发明名称 DETECTION OF UNAUTHORIZED MEMORY MODIFICATION AND ACCESS USING TRANSACTIONAL MEMORY
摘要 Technologies for detecting unauthorized memory accesses include a computing device having transactional memory support. The computing device executes a code segment identified as suspicious and detects a transactional abort during execution of the code segment. The computing device may execute a security support thread concurrently with the code segment that reads one or more monitored memory locations. A transactional abort may be caused by a read of the security support thread conflicting with a write from the code segment. The computing device may set a breakpoint within the code segment, and a transactional abort may be caused by execution of the code segment reaching the breakpoint. An abort handler determines whether a security event has occurred and reports the security event. The abort handler may determine whether the security event has occurred based on the cause of the transactional abort. Other embodiments are described and claimed.
申请公布号 EP3084615(A1) 申请公布日期 2016.10.26
申请号 EP20130899925 申请日期 2013.12.17
申请人 INTEL CORPORATION 发明人 MUTTIK, IGOR;DEMENTIEV, ROMAN;NAYSHTUT, ALEX
分类号 G06F12/14;G06F21/00 主分类号 G06F12/14
代理机构 代理人
主权项
地址