IP Library Granted Patent US 12,596,808
Granted Patent B1
US 12,596,808 · App. 18/886,124 · Granted Apr 7, 2026

System and method to detect boot kit attacks

Inventors: Nagasubramanya Lakshminarayana (Concord, NC); Vijay Yarabolu (Hyderabad, IN)
Assignee: Bank of America Corporation
G06F21/575G06F21/53G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,596,808
App. No.
18/886,124
Granted
Apr 7, 2026
Kind
B1
Abstract

A system and method for detecting boot kit attacks that includes a memory configured to store previous hash values associated with a good boot sequence and a processor operably coupled to the memory. The processor is configured to receive from an external device current boot data associated with a current boot procedure of the external device. The current boot data includes at least an amount of network data sent and received by the external device. Once the processor receives the current boot data, the processor then performs a hash function on the current boot data to produce a current hash value. The processor then compares the current hash value with the previous hash value stored in the memory and sends to the external device a notification to use a previous boot procedure when the current hash value is different than the previous hash value.

Claims (58)

1 . A system, comprising:

a memory configured to store a previous hash value for a first external device wherein the previous hash value was produced using data associated with a previous boot procedure of the first external device that has been identified as not being corrupted; and

a processor operably coupled to the memory and configured to:

receive, current boot data associated with a current boot procedure of the first external device, wherein the first external device is connected to an external network, and the current boot data includes at least an amount of network data sent and received by the first external device over the external network during the current boot procedure and an amount of time that each step of the current boot procedure takes to be performed;

perform a hash function on the current boot data to produce a current hash value;

compare the current hash value with the previous hash value; and

send to the first external device a first instruction to use a previous boot procedure when the current hash value is different than the previous hash value.

2 . The system of claim 1 , wherein the processor is further configured to:

receive a new boot procedure from a second external device;

perform the hash function on data associated with the new boot procedure to produce an updated hash value; and

replace the previous hash value with the updated hash value.

3 . The system of claim 2 , wherein the previous hash value is stored in a blockchain and replacing the previous hash value comprises producing a new block on the blockchain that stores the updated hash value as the previous hash value.

4 . The system of claim 1 , wherein the processor is further configured to:

receive from the first external device, new boot data associated with the previous boot procedure;

perform a hash function on the new boot data to produce a new hash value;

compare the new hash value with the previous hash value;

send a second instruction to the first external device to perform at least one quarantine action; and

send an alert to a security organization associated with the first external device.

5 . The system of claim 4 , wherein at least one quarantine action comprises disconnecting the first external device from the external network.

6 . The system of claim 1 , wherein the current boot data further comprises data associated with a physical characteristic of the first external device when it performs the current boot procedure.

7 . The system of claim 1 , wherein the current boot data further comprises a total amount of time that the current boot procedure takes to be performed.

8 . A method comprising:

receiving, current boot data associated with a current boot procedure of a first external device, wherein the first external device is connected to an external network, and the current boot data includes at least an amount of network data sent and received by the first external device over the external network during the current boot procedure and an amount of time that each step of the current boot procedure takes to be performed;

performing a hash function on the current boot data to produce a current hash value;

comparing the current hash value with a previous hash value that was produced using data associated with a previous boot procedure of the first external device that has been identified as not being corrupted; and

sending to the first external device a first instruction to use a previous boot procedure when the current hash value is different than the previous hash value.

9 . The method of claim 8 , further comprising:

receiving a new boot procedure from a second external device;

performing the hash function on data associated with the new boot procedure to produce an updated hash value; and

replacing the previous hash value with the updated hash value.

10 . The method of claim 9 , wherein the previous hash value is stored in a blockchain and replacing the previous hash value comprises of producing a new block on the blockchain that stores the updated hash value as the previous hash value.

11 . The method of claim 8 , further comprising:

receiving from the first external device new boot data associated with the previous boot procedure;

performing a hash function on the new boot data to produce a new hash value;

comparing the new hash value with the previous hash value;

sending a second instruction to the first external device to perform at least one quarantine action; and

sending an alert to a security organization associated with the first external device.

12 . The method of claim 11 , wherein at least one quarantine action comprises disconnecting the first external device from the external network.

13 . The method of claim 8 , wherein the current boot data further comprises data associated with a physical characteristic of the first external device when it performs the current boot procedure.

14 . The method of claim 8 , wherein the current boot data further comprises a total amount of time that the current boot procedure takes to be performed.

15 . A non-transitory computer-readable medium storing instructions that, when executed by a processor, cause the processor to:

receive, current boot data associated with a current boot procedure of a first external device, wherein the first external device is connected to an external network, and the current boot data includes at least an amount of network data sent and received by the first external device over the external network during the current boot procedure and an amount of time that each step of the current boot procedure takes to be performed;

perform a hash function on the current boot data to produce a current hash value;

compare the current hash value with a previous hash value that was produced using data associated with a previous boot procedure of the first external device that has been identified as not being corrupted; and

send to the first external device a first instruction to use a previous boot procedure when the current hash value is different than the previous hash value.

16 . The non-transitory computer-readable medium of claim 15 , wherein the instructions further cause the processor to:

receive a new boot procedure from a second external device;

perform the hash function on data associated with the new boot procedure to produce an updated hash value; and

replace the previous hash value with the updated hash value.

17 . The non-transitory computer-readable medium of claim 16 , wherein the previous hash value is stored in a blockchain and replacing the previous hash value comprises of producing a new block on the blockchain that stores the updated hash value as the previous hash value.

18 . The non-transitory computer-readable medium of claim 15 , wherein the instructions further cause the processor to:

receive from the first external device, new boot data associated with the previous boot procedure;

perform a hash function on the new boot data to produce a new hash value;

compare the new hash value with the previous hash value;

send a second instruction to the first external device to perform at least one quarantine action; and

send an alert to a security organization associated with the first external device.

19 . The non-transitory computer-readable medium of claim 18 , wherein at least one quarantine action comprises disconnecting the first external device from the external network.

20 . The non-transitory computer-readable medium of claim 15 , wherein the current boot data further comprises data associated with a physical characteristic of the first external device when it performs the current boot procedure.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2024
From: LAKSHMINARAYANA, NAGASUBRAMANYA; YARABOLU, VIJAY
To: BANK OF AMERICA CORPORATION
Reel/Frame 068596/0351 →
References Cited (21)
US 8365297B1 · Parshin et al. · 2013 [cited by applicant]
US 9230112B1 · Peterson · 2016 [cited by examiner]
US 9251343B1 · Vincent · 2016 [cited by examiner]
US 11537716B1 · Choudhary · 2022 [cited by examiner]
US 20150212747A1 · Hutchison et al. · 2015 [cited by applicant]
US 20160357963A1 · Sherman · 2016 [cited by applicant]
US 20160359636A1 · Kreft · 2016 [cited by applicant]
US 20170213030A1 · Mooring et al. · 2017 [cited by applicant]
US 20170357808A1 · Arroyo · 2017 [cited by applicant]
US 20180004953A1 · Smith, II et al. · 2018 [cited by applicant]
US 20190163909A1 · Schilder et al. · 2019 [cited by applicant]
US 20190363894A1 · Kumar Ujjwal · 2019 [cited by applicant]
US 20200174949A1 · Ramasamy et al. · 2020 [cited by applicant]
US 20200302061A1 · Rizos · 2020 [cited by examiner]
US 20200342112A1 · Plusquellic · 2020 [cited by applicant]
US 20210312052A1 · Kloth · 2021 [cited by applicant]
US 20220100849A1 · Vandergeest · 2022 [cited by applicant]
EP 3259698B1 · 2020 [cited by examiner]
“There's a Hole in the Boot;” by: Eclypsium; dtd Jul. 29, 2020; https://eclypsium.com/blog/theres-a-hole-in-the-boot/. [cited by applicant]
“What is Bootkit;” ReasonLabs; https://cyberpedia.reasonlabs.com/EN/bootkit.html; copyright 2023; printed Sep. 10, 2024. [cited by applicant]
“What is Bootkit;” ReasonLabs; https://cyberpedia.reasonlabs.com/EN/bootkit.html#:˜:text=Bootkits%20are%20especially%20dangerous%20because,challenging%20to%20locate%20and%20eradicate; copyright 2023; printed Sep. 10, 20… [cited by applicant]