IP Library Granted Patent US 9,319,426
Granted Patent B2
US 9,319,426 · App. 13/920,746 · Granted Apr 19, 2016

System and method for operating malicious marker detection software on management controller of protected system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,319,426
App. No.
13/920,746
Granted
Apr 19, 2016
Kind
B2
Abstract

An information handling system includes a processor and a management controller separate from the processor. The management controller is operable to store an anti-virus program and a malicious marker detection program in a memory of the management controller, and to execute the malicious marker detection program. The malicious marker detection program operates to detect a state of a device of the information handling system, determine that the information handling system is under attack from a malicious program in response to detecting the state of the device, and send an alert to a management system coupled to the information handling system, the alert indicating that the information handling system is under attack from the malicious program.

Claims (59)

1. An information handling system, comprising:

a processor to provide a host processing environment; and

a management controller separate from the processor and on a common board with the processor, the management controller operable to:

store an anti-virus program and a malicious marker detection program in a memory of the management controller; and

execute the malicious marker detection program to:

detect a state of a device of the information handling system;

determine that the host processing environment is under attack from a malicious program in response to detecting the state of the device; and

send an alert to a management system coupled to the information handling system, the alert indicating that the host processing environment is under attack from the malicious program.

2. The information handling system of claim 1 , wherein in detecting the state of the device the malicious marker detection program is further executed to:

read a status register of the device.

3. The information handling system of claim 2 , wherein in determining that the host processing environment is under attack the malicious marker detection program is further executed to:

detect that the status register has been changed.

4. The information handling system of claim 1 , wherein in detecting the state of the device the malicious marker detection program is further executed to:

read a memory of the information handling system.

5. The information handling system of claim 1 , wherein in detecting the state of the device the malicious marker detection program is further executed to:

detect a network destination of network traffic on the information handling system.

6. The information handling system of claim 1 , wherein in detecting the state of the device the malicious marker detection program is further executed to:

detect a malicious packet in network traffic on the information handling system.

7. The information handling system of claim 1 , wherein:

the device comprises a network storage device; and

in detecting the state of the device the malicious marker detection program is further executed to read data from the storage device.

8. The information handling system of claim 1 , wherein the management controller is further operable to:

receive an update to the malicious marker detection program from the management system; and

store the update to the malicious marker detection program in the memory of the management controller.

9. The information handling system of claim 8 , wherein, prior to receiving the update to the malicious marker detection program, the management controller is further operable to:

determine that the malicious marker detection program is out of date.

10. The information handling system of claim 1 , wherein the malicious marker detection program is further executed to:

determine that the attack from the malicious program can be mitigated; and

mitigate the attack from the malicious program.

11. A method comprising:

storing an anti-virus program and a malicious marker detection program in a memory of a management controller on an information handling system; and

executing by the management controller the malicious marker detection program, wherein executing the malicious marker detection program comprises:

detecting a state of a device of the information handling system;

determining that a host processing environment instantiated on a processor of the information handling system is under attack from a malicious program in response to detecting the state of the device, wherein the management controller is on a common board with the processor; and

sending an alert to a management system coupled to the information handling system, the alert indicating that the host processing environment is under attack from the malicious program.

12. The method of claim 11 , wherein in detecting the state of the device the malicious marker detection program, executing the malicious marker detection program further comprises:

reading a status register of the device.

13. The method of claim 12 , wherein in determining that the host processing environment is under attack, executing the malicious marker detection program further comprises:

detecting that the status register has been changed.

14. The method of claim 11 , wherein in detecting the state of the device, executing the malicious marker detection program further comprises:

reading a memory of the information handling system.

15. The method of claim 11 , wherein:

the device comprises a network storage device; and

in detecting the state of the device, executing the malicious marker detection program further comprises reading data from the storage device.

16. The method of claim 11 , further comprising:

receiving by the management controller an update to the malicious marker detection program from the management system; and

storing the update to the malicious marker detection program in the memory of the management controller.

17. The method of claim 16 , further comprising:

determine that the malicious marker detection program is out of date, prior to receiving the update to the malicious marker detection program.

18. A non-transitory computer-readable medium including code for carrying out a method, the method comprising:

storing an anti-virus program and a malicious marker detection program in a memory of a management controller; and

executing the malicious marker detection program, wherein executing the malicious marker detection program comprises:

detecting a state of a device of an information handling system;

determining that a host processing environment instantiated on a processor of the information handling system is under attack from a malicious program in response to detecting the state of the device, wherein the management controller is on a common board with the processor; and

sending an alert to a management system coupled to the information handling system, the alert indicating that the host processing environment is under attack from the malicious program.

19. The computer-readable medium of claim 18 , wherein in detecting the state of the device the malicious marker detection program, executing the malicious marker detection program further comprises:

reading a status register of the device.

20. The computer-readable medium of claim 19 , wherein in determining that the host processing environment is under attack, executing the malicious marker detection program further comprises:

detecting that the status register has been changed.

Assignments (13)
SECURITY INTEREST Recorded May 2, 2025
From: SECUREWORKS CORP.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 071156/0529 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
ENTITY CONVERSION WITH NAME CHANGE Recorded Dec 8, 2015
From: SECUREWORKS HOLDING CORPORATION
To: SECUREWORKS CORP.
Reel/Frame 037243/0736 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2015
From: DELL PRODUCTS L.P.
To: SECUREWORKS HOLDING CORPORATION
Reel/Frame 036262/0417 →
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2015
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: SECUREWORKS HOLDING CORPORATION; SECUREWORKS, INC.
Reel/Frame 036262/0525 →
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2015
From: BANK OF AMERICA, N.A.
To: SECUREWORKS HOLDING CORPORATION; SECUREWORKS, INC.
Reel/Frame 036262/0509 →
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2015
From: BANK OF AMERICA, N.A.
To: SECUREWORKS HOLDING CORPORATION; SECUREWORKS, INC.
Reel/Frame 036262/0490 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2013
From: WEBB, THEODORE S.; WILSON, JACQUELINE H.; RAMSEY, JON R.; KHATRI, MUKUND P.
To: DELL PRODUCTS, LP
Reel/Frame 030637/0463 →