system may then reboot the computing device into a clean environment once any detected viruses are removed.


