IP Library Granted Patent US 9,785,492
Granted Patent B1
US 9,785,492 · App. 14/101,130 · Granted Oct 10, 2017

Technique for hypervisor-based firmware acquisition and analysis

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,785,492
App. No.
14/101,130
Granted
Oct 10, 2017
Kind
B1
Abstract

A method includes detecting a triggering event at a hypervisor, where the hypervisor is executed by a computing node. The method also includes capturing, from a memory device of the computing node using the hypervisor, one or more images of a basic input/output system (BIOS) of the computing node and/or a firmware of the computing node. The method further includes analyzing the one or more images to detect a problem with the computing node and taking at least one action in response to detecting the problem with the computing node. The one or more images are obtained by the hypervisor directly from the memory device.

Claims (43)

1. A method comprising:

detecting a triggering event at a hypervisor, the hypervisor executed by a computing node;

capturing, by the hypervisor from a memory device of the computing node, one or more images of at least one of: a basic input/output system (BIOS) of the computing node and a firmware of the computing node;

analyzing the one or more images to detect a problem with the computing node; and

taking at least one action in response to detecting the problem with the computing node;

wherein the one or more images are captured by the hypervisor directly from the memory device without having data defining the one or more images pass through any intervening application.

2. The method of claim 1 , wherein analyzing the one or more images comprises:

performing a hashing operation of at least one of the one or more images; and

comparing results of the hashing operation against hash results associated with one or more known good images of the BIOS or firmware.

3. The method of claim 1 , wherein analyzing the one or more images comprises:

determining whether different portions of the BIOS or firmware are associated with different vendors.

4. The method of claim 1 , wherein the triggering event comprises a request to create, modify, or execute a virtual machine on the computing node.

5. The method of claim 1 , wherein the triggering event comprises a request from an authorized application executing within a virtual machine on the computing node.

6. The method of claim 1 , wherein the detecting, capturing, analyzing, and taking occur repeatedly while the computing node is in an operational state after bootup.

7. The method of claim 1 , wherein the hypervisor is a first hypervisor, and the triggering event is associated with execution of a virtual machine managed by a second hypervisor executed by the computing node.

8. An apparatus comprising:

at least one memory; and

at least one processing device configured to execute a hypervisor, wherein the at least one processing device is configured when executing the hypervisor to:

detect a triggering event;

capture, from the at least one memory, one or more images of at least one of: a basic input/output system (BIOS) of the apparatus and a firmware of the apparatus;

analyze the one or more images to detect a problem with the apparatus; and

take at least one action in response to detecting the problem with the apparatus;

wherein the hypervisor is configured to capture the one or more images directly from the at least one memory without having data defining the one or more images pass through any intervening application.

9. The apparatus of claim 8 , wherein the at least one processing device is configured to analyze the one or more images by:

performing a hashing operation of at least one of the one or more images; and

comparing results of the hashing operation against hash results associated with one or more known good images of the BIOS or firmware.

10. The apparatus of claim 8 , wherein the at least one processing device is configured to analyze the one or more images by determining whether different portions of the BIOS or firmware are associated with different vendors.

11. The apparatus of claim 8 , wherein the triggering event comprises a request to create, modify, or execute a virtual machine on the apparatus.

12. The apparatus of claim 8 , wherein the at least one processing device is configured to detect the triggering event, capture the one or more images, analyze the one or more images, and take the at least one action repeatedly while the apparatus is in an operational state after bootup.

13. The apparatus of claim 8 , wherein the at least one processing device is configured to take the at least one action by disabling or stopping execution of one or more virtual machines by the apparatus.

14. The apparatus of claim 8 , wherein the apparatus comprises a computing node configured to operate within a computing cloud.

15. A non-transitory computer readable medium storing computer readable program code that when executed causes a computing node to:

detect a triggering event at a hypervisor;

capture, by the hypervisor directly from a memory device of the computing node, one or more images of at least one of: a basic input/output system (BIOS) of the computing node and a firmware of the computing node without having data defining the one or more images pass through any intervening application;

analyze the one or more images to detect a problem with the computing node; and

take at least one action in response to detecting the problem with the computing node.

16. The computer readable medium of claim 15 , wherein the computer readable program code that when executed causes the computing node to analyze the one or more images comprises computer readable program code that when executed causes the computing node to:

perform a hashing operation of at least one of the one or more images; and

compare results of the hashing operation against hash results associated with one or more known good images of the BIOS or firmware.

17. The computer readable medium of claim 15 , wherein the computer readable program code that when executed causes the computing node to analyze the one or more images comprises computer readable program code that when executed causes the computing node to determine whether different portions of the BIOS or firmware are associated with different vendors.

18. The computer readable medium of claim 15 , wherein the triggering event comprises a request to create, modify, or execute a virtual machine on the computing node.

19. The computer readable medium of claim 15 , wherein the computer readable program code when executed causes the computing node to detect the triggering event, capture the one or more images, analyze the one or more images, and take the at least one action repeatedly while the computing node is in an operational state after bootup.

20. The computer readable medium of claim 15 , wherein the computer readable program code that when executed causes the computing node to take the at least one action comprises computer readable program code that when executed causes the computing node to disable or stop execution of one or more virtual machines by the computing node.

Assignments (12)
CHANGE OF NAME Recorded Jul 3, 2024
From: COLUMBUS BUYER LLC
To: NIGHTWING GROUP, LLC
Reel/Frame 068106/0251 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2024
From: RAYTHEON COMPANY
To: COLUMBUS BUYER LLC
Reel/Frame 068233/0420 →
SECURITY INTEREST Recorded Apr 1, 2024
From: COLUMBUS BUYER LLC; RAYTHEON BLACKBIRD TECHNOLOGIES, INC.; RAYTHEON FOREGROUND SECURITY, INC.
To: WELLS FARGO BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066960/0411 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2020
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 053927/0280 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2020
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 053389/0473 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: FORCEPOINT FEDERAL LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0460 →
CHANGE OF NAME Recorded Feb 16, 2016
From: RAYTHEON CYBER PRODUCTS, LLC
To: FORCEPOINT FEDERAL LLC
Reel/Frame 037821/0818 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
CHANGE OF NAME Recorded Jun 2, 2015
From: RAYTHEON CYBER PRODUCTS, INC.
To: RAYTHEON CYBER PRODUCTS, LLC
Reel/Frame 035806/0367 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2015
From: RAYTHEON COMPANY
To: RAYTHEON CYBER PRODUCTS, INC.
Reel/Frame 035774/0322 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2013
From: NEUMANN, MATTHEW D.; THOMPSON, IRBY J., JR.; SIMMS, MICHAEL
To: RAYTHEON COMPANY
Reel/Frame 031743/0752 →