Trusted Operating Environment for Rootkit Bypass

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer security tools are ineffective against malware that uses rootkits to hide from antivirus scans, allowing infections to persist undetected.

Innovation Solution

A trusted operating environment is created on a removable device with a trusted operating system and antivirus tool, which boots the computing device and scans for malware updates, authenticates them, and interacts with the operating system to perform a thorough virus scan, ensuring accurate detection and removal of malware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If antivirus tools scan the computer's hard disk for viruses using the operating system's function calls, then the scanning process can access files, but malware using rootkits can intercept these function calls and return wrong information, causing the antivirus tool to be unable to detect infections

Engineering Contradiction:
Improvevirus detection accuracyVSAvoidsecurity tool effectiveness
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces a trusted operating environment as an intermediary layer between the antivirus tool and the compromised operating system. This trusted environment provides alternative, unintercepted function calls that allow the antivirus scanner to access files and system information without being fooled by rootkit interceptions, thereby restoring detection accuracy while maintaining system compatibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the operating system functionality by creating a separate trusted operating environment that runs alongside or instead of the compromised OS. This segmentation isolates the antivirus scanning operations from the malicious intercepts, allowing the scanner to operate in a clean, trusted context where function calls cannot be intercepted by rootkits

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If security tools are made more sophisticated to detect hidden malware, then detection capability improves, but the complexity of the security system increases

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidsecurity system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

Rather than making the antivirus tool itself more complex to detect rootkits, the patent introduces a trusted operating environment as a mediator that provides a clean execution context. This approach improves detection capability by eliminating the interception problem at its source, while keeping the antivirus tool's core logic relatively simple and focused on traditional signature-based and heuristic scanning

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the operating system is updated to fix security vulnerabilities, then system security improves, but malware can use these updates to maintain persistence or adapt to new detection methods

Engineering Contradiction:
Improvesystem securityVSAvoidmalware persistence capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent performs preliminary actions by establishing a trusted operating environment before the antivirus scan begins. This trusted environment is configured with known-good system state and unintercepted function calls, allowing the scanner to detect malware that may have adapted to OS updates. The trusted environment serves as a baseline for detecting deviations caused by malicious software

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2156356B1Trusted operating environment for malware detection
Publication Date: 2018.05.02 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2156356B1 patent drawingFigure 1
  • EP2156356B1 patent drawingFigure 2
  • EP2156356B1 patent drawingFigure 3

AI summary

Techniques and apparatuses for scanning a computing device for malware are described. In one implementation, a trusted operating environment, which includes a trusted operating system and a trusted antivirus tool, is embodied on a removable data storage medium. A computing device is then booted from the removable data storage medium using the trusted operating system. The trusted antivirus tool searches the computing device for malware definition updates (e.g., virus signature updates) and uses the trusted operating system to scan the computing device for malware. In another implementation, a computing device is booting from a trusted operating system on a removable device and a trusted antivirus tool on the removable device scans the computing device for malware. The removable device can update its own internal components (e.g., virus signatures and antivirus tool) by searching the computing device or a remote resource for updates and authenticating any updates that are located.