IP Library Granted Patent US 10,122,739
Granted Patent B2
US 10,122,739 · App. 15/253,427 · Granted Nov 6, 2018

Rootkit detection system and method

Inventors: David Warden (Leander, TX); Marshal F. Savage (Austin, TX)
Assignee: Dell Products L.P.
H04L63/1416H04L9/3247H04L63/0442H04L63/061H04L63/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,122,739
App. No.
15/253,427
Granted
Nov 6, 2018
Kind
B2
Abstract

A rootkit detection method includes obtaining, from a target system, first data comprising raw data stored in a data block of a storage drive, checking the first data for known malware, and generating a first alert if known malware is detected. The drive may include a public key, the first data may include a digital signature based on the key, and checking the first data may include validating the signature. The method may be performed by a system management resource that sends a management request for a particular data block. Second data, corresponding to an operating system access of the particular data block, may be obtained and compared to the first data. Responsive to detecting a discrepancy, generating a second alert. The system management resource may be a cloud based server, a premise installed appliance, premise installed security server, or a management controller of the target system.

Claims (53)

1. A rootkit detection method comprising:

obtaining, from a storage subsystem of a target information handling system, first data comprising raw data stored in a particular data block of a storage drive within the storage subsystem, wherein obtaining the first data includes sending, by a system management resource, a management request for the particular data block;

checking the first data for known malware; and

responsive to detecting known malware in the first data, generating a malware alert;

obtaining host configuration information from the target information handling system, wherein the host configuration information includes storage configuration information indicating storage controllers and storage drives associated with the target information handling system;

comparing a current storage configuration of the target information handling system to a previous storage configuration and, responsive to detecting a discrepancy, generating a storage configuration alert.

2. The method of claim 1 , wherein the storage drive includes a public-key certificate, signed by a trusted authority, indicative of a unique identifier of the storage drive and wherein the first data includes a digital signature in accordance with the raw data and the public-key certificate and wherein checking the first data includes verifying the digital signature.

3. The method of claim 1 , further comprising:

obtaining second data comprising data corresponding to an operating system access of the particular data block;

comparing the first data to the second data, and

responsive to detecting a discrepancy, generating a second alert.

4. The method of claim 1 , wherein the system management resource comprises a rootkit detection system implemented as a system selected from:

a cloud based server;

a premise installed appliance;

a premise installed security server; and

a management controller of the target information handling system.

5. The method of claim 1 , wherein the target information handling system includes a secure storage drive coupled to a managed host and wherein the managed host is configured to respond to the management request by returning raw data stored in the particular data block.

6. The method of claim 5 , wherein the raw data comprises encrypted raw data and wherein the method includes:

requesting a decryption key from the target information handling system; and

responsive to receiving the decryption key, decrypting the encrypted raw data to obtain decrypted data, wherein checking the first data comprises scanning the decrypted data.

7. The method of claim 1 , wherein the raw data comprises one or more files necessary to load an operating system hosted by a file system.

8. The method of claim 7 , wherein checking the first data comprises comparing each of the one or more files necessary to load the operating system against at least one of:

an expected value; and

a verified digital signature.

9. The method of claim 7 , further comprising:

emulating at least a portion of a boot process;

identifying accessed files comprising files accessed during the portion of the boot process; and

checking the accessed files for known malware.

10. The method of claim 9 , wherein emulating at least a portion of the boot process comprises emulating the boot process for a particular interval following an initiation of system boot and wherein the accessed files comprises files accessed by the boot process within the particular interval.

11. The method of claim 7 , wherein the target information handling system comprises:

a file system hosting a hypervisor; and

nested file systems comprising data files representing storage of guest operating systems and wherein the raw data comprises files necessary to load the guest operating systems.

12. A rootkit detection method comprising:

obtaining, from a storage subsystem of a target information handling system, first data comprising raw data stored in a data block of a storage drive within the storage subsystem, wherein the target information handling system comprises a managed host system configured to respond to a management request for host configuration information by returning configuration lists indicating storage controllers and storage drives associated with the target information handling system;

checking the first data for known malware;

responsive to detecting known malware in the first data, generating a malware alert;

sending a management request for current host configuration information for the target information handling system; and

comparing a current storage configuration of the target information handling system to a previous storage configuration and, responsive to detecting a discrepancy, generating a storage configuration alert.

13. The method of claim 12 , further comprising:

obtaining from the storage subsystem of the target information handling system, unallocated data comprising raw data stored in an unallocated data block of the storage drive within the storage subsystem;

scanning the unallocated data for known malware; and

responsive to detecting known malware in the unallocated data, generating a unallocated access alert.

14. The method of claim 12 , wherein the target information handling system is further configured to respond to management requests for a block of system RAM by returning digitally signed data corresponding to raw data in the block of system RAM.

15. The method of claim 12 , wherein comparing the current storage configuration information includes:

retrieving as-built configuration information, indicative of an original configuration of the storage controllers and storage drives attached to the target information handling system; and

comparing the as-built configuration information to the current configuration information.

16. The method of claim 12 , wherein the target information handling system is further configured to respond to management requests for host information by returning configuration lists indicating at least one of: hypervisors and operating systems of the target information handling system.

17. The method of claim 12 , wherein the storage drive includes a public-key certificate, signed by a trusted authority, indicative of a unique identifier of the storage drive and wherein the first data includes a digital signature in accordance with the raw data and the public-key certificate and wherein checking the first data includes verifying the digital signature.

18. The method of claim 12 , wherein the target information handling system is further configured to respond to management requests for a block of system RAM by returning digitally signed data corresponding to raw data in the block of system RAM.

19. The method of claim 12 , further comprising:

obtaining, from the storage subsystem of the target information handling system, unallocated data comprising raw data stored in an unallocated data block of the storage drive within the storage subsystem;

scanning the unallocated data for known malware; and

responsive to detecting known malware in the unallocated data, generating a fourth alert.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040679/0386) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 059803/0666 →
RELEASE OF SECURITY INTEREST AT REEL 040633 FRAME 0799 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL INTERNATIONAL, L.L.C.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.; EMC CORPORATION
Reel/Frame 058297/0427 →
RELEASE OF SECURITY INTEREST AT REEL 048825 FRAME 0489 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058000/0916 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Apr 8, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 048825/0489 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Nov 23, 2016
From: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.; EMC CORPORATION
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 040679/0386 →
SECURITY INTEREST Recorded Nov 16, 2016
From: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.; EMC CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040633/0799 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2016
From: WARDEN, DAVID; SAVAGE, MARSHAL F.
To: DELL PRODUCTS L.P.
Reel/Frame 039606/0568 →
Continuity (1)
Related Publication 20180063166A1 · Mar 1, 2018