Existing performance monitoring and last branch recording processor hardware may be configured and used for detection of return-oriented and jump-oriented programming exploits with less performance impact that software-only techniques. Upon generation of a performance monitoring interrupt indicating that a predetermined number of mispredicted branches have occurred, the control flow and code may be analyzed to detect a return-oriented or jump- oriented exploit.
申请公布号
WO2017053648(A1)
申请公布日期
2017.03.30
申请号
WO2016US53229
申请日期
2016.09.23
申请人
MCAFEE, INC.
发明人
SUKHOMLINOV, Vadim;BAZHANIUK, Oleksandr;BULYGIN, Yuriy;NAYSHTUT, Alex;FURTAK, Andrew, A.;MUTTIK, Igor