IP Library Granted Patent US 8,869,282
Granted Patent B1
US 8,869,282 · App. 12/579,734 · Granted Oct 21, 2014

Anti-malware support for firmware

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,869,282
App. No.
12/579,734
Granted
Oct 21, 2014
Kind
B1
Abstract

Technologies are described herein for anti-malware support within firmware. Through the utilization of the technologies and concepts presented herein, malicious software protection may be extended down to the firmware level. Detecting malicious firmware or software, removing it from firmware, and actively preventing it from exploiting known security vulnerabilities may be supported. Application level anti-malware software may interface with, and be supported by, one or more firmware level anti-malware modules. Firmware level anti-malware modules can actively prevent malicious software from affecting the system firmware. For example, the anti-malware modules may monitor or block access to the firmware. Anti-malware modules may be available at both boot-time and run-time. Thus, a wider range of malicious software attacks or infiltrations may be mitigated.

Claims (29)

1. A computer-implemented method for supporting anti-malware operations within a firmware of a computer, the computer-implemented method comprising:

receiving a first request at a firmware level anti-malware module stored within the firmware of the computer to perform a malware scan;

in response to receiving the first request, performing the malware scan by scanning the firmware by the anti-malware module;

receiving a second request at the firmware level anti-malware module stored within the firmware to perform monitoring of firmware accesses during a normal operational mode following a boot-time; and

performing the monitoring of the firmware accesses by the anti-malware module in response to receiving the second request, and

wherein the anti-malware module is configured to block unauthorized modifications to the firmware.

2. The method of claim 1 , wherein the anti-malware module is further configured to expose a configuration interface for configuring a frequency of performing the malware scan.

3. The method of claim 1 , further comprising providing an interface between the anti-malware module and an anti-malware application executing at an operating system level.

4. The method of claim 1 , wherein the anti-malware module comprises a boot-time module for performing the malware scan.

5. The method of claim 1 , wherein the anti-malware module comprises a run-time module for performing the monitoring of the firmware accesses.

6. A computing system comprising:

a processing unit; and

a non-volatile memory device storing a firmware comprising an anti-malware module for execution, at a firmware level, on the processing unit, configured to perform anti-malware operations comprising

performing a malware scan by scanning the firmware by the anti-malware module,

perform monitoring of firmware accesses, by the anti-malware module, during a normal operational mode following a boot-time,

blocking unauthorized modifications to the firmware, and

providing an interface between the anti-malware module and an anti-malware application executing at an operating system level.

7. The computing system of claim 6 , wherein monitoring the firmware accesses during the normal operational mode following a boot-time further comprises monitoring the firmware accesses for malware.

8. The computing system of claim 6 , wherein the anti-malware module is further configured to provide a configuration interface for configuring a frequency of performing the malware scan.

9. The computing system of claim 6 , wherein the anti-malware module comprises a boot-time anti-malware module.

10. The computing system of claim 9 , wherein the anti-malware application is configured to load and configure the boot-time anti-malware module through the interface between the anti-malware module and the anti-malware application.

11. The computing system of claim 6 , wherein the anti-malware module comprises a run-time anti-malware module.

12. The computing system of claim 11 , wherein the anti-malware application is configured to load and configure the run-time anti-malware module through the interface between the anti-malware module and the anti-malware application.

13. A non-transitory computer storage medium having computer-executable instructions stored thereon which, when executed by a computer system, cause the computer system to:

provide anti-malware support from an anti-malware module stored within a computer system firmware, the anti-malware module comprising a boot-time module and a run-time module, and the anti-malware support comprising

performing a malware scan by scanning the firmware for malware by the anti-malware module,

performing monitoring of firmware accesses during a normal operational mode following a boot-time for malware by the anti-malware module, and

blocking unauthorized modifications to the firmware; and

provide an interface between the anti-malware module stored in the computer system firmware and an anti-malware application executing at an operating system level.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Oct 17, 2024
From: MIDCAP FINANCIAL TRUST
To: AMERICAN MEGATRENDS INTERNATIONAL, LLC
Reel/Frame 069205/0795 →
SECURITY INTEREST Recorded May 6, 2019
From: AMERICAN MEGATRENDS INTERNATIONAL, LLC
To: MIDCAP FINANCIAL TRUST, AS COLLATERAL AGENT
Reel/Frame 049087/0266 →
ENTITY CONVERSION Recorded Apr 15, 2019
From: AMERICAN MEGATRENDS, INC.
To: AMERICAN MEGATRENDS INTERNATIONAL, LLC
Reel/Frame 049091/0973 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2009
From: LAZAROWITZ, MATTHEW
To: AMERICAN MEGATRENDS, INC.
Reel/Frame 023403/0338 →