Original URL: http://www.reghardware.co.uk/2005/12/09/intel_anti-rootkit_chip/
Intel has begun developing rootkit-detection technology with a view to preventing malicious code from modifying the host system's memory.
According to an IT Observer report (http://www.it-observer.com/articles.php?id=977), the system will monitor the OS and other software that could be covertly modified by a rootkit to hide its presence and any security holes it has created. The monitor is implemented in hardware and checks for unnecessary changes made to memory containing system and application code.
Non-running rootkit code will continue to be the responsibility of anti-virus software, Intel said, with the hardware system present to prevent the activated code from damaging the host.
According to the report, Intel's researchers hope to implement the technology in commercially available silicon in the 2008-2009 timeframe. By then Intel should have shipped its 'LaGrande' security system, which is geared to encrypting information held in keyboard and graphics buffers, and to isolating blocks of memory to prevent processes snooping on each other.
As it stands, LaGrande is about protected data and code from outside threats - it's less able to deal with malicious code operating from within the sealed environment. It may be able to tell the user his or her system has been compromised, but not necessarily prevent the attack in the first place.
This is where the new technology, which will presumably be part of LaGrande 2, comes in.
"We need to connect the computers directly to the data, so the human beings don't have to be the I/O channel, and elevate the role of the human being to a more supervisory role," said Intel's director of research, David Tennenhouse.
LaGrande uses a Trusted Platform Modile (TPM) chip connected to the chipset. ®
Intel and Symantec team up on 'bare metal' security (15 August 2007)
http://www.theregister.co.uk/2007/08/15/virtual_security_intel_symantec/
Trusted Computing readies anti-malware specs (17 November 2006)
http://www.theregister.co.uk/2006/11/17/tcg_software_specs/
VXers add rootkit tech to MyDoom and Bagle (30 March 2006)
http://www.theregister.co.uk/2006/03/30/mainstream_rootkit/
Virtual rootkits create stealth risk (13 March 2006)
http://www.theregister.co.uk/2006/03/13/virtual_rootkit/
Hackers download pirate movies onto compromised PCs (21 December 2005)
http://www.channelregister.co.uk/2005/12/21/bittorrent_botnet_attack/
Nvidia nabs ULi (14 December 2005)
http://www.reghardware.co.uk/2005/12/14/nvidia_buys_uli/
Intel to sell $1.4bn debt (13 December 2005)
http://www.theregister.co.uk/2005/12/13/intel_convertible_debt_sale/
SonyBMG backtracks on buggy bug fix (9 December 2005)
http://www.theregister.co.uk/2005/12/09/sony_mediamax_problems/
Sony opens up over another CD security hole (7 December 2005)
http://www.theregister.co.uk/2005/12/07/sony_cd_security/
Sony's DRM woes worsen (30 November 2005)
http://www.theregister.co.uk/2005/11/30/sony_drm_spitzer/
Gaffer tape defeats Sony DRM rootkit (21 November 2005)
http://www.theregister.co.uk/2005/11/21/gaffer_tape_trips_up_sony_drm/
Sony's CD rootkit infringes DVD Jon's copyright (18 November 2005)
http://www.theregister.co.uk/2005/11/18/sony_copyright_infringement/
Sony DRM uninstaller 'worse than rootkit' (17 November 2005)
http://www.theregister.co.uk/2005/11/17/sony_drm_uninstaller_peril/
Sony pulls rootkit DRM CDs (16 November 2005)
http://www.theregister.co.uk/2005/11/16/sony_withdraws_xcp_cds/
Sony suspends rootkit DRM (12 November 2005)
http://www.theregister.co.uk/2005/11/12/sony_suspends_rootkit_drm/
Mac anti-rip code surfaces on Sony BMG CD (11 November 2005)
http://www.theregister.co.uk/2005/11/11/sony_bmg_mac_drm/
Sony hit by lawsuits over root kit (10 November 2005)
http://www.theregister.co.uk/2005/11/10/sony_sued_for_rootkit/
Removing Sony's CD 'rootkit' kills Windows (1 November 2005)
http://www.theregister.co.uk/2005/11/01/sony_rootkit_drm/