发明名称 THREAT DETECTION FOR RETURN ORIENTED PROGRAMMING
摘要 Techniques for detecting security exploits associated with return-oriented programming are described herein. For example, a computing device may determine that a retrieved count is indicative of malicious activity, such as return oriented programming. The computing device may retrieve the count from a processor performance counter of prediction mismatches, the prediction mismatches resulting from comparisons of a call stack of the computing device and of a shadow call stack maintained by a processor of the computing device. In response to determining that the count indicates malicious activity, the computing device may perform at least one security response action.
申请公布号 EP2893486(A4) 申请公布日期 2016.03.02
申请号 EP20130835703 申请日期 2013.09.06
申请人 CROWDSTRIKE, INC. 发明人 WICHERSKI, GEORG
分类号 G06F21/50;G06F11/30;G06F21/52;G06F21/55 主分类号 G06F21/50
代理机构 代理人
主权项
地址