IP Library Granted Patent US 9,817,975
Granted Patent B2
US 9,817,975 · App. 14/605,537 · Granted Nov 14, 2017

Method for logging firmware attack event and system therefor

Inventors: Wei Liu (Austin, TX); Juan F. Diaz (Round Rock, TX)
Assignee: DELL PRODUCTS, LP
G06F21/566G06F21/554G06F21/572G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,817,975
App. No.
14/605,537
Filed
Jan 26, 2015
Granted
Nov 14, 2017
Kind
B2
Art Unit
2435
USPC
726/1
Abstract

A violation of a firmware access rule is detected, and an entry is generated at a log file stored at a baseboard management controller, the entry identifying the violation. In an embodiment, detecting the violation is in response to receiving a system management interrupt at an information handling system.

Claims (35)

1. A method comprising:

receiving a system management interrupt (SMI) at an information handling system;

executing an SMI handler in response to receiving the SMI, the SMI handler defining a list of firmware access rules identifying potentially malicious activity;

detecting by the SMI handler a violation of a firmware access rule included at the list; and

generating an entry at a log file stored at a memory included at a baseboard management controller, the entry identifying the violation.

2. The method of claim 1 , further comprising generating an electronic mail message informing a user of the information handling system that the violation has been detected.

3. The method of claim 1 , wherein the violation comprises an attempt to perform a write operation at a firmware memory after the memory has been declared as read-only.

4. The method of claim 1 , wherein the violation comprises a failure to authenticate a payload containing a firmware image or a failure to authenticate a variable to be stored at a firmware memory.

5. The method of claim 1 , wherein the violation comprises determining that there is insufficient space at a firmware memory to store a variable.

6. The method of claim 1 , wherein the violation comprises detecting a buffer overrun that would result in modification of system management mode program instructions.

7. The method of claim 1 , wherein the violation comprises determining whether a system management interrupt handler is attempting to execute instructions at a memory address that is not included at a region of system memory corresponding to a system management mode.

8. The method of claim 1 , wherein the log file is a system event log.

9. An information handling system comprising:

a processor;

a system memory device; and

a firmware memory device for storing firmware, the firmware including instructions to:

receive a system management interrupt (SMI) at an information handling system;

execute an SMI handler in response to receiving the SMI, the SMI handler defining a list of firmware access rules identifying potentially malicious activity;

detect by the SMI handler a violation of a firmware access rule included at the list; and

generate an entry at a log file stored at a memory included at a baseboard management controller, the entry identifying the violation.

10. The system of claim 9 , further comprising instructions to generate an electronic mail message informing a user of the information handling system that the violation has been detected.

11. The system of claim 9 , wherein the violation comprises an attempt to perform a write operation at a firmware memory after the memory has been declared as read-only.

12. The system of claim 9 , wherein the violation comprises a failure to authenticate a payload containing a firmware image or a failure to authenticate a variable to be stored at a firmware memory.

13. The system of claim 9 , wherein the violation comprises determining that there is insufficient space at a firmware memory to store a variable.

14. The system of claim 9 , wherein the violation comprises detecting a buffer overrun that would result in modification of system management mode program instructions.

15. The system of claim 9 , wherein the violation comprises determining whether a system management interrupt handler is attempting to execute instructions at a memory address that is not included at a region of system memory corresponding to a system management mode.

16. The system of claim 9 , wherein the log file is a system event log.

17. A non-transitory data storage medium storing instructions executable by a processor to cause the processor to:

receive a system management interrupt at an information handling system;

execute an SMI handler in response to receiving the SMI, the SMI handler defining a list of firmware access rules identifying potentially malicious activity;

detect by the SMI handler a violation of a firmware access rule included at the list; and

generate an entry at a log file stored at a memory included at a baseboard management controller, the entry identifying the violation.

18. The medium of claim 17 , further comprising instructions to generate an electronic mail message informing a user of the information handling system that the violation has been detected.

19. The method of claim 1 , further comprising blocking modification of firmware in response to the detecting.

20. The system of claim 9 , further comprising instructions to block modification of firmware in response to the detecting.

Assignments (16)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2017
From: LIU, WEI; DIAZ, JUAN F.
To: DELL PRODUCTS, LP
Reel/Frame 042231/0633 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2016
From: LIU, WEI; DIAZ, JUAN F.
To: DELL PRODUCTS, LP
Reel/Frame 040149/0108 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
RELEASE OF REEL 035103 FRAME 0809 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.
Reel/Frame 040027/0934 →
RELEASE OF REEL 035104 FRAME 0043 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.
Reel/Frame 040027/0123 →
RELEASE OF REEL 035103 FRAME 0536 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.
Reel/Frame 040016/0864 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Feb 26, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 035103/0536 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Feb 26, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 035103/0809 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Feb 26, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 035104/0043 →
Continuity (1)
Related Publication 20160217283A1 · Jul 28, 2016