发明名称 MEMORY ACCESS PROTECTION USING PROCESSOR TRANSACTIONAL MEMORY SUPPORT
摘要 Technologies for detecting unauthorized memory accesses include a computing device with a processor having transactional memory support. The computing device executes a security assistance thread that starts a transaction using the transactional memory support. Within the transaction, the security assistance thread writes arbitrary data to one or more monitored memory locations. The security assistance thread waits without committing the transaction. The security assistance thread may loop endlessly. The transactional memory support of the computing device detects a transactional abort caused by an external read of the monitored memory location. The computing device analyzes the transactional abort and determines whether a security event has occurred. The computing device performs a security response if a security event has occurred. The monitored memory locations may include memory-mapped operating system libraries, kernel data structures, executable images, or other memory structures that may be scanned by malicious software. Other embodiments are described and claimed.
申请公布号 WO2016109071(A1) 申请公布日期 2016.07.07
申请号 WO2015US62903 申请日期 2015.11.30
申请人 MCAFEE, INC. 发明人 DEMENTIEV, ROMAN;MUTTIK, IGOR;NAYSHTUT, ALEX
分类号 G06F12/14;G06F21/50 主分类号 G06F12/14
代理机构 代理人
主权项
地址