IP Library Granted Patent US 10,114,948
Granted Patent B2
US 10,114,948 · App. 14/129,558 · Granted Oct 30, 2018

Hypervisor-based buffer overflow detection and prevention

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,114,948
App. No.
14/129,558
Granted
Oct 30, 2018
Kind
B2
Abstract

Technologies for securing an electronic device include determining addresses of one or more memory pages, injecting for each memory page a portion of identifier data into the memory page, storing an indication of the identifier data injected into each of the memory pages, determining an attempt to access at least one of the memory pages, determining any of the identifier data present on a memory page associated with the attempt, comparing the indication of the identifier data with the determined identifier data present on the memory page, and, based on the comparison, determining whether to allow the access.

Claims (38)

1. A method for securing an electronic device, comprising:

determining a memory page to be monitored;

determining portions of the memory page allocated for content for applications;

marking all remaining portions of the memory page as unallocated for content for applications and unwriteable other than by authorized functions of an operating system;

determining, at a level below the operating system, an attempt from the level of the operating system, the attempt to access unallocated portions of the memory page marked as unwriteable other than by authorized functions of the operating system;

determining whether the attempt originated from an authorized function of the operating system; and

in response to a determination that the attempt did not originate from an authorized function of the operating system, blocking the attempt,

wherein the remaining portions of the memory page include a size indicator of an allocation, the size indicator having been written to an unallocated portion of the memory page by an authorized function of the operating system,

wherein determining whether the attempt originated from an authorized function of the operating system includes determining whether the attempt originated from a deallocation function of the operating system,

wherein the portions of the memory page marked as unallocated for content for applications and unwriteable other than by authorized functions of the operating system include one or more portions of the memory between memory allocations.

2. The method of claim 1 , wherein the remaining portions of the memory page include unused memory spaces.

3. The method of claim 1 , wherein determining whether the attempt originated from an authorized function of the operating system includes determining whether the attempt originated from an allocation function of the operating system.

4. At least one non-transitory machine readable storage medium, comprising computer-executable instructions carried on the machine readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to:

determine a memory page to be monitored;

determine portions of the memory page allocated for content for applications;

mark all remaining portions of the memory page as unallocated for content for applications and unwriteable other than by authorized functions of an operating system;

determine, at a level below the operating system, an attempt from the level of the operating system, the attempt to access unallocated portions of the memory page marked as unwriteable other than by authorized functions of the operating system;

determine whether the attempt originated from an authorized function of the operating system; and

in response to a determination that the attempt did not originate from an authorized function of the operating system, block the attempt,

wherein the remaining portions of the memory page include a size indicator of an allocation, the size indicator having been written to an unallocated portion of the memory page by an authorized function of the operating system,

wherein determining whether the attempt originated from an authorized function of the operating system includes determining whether the attempt originated from a deallocation function of the operating system,

wherein the portions of the memory page marked as unallocated for content for applications and unwriteable other than by authorized functions of the operating system include one or more portions of the memory between memory allocations.

5. The medium of claim 4 , wherein the remaining portions of the memory page include unused memory spaces.

6. The medium of claim 4 , wherein determining whether the attempt originated from an authorized function of the operating system includes determining whether the attempt originated from an allocation function of the operating system.

7. A system for securing an electronic device, comprising:

a processor;

at least one non-transitory machine readable storage medium communicatively coupled to the processor and comprising computer-executable instructions carried on the machine readable medium, the instructions readable by the processor, the instructions, when read and executed, for causing the processor to:

determine a memory page to be monitored;

determine portions of the memory page allocated for content for applications;

mark all remaining portions of the memory page as unallocated for content for applications and unwriteable other than by authorized functions of an operating system;

determine, at a level below the operating system, an attempt from the level of the operating system, the attempt to write to unallocated portions of the memory page marked as unwriteable other than by authorized functions of the operating system;

determine whether the attempt originated from an authorized function of the operating system; and

in response to a determination that the attempt did not originate from an authorized function of the operating system, block the attempt,

wherein the remaining portions of the memory page include a size indicator of an allocation, the size indicator having been written to an unallocated portion of the memory page by an authorized function of the operating system,

wherein determining whether the attempt originated from an authorized function of the operating system includes determining whether the attempt originated from a deallocation function of the operating system,

wherein the portions of the memory page marked as unallocated for content for applications and unwriteable other than by authorized functions of the operating system include one or more portions of the memory between memory allocations.

8. The system of claim 7 , wherein the remaining portions of the memory page include unused memory spaces.

9. The system of claim 7 , wherein determining whether the attempt originated from an authorized function of the operating system includes determining whether the attempt originated from an allocation function of the operating system.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Sep 15, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043969/0057 →