×

Systems and methods for providing automatic system stop and boot-to-service OS for forensics analysis

  • US 10,102,073 B2
  • Filed: 05/20/2015
  • Issued: 10/16/2018
  • Est. Priority Date: 05/20/2015
  • Status: Active Grant
First Claim
Patent Images

1. An Information Handling System (IHS), comprising:

  • a processor; and

    a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution by the processor, cause the IHS to;

    detect an Indicator of Compromise (IoC);

    send, to a server, a message including the IoC;

    receive, from the server, a recovery instruction, wherein the server is configured to generate the recovery instruction based, at least in part, upon the IoC and upon a recovery success history of other IHSS, and wherein the recovery instruction includes a list of two or more service OSs; and

    attempt to boot at least one of the two or more service OSs in the listed order, wherein the at least one of the two or more service OSs is distinct from a main OS included in the IHS, and wherein at least one of;

    (a) the recovery instruction further includes an ordered list of two or more service OS sources, wherein the program instructions, upon execution by the processor, cause the IHS to attempt to boot the at least one of the two or more service OSs from at least one of the two or more service OS sources in the listed order;

    (b) the recovery instruction further includes an ordered list of two or more modes of operation of the at least one of the two or more service OSs, wherein the program instructions, upon execution by the processor, cause the IHS to attempt to boot the at least one of the two or more service OSs in at least one of the two or modes of operation in the listed order;

    or(c) the recovery instruction further includes a list of two or more recovery options, each recovery option having one of a plurality of service OSs, one of a plurality of service OS sources, and one of a plurality of modes of operation, wherein the program instructions, upon execution by the processor, cause the IHS to attempt to boot following at least one of the two or more recovery options in the listed order.

View all claims
  • 14 Assignments
Timeline View
Assignment View
    ×
    ×