IP Library Granted Patent US 11,797,682
Granted Patent B2
US 11,797,682 · App. 17/375,809 · Granted Oct 24, 2023

Pre-OS resiliency

Inventors: Ibrahim Sayyed (Georgetown, TX); Daniel L. Hamlin (Round Rock, TX)
Assignee: Dell Products L.P.
G06F21/575G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,797,682
App. No.
17/375,809
Granted
Oct 24, 2023
Kind
B2
Abstract

An information handling system may include a physical storage resource having a portion thereof that includes files that are usable during boot of the information handling system; at least one processor; and a Basic Input/Output System (BIOS) including instructions that are executable by the at least one processor for: during a boot process, determining whether any of a plurality of BIOS events have taken place during a previous boot process, wherein the plurality of BIOS events are indicative of malicious behavior during the previous boot process; and in response to a determination that at least a predetermined number of the plurality of BIOS events have taken place during the previous boot process, carrying out a remedial action during the boot process.

Claims (27)

1. An information handling system comprising:

a physical storage resource having a portion thereof that includes files that are usable during boot of the information handling system;

at least one processor; and

a Basic Input/Output System (BIOS) including instructions that are executable by the at least one processor for:

during a boot process and prior to beginning initialization of an operating system (OS), determining whether any of a plurality of BIOS events have taken place during a previous boot process, wherein the plurality of BIOS events are indicative of malicious behavior during the previous boot process, and wherein the plurality of BIOS events includes a Secure Boot configuration change event; and

in response to a determination that at least a predetermined number of the plurality of BIOS events have taken place during the previous boot process, carrying out a remedial action during the boot process and prior to initialization of the OS.

2. The information handling system of claim 1 , wherein the BIOS is a Unified Extensible Firmware Interface (UEFI) BIOS.

3. The information handling system of claim 2 , wherein the portion of the physical storage resource is an Extensible Firmware Interface (EFI) System Partition (ESP).

4. The information handling system of claim 1 , wherein the plurality of BIOS events further includes at least one event selected from the group consisting of a boot deviation attempt, an increased boot time, a setting change relating to the physical storage resource, and an incomplete boot.

5. The information handling system of claim 1 , wherein the instructions are further executable for notifying a user prior to carrying out the remedial action.

6. The information handling system of claim 1 , wherein the remedial action includes at least one action selected from the group consisting of booting to a service operating system, parsing at least one of the files that are usable during boot and changing a setting therein, and updating the BIOS to restore a missing recovery file.

7. A method comprising:

during a boot process and prior to beginning initialization of an operating system (OS) of an information handling system that includes a physical storage resource having a portion thereof that includes files that are usable during boot of the information handling system, at least one processor, and a Basic Input/Output System (BIOS), the information handling system determining whether any of a plurality of BIOS events have taken place during a previous boot process, wherein the plurality of BIOS events are indicative of malicious behavior during the previous boot process, and wherein the plurality of BIOS events includes a Secure Boot configuration change event; and

in response to a determination that at least a predetermined number of the plurality of BIOS events have taken place during the previous boot process, the information handling system carrying out a remedial action during the boot process and prior to initialization of the OS.

8. The method of claim 7 , wherein the BIOS is a Unified Extensible Firmware Interface (UEFI) BIOS.

9. The method of claim 8 , wherein the portion of the physical storage resource is an Extensible Firmware Interface (EFI) System Partition (ESP).

10. The method of claim 7 , wherein the plurality of BIOS events further includes at least one event selected from the group consisting of a boot deviation attempt, an increased boot time, a setting change relating to the physical storage resource, and an incomplete boot.

11. The method of claim 7 , further comprising notifying a user prior to carrying out the remedial action.

12. The method of claim 7 , wherein the remedial action includes at least one action selected from the group consisting of booting to a service operating system, parsing at least one of the files that are usable during boot and changing a setting therein, and updating the BIOS to restore a missing recovery file.

13. An article of manufacture comprising a non-transitory, computer-readable medium having computer-executable code thereon that is executable by a processor of an information handling system that includes a physical storage resource having a portion thereof that includes files that are usable during boot of the information handling system, at least one processor, and a Basic Input/Output System (BIOS), the code being executable for:

during a boot process of the information handling system and prior to beginning initialization of an operating system (OS), determining whether any of a plurality of BIOS events have taken place during a previous boot process, wherein the plurality of BIOS events are indicative of malicious behavior during the previous boot process, and wherein the plurality of BIOS events includes a Secure Boot configuration change event; and

in response to a determination that at least a predetermined number of the plurality of BIOS events have taken place during the previous boot process, carrying out a remedial action during the boot process and prior to initialization of the OS.

14. The article of claim 13 , wherein the BIOS is a Unified Extensible Firmware Interface (UEFI) BIOS.

15. The article of claim 14 , wherein the portion of the physical storage resource is an Extensible Firmware Interface (EFI) System Partition (ESP).

16. The article of claim 13 , wherein the plurality of BIOS events further includes at least one event selected from the group consisting of a boot deviation attempt, an increased boot time, a setting change relating to the physical storage resource, and an incomplete boot.

17. The article of claim 13 , wherein the code is further executable for notifying a user prior to carrying out the remedial action.

18. The article of claim 13 , wherein the remedial action includes at least one action selected from the group consisting of booting to a service operating system, parsing at least one of the files that are usable during boot and changing a setting therein, and updating the BIOS to restore a missing recovery file.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (058014/0560) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0473 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057931/0392) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0382 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057758/0286) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 061654/0064 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 058014/0560 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057758/0286 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057931/0392 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2021
From: SAYYED, IBRAHIM; HAMLIN, DANIEL L.
To: DELL PRODUCTS L.P.
Reel/Frame 056856/0420 →
Continuity (1)
Related Publication 20230019196A1 · Jan 19, 2023