Systems and methods for providing automatic system stop and boot-to-service OS for forensics analysis
First Claim
Patent Images
1. An Information Handling System (IHS), comprising:
- a processor; and
a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution by the processor, cause the IHS to;
detect an Indicator of Compromise (IoC);
send, to a server, a message including the IoC;
receive, from the server, a recovery instruction, wherein the server is configured to generate the recovery instruction based, at least in part, upon the IoC and upon a recovery success history of other IHSS, and wherein the recovery instruction includes a list of two or more service OSs; and
attempt to boot at least one of the two or more service OSs in the listed order, wherein the at least one of the two or more service OSs is distinct from a main OS included in the IHS, and wherein at least one of;
(a) the recovery instruction further includes an ordered list of two or more service OS sources, wherein the program instructions, upon execution by the processor, cause the IHS to attempt to boot the at least one of the two or more service OSs from at least one of the two or more service OS sources in the listed order;
(b) the recovery instruction further includes an ordered list of two or more modes of operation of the at least one of the two or more service OSs, wherein the program instructions, upon execution by the processor, cause the IHS to attempt to boot the at least one of the two or more service OSs in at least one of the two or modes of operation in the listed order;
or(c) the recovery instruction further includes a list of two or more recovery options, each recovery option having one of a plurality of service OSs, one of a plurality of service OS sources, and one of a plurality of modes of operation, wherein the program instructions, upon execution by the processor, cause the IHS to attempt to boot following at least one of the two or more recovery options in the listed order.
14 Assignments
0 Petitions
Accused Products
Abstract
Systems and methods for providing automatic system stop and boot-to-service OS for forensic analysis. In some embodiments, an Information Handling System (IHS) includes a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution by the processor, cause the IHS to: detect an Indicator of Compromise (IoC); send, to a server, a message including the IoC; receive, from the server, a recovery instruction; and boot into a service OS identified in the recovery instruction, wherein the service OS is distinct from a main OS included in the IHS.
14 Citations
14 Claims
-
1. An Information Handling System (IHS), comprising:
-
a processor; and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution by the processor, cause the IHS to; detect an Indicator of Compromise (IoC); send, to a server, a message including the IoC; receive, from the server, a recovery instruction, wherein the server is configured to generate the recovery instruction based, at least in part, upon the IoC and upon a recovery success history of other IHSS, and wherein the recovery instruction includes a list of two or more service OSs; and attempt to boot at least one of the two or more service OSs in the listed order, wherein the at least one of the two or more service OSs is distinct from a main OS included in the IHS, and wherein at least one of; (a) the recovery instruction further includes an ordered list of two or more service OS sources, wherein the program instructions, upon execution by the processor, cause the IHS to attempt to boot the at least one of the two or more service OSs from at least one of the two or more service OS sources in the listed order; (b) the recovery instruction further includes an ordered list of two or more modes of operation of the at least one of the two or more service OSs, wherein the program instructions, upon execution by the processor, cause the IHS to attempt to boot the at least one of the two or more service OSs in at least one of the two or modes of operation in the listed order;
or(c) the recovery instruction further includes a list of two or more recovery options, each recovery option having one of a plurality of service OSs, one of a plurality of service OS sources, and one of a plurality of modes of operation, wherein the program instructions, upon execution by the processor, cause the IHS to attempt to boot following at least one of the two or more recovery options in the listed order. - View Dependent Claims (2, 3, 4, 5, 6)
-
-
7. A computer-implemented method, comprising:
-
receiving, from a client device, a message including an Indicator of Compromise (IoC); determining, based at least in part upon the IoC and upon a recovery history of other client devices, a list of two or more service OSs; and transmitting a recovery instruction to the client device, wherein the recovery instruction includes the list, wherein the client device is configured to boot into a service OS identified in the recovery instruction, and wherein the service OS is distinct from a main OS included in the client device. - View Dependent Claims (8, 9, 10)
-
-
11. A non-transitory memory device having program instructions stored thereon that, upon execution by an Information Handling System (IHS), cause the IHS to:
-
detect an Indicator of Compromise (IoC); send, to a server, a message including the IoC; receive, from the server, a recovery instruction; and boot into a service OS identified in the recovery instruction, wherein the recovery instruction includes an ordered list of two or more service OSs, and wherein the program instructions, upon execution by the processor, cause the IHS to attempt to boot at least one of the two or more service OSs in the listed order. - View Dependent Claims (12, 13, 14)
-
Specification