Dell has announced a new partnership with Cylance to add a new level of security to motherboards.
What does this mean? It means the addition of a new BIOS integrity verification mechanism that will be able to detect corrupted or tampered boot images when loading the operating system.
Dell seems to have realized the threat posed by bootkit malware, one of the most difficult security threats since even trained professionals have difficulty removing the malware.
Of course, rootkits have been around for many years, but last summer, after the Hacking Team systems were breached, security researchers realized how vast the hacking arsenal was in this particular malware.
Recently (last week) VirusTotal announced a firmware scanning feature. Today Dell also announced its own tool to combat this threat.
It's called Dell Data Protection | Endpoint Security Suite Enterprise, and it's a simple yet effective boot data scanning mechanism to protect users from bootkit malware.
The manufacturer's new tool will run after boot and send the already loaded post-boot image to a secure cloud server where it will compare it to a catalog of BIOS images issued by Dell labs.
What is unique about this tool is the fact that it will not require boot image signatures to validate their authenticity.
Cylance AI technology will allow the detection of infected images using a dynamic mathematical model.
The company's customers who want the new security feature will need to purchase a special license of Dell Data Protection | Endpoint Security Suite Enterprise.
