eWeek Security Watch
Advertisement
Advertisement
March 20, 2008 6:11 PM

Microsoft's Komoku Buy Could Hit Patent Hiccup



grand_tribble I'm hearing some murmurs that Microsoft's acquisition of anti-rootkit startup Komoku could hit a patent hurdle.

My sources point to Patent #7,181,560, which was granted to Joe Grand (aka Kingpin from L0pht) and Brian Carrier of digital-evidence.org and covers a "Method and Apparatus for Preserving Computer Memory Using Expansion Card."

The concept covered in the patent has been used in Tribble, a hardware expansion card (See image) from Grand Idea Studio that can "reliably acquire the volatile memory of a live system to removable storage."

Not much is known about the actual technology and approach behind Komoku's hardware-based rootkit detection capabilities. When I profiled the company in 2006, the flagship CoPilot product was described to me as a PCI card capable of monitoring the host's memory and file system at the hardware level.

Grand Idea Studio has made it publicly known that it is looking for licensing opportunities for its patent and associated technology, and now that Komoku is owned by a deep-pocketed company, my sources say a legal/patent dispute could be brewing.

[ SEE: Government-Funded Startup Blasts Rootkits ]

I'm very curious about what Microsoft will do with the hardware component of this acquisition. Komoku's software, which is aimed at aimed at businesses looking for a low-assurance utility, is useful for Redmond's consumer security offering (Windows Live OneCare). But the real value of this deal is in the .gov/.mil market, where CoPilot (the PCI card) is already in use.

In many respects, hardware-based RAM acquisition is the most reliable and secure way to sniff out sophisticated malicious rootkits, but, then again, this discussion may be moot. Just ask Joanna.

Create, Communicate, Collaborate with IT Professionals at Ziff Davis Enterprise IT Link

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/13072

Post a Comment

 
 


RSS Syndication
Advertisement
Advertisement
Security Watch     Contact Us | Advertise | Site Map
Ziff Davis Enterprise

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
RSS Feeds | White Papers | ROI Calculators | Tech Podcasts | Tech Video |

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | eWeek Security | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | IT Marketplace | igrep

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2007 Ziff Davis Enterprise, Inc. All Rights Reserved. Security Watch is a trademark of Ziff Davis Enterprise, Inc. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.

Ziff Davis Enterprise