IL237385A

Threat detection for return oriented programming

Abstract

This record has no abstract on file.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

18 claims: 3 independent, 15 dependent

  1. 1
    20 237385/2 CLAIMS WHAT IS CLAIMED IS:1. A computer-implemented method comprising: retrieving a count of prediction mismatches from a processor performance counter, the prediction mismatches resulting from comparisons of a call stack of a computing device and of a shadow call stack maintained by a processor of the computing device, wherein the shadow call stack is used for branch predictions that attempt to predict a state of the call stack;determining whether the count of prediction mismatches indicates malicious activity by determining whether the count of prediction mismatches exceeds a threshold or diverges from a pattern;and in response to determining that the count of prediction mismatches indicates malicious activity, performing at least one security response action.
  2. 11
    One or more non-transitory computer-readable media storing computer-executable instructions configured to program first one or more computing devices to perform operations comprising:retrieving a count of prediction mismatches from a processor performance counter, the prediction mismatches resulting from comparisons of a call stack of a second computing device and of a shadow call stack maintained by a processor of the second computing device, wherein the shadow call stack is used for branch predictions that attempt to predict a state of the call stack;determining whether the count of prediction mismatches indicates malicious activity by determining whether the count of prediction mismatches exceeds a threshold or diverges from a pattern;and in response to determining that the count of prediction mismatches indicates malicious activity, performing at least one security response action. 22 237385/2
  3. 17
    A computing device comprising:a processor, including cache memory of the processor, a processor performance counter, and a shadow call stack stored in the cache memory;a call stack communicatively coupled to the processor, wherein the shadow call stack is used for branch predictions that attempt to predict a state of the call stack;a detection module configured to be operated by the processor to: set a threshold or pattern based at least in part on monitoring, over a period of time, a count of prediction mismatches from the processor performance counter, the prediction mismatches resulting from comparisons of the call stack and of the shadow call stack;23 237385/2 retrieve the count of prediction mismatches from the processor performance counter, and determine whether the count of prediction mismatches indicates malicious activity by determining whether the count of prediction mismatches exceeds the threshold or diverges from the pattern;and a response module configured to be operated by the processor to perform, in response to determining that the count of prediction mismatches indicates malicious activity, invoking at least one of: an alert module of the computing device to provide a graphic, audible, or haptic alert to a user of the computing device, a report module of the computing device to notify a remote security monitoring server of the malicious activity, a remediation module of the computing device to halt execution of one or more processes, or an analysis module of the computing device to determine information associated with the one or more processes and analyze the determined information.