IP Library Granted Patent US 11,423,153
Granted Patent B2
US 11,423,153 · App. 16/996,529 · Granted Aug 23, 2022

Detection of malicious operating system booting and operating system loading

Inventor: Daniel S. Rose (Salado, TX)
Assignee: Raytheon Company
G06F21/575G06F9/4406G06F9/44505G06F21/54G06F21/566G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,423,153
App. No.
16/996,529
Granted
Aug 23, 2022
Kind
B2
Abstract

A system detects deviation from a computer operating system boot and operating system load. The system identifies approved operating system boot modules, approved operating system load modules, essential operating system boot components, and essential operating system configuration information, which are then hashed to create an operating system boot profile. The operating system boot modules and the operating system load modules are then executed to start the operating system. The operating system boot profile is used to verify that that there has not be any deviation from the start of the operating system.

Claims (33)

1. A process to detect deviation from an operating system boot and an operating system load comprising: (a) identifying with a computer processor a plurality of approved operating system boot modules, a plurality of approved operating system load modules, essential operating system boot components, and essential operating system configuration information; (b) generating an operating system boot profile based on a hashing of the operating system boot modules, the operating system load modules, and at least one of the essential operating system boot components or the essential operating system configuration information; (c) executing the operating system boot modules and the operating system load modules to start the operating system; and (d) using the operating system boot profile to verify that there has not been any deviation from the start of the operating system.

2. The process of claim 1 , wherein using the operating system boot profile to verify that there has not been any deviation from the start of the operating system comprises a forensic analysis.

3. The process of claim 2 , wherein the forensic analysis comprises identifying remnants of the operating system boot modules or the operating system load modules.

4. The process of claim 3 , wherein the identifying remnants of operating system boot modules and of the operating system load modules comprises reverse engineering of operating system kernel data structures and operating system kernel memory layout.

5. The process of claim 3 , wherein the identifying remnants of the operating system boot modules or of the operating system load modules comprises:

identifying the operating system boot modules or the operating system load modules that have been loaded and then unloaded during the start of the operating system;

comparing the operating system boot modules or the operating system load modules that have been loaded and then unloaded during the start of the operating system with the operating system boot profile; and

identifying malicious operating system boot modules or malicious operating system load modules based on the comparison.

6. The process of claim 3 , wherein the identifying remnants of the operating system boot modules or of the operating system load modules comprises:

identifying the operating system boot modules or the operating system load modules that have been loaded during the start of the operating system;

comparing the operating system boot modules or the operating system load modules that have been loaded during the start of the operating system with the operating system boot profile; and

identifying malicious operating system boot modules or malicious operating system load modules based on the comparison.

7. The process of claim 5 , comprising halting the start of the operating system when the malicious operating system boot modules or the malicious operating system load modules have been identified.

8. The process of claim 1 , wherein operations (a) and (b) are executed in an offline environment.

9. The process of claim 1 , wherein the plurality of operating system boot modules and the plurality of operating system load modules comprises the operating system boot modules and the operating system load modules that are required for startup of the operating system.

10. A non-transitory computer readable medium comprising instructions that when executed by a processor execute a process comprising: (a) identifying with a computer processor a plurality of approved operating system boot modules, a plurality of approved operating system load modules, essential operating system boot components, and essential operating system configuration information; (b) generating an operating system boot profile based on a hashing of the operating system boot modules, the operating system load modules, and at least one of the essential operating system boot components or the essential operating system configuration information;

(c) executing the operating system boot modules and the operating system load modules to start the operating system; and (d) using the operating system boot profile to verify that there has not been any deviation from the start of the operating system.

11. The non-transitory computer readable medium of claim 10 , wherein using the operating system boot profile to verify that there has not been any deviation from the start of the operating system comprises a forensic analysis.

12. The non-transitory computer readable medium of claim 11 , wherein the forensic analysis comprises instructions for identifying remnants of the operating system boot modules or the operating system load modules.

13. The non-transitory computer readable medium of claim 12 , wherein the identifying remnants of operating system boot modules and of the operating system load modules comprises instructions for reverse engineering of operating system kernel data structures and operating system kernel memory layout.

14. The non-transitory computer readable medium of claim 12 , wherein the identifying remnants of the operating system boot modules or of the operating system load modules comprises instructions for:

identifying the operating system boot modules or the operating system load modules that have been loaded and then unloaded during the start of the operating system;

comparing the operating system boot modules or the operating system load modules that have been loaded and then unloaded during the start of the operating system with the operating system boot profile; and

identifying malicious operating system boot modules or malicious operating system load modules based on the comparison.

15. The non-transitory computer readable medium of claim 12 , wherein the identifying remnants of the operating system boot modules or of the operating system load modules comprises:

identifying the operating system boot modules or the operating system load modules that have been loaded during the start of the operating system;

comparing the operating system boot modules or the operating system load modules that have been loaded during the start of the operating system with the operating system boot profile; and

identifying malicious operating system boot modules or malicious operating system load modules based on the comparison.

16. The non-transitory computer readable medium of claim 15 , comprising instructions for halting the start of the operating system when the malicious operating system boot modules or the malicious operating system load modules have been identified.

17. The non-transitory computer readable medium of claim 10 , wherein operations (a), (b), (c), and (d) are executed in an offline environment.

18. A system comprising: a computer processor; and a memory coupled to the computer processor; wherein the computer processor is operable for: (a) identifying with a computer processor a plurality of approved operating system boot modules, a plurality of approved operating system load modules, essential operating system boot components, and essential operating system configuration information; (b) generating an operating system boot profile based on a hashing of the operating system boot modules, the operating system load modules, and at least one of the essential operating system boot components or the essential operating system configuration information; (c) executing the operating system boot modules and the operating system load modules to start the operating system; and (d) using the operating system boot profile to verify that there has not been any deviation from the start of the operating system.

19. The system of claim 18 , wherein using the operating system boot profile to verify that there has not been any deviation from the start of the operating system comprises identifying remnants of the operating system boot modules or the operating system load modules.

20. The system of claim 18 , wherein the plurality of operating system boot modules and the plurality of operating system load modules comprises the operating system boot modules and the operating system load modules that are required for startup of the operating system.

Assignments (4)
CHANGE OF NAME Recorded Jul 3, 2024
From: COLUMBUS BUYER LLC
To: NIGHTWING GROUP, LLC
Reel/Frame 068106/0251 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2024
From: RAYTHEON COMPANY
To: COLUMBUS BUYER LLC
Reel/Frame 068233/0420 →
SECURITY INTEREST Recorded Apr 1, 2024
From: COLUMBUS BUYER LLC; RAYTHEON BLACKBIRD TECHNOLOGIES, INC.; RAYTHEON FOREGROUND SECURITY, INC.
To: WELLS FARGO BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066960/0411 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2020
From: ROSE, DANIEL S.
To: RAYTHEON COMPANY
Reel/Frame 053532/0852 →