IP Library Granted Patent US 9,870,469
Granted Patent B2
US 9,870,469 · App. 14/497,789 · Granted Jan 16, 2018

Mitigation of stack corruption exploits

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,870,469
App. No.
14/497,789
Granted
Jan 16, 2018
Kind
B2
Abstract

In an example, a stack protection engine is disclosed for preventing or ameliorating stack corruption attacks. The stack protection engine may operate transparently to user-space processes. After a call to a subroutine from a parent routine, the stack protection engine encodes the return address on the stack, such as with an exclusive or cipher and a key selected from a key array. After the subroutine returns control to the main routine, the stack protection engine decodes the address, and returns control. If a stack corruption attack occurs, the malicious return address is not properly encoded, so that when decoding occurs, the program may simply crash rather than returning control to the malicious code.

Claims (32)

1. A computing device comprising:

a memory comprising a stack, the stack including a return address location; and

a stack protection engine, implemented at least partly on a hardware platform and comprising a key array, the stack protection engine operable for:

receiving a return address;

encoding at least a portion of the return address with a cipher with a key from the key array, comprising using a portion of the return address as an index to the key array; and

placing the return encoded address in the return address location of the stack.

2. The computing device of claim 1 , wherein the stack protection engine is operable for decoding the return address.

3. The computing device of claim 2 , wherein the stack protection engine is operable for encoding at least a portion of the return address with a cipher after a call to a subroutine by a parent routine, and is operable for decoding the return address after a return from the subroutine to the parent routine.

4. The computing device of claim 3 , wherein the stack protection engine is operable for assigning pseudo-random key values to the key array.

5. The computing device of claim 4 , wherein the stack protection engine is operable for refreshing the key array.

6. The computing device of claim 5 , wherein the stack protection engine is operable for refreshing the key array according to a periodic schedule.

7. The computing device of claim 3 , wherein the key array is write-only with respect to user-space processes.

8. The computing device of claim 1 , wherein the cipher is an exclusive or, and wherein encoding comprises selecting an encoding key from the key array.

9. The computing device of claim 8 , wherein the stack protection engine is operable for decoding the return address with an exclusive or cipher.

10. The computing device of claim 1 , wherein the stack protection engine operates invisibly to user-space processes.

11. The computing device of claim 1 , wherein the stack protection engine comprises logic encoded on a microprocessor.

12. Logic encoded on one or more tangible, non-transitory computer-readable mediums operable for providing a stack protection engine, implemented at least partly on a hardware platform and comprising a key array, wherein the stack protection engine is operable for:

receiving a return address;

encoding at least a portion of the return address with a cipher with a key from the key array, comprising using a portion of the return address as an index to the key array; and

placing the return encoded address in a return address location of a memory stack.

13. The logic of claim 12 , wherein the stack protection engine is operable for decoding the return address.

14. The logic of claim 13 , wherein the stack protection engine is operable for encoding at least a portion of the return address with a cipher after a call to a subroutine by a parent routine, and is operable for decoding the return address after a return from the subroutine to the parent routine.

15. The logic of claim 14 , wherein the stack protection engine is operable for assigning pseudo-random key values to the key array and for refreshing the key array.

16. The logic of claim 15 , wherein the stack protection engine is operable for refreshing the key array according to a periodic schedule.

17. The logic of claim 14 , wherein the key array is write-only with respect to user-space processes.

18. The logic of claim 12 , wherein the cipher is an exclusive or, and wherein encoding comprises selecting an encoding key from the key array.

19. The logic of claim 18 , wherein the stack protection engine is operable for decoding the return address with an exclusive or cipher.

20. A method for providing a stack protection engine, implemented at least partly on a hardware platform and comprising a key array, the stack protection engine operable for:

receiving a return address;

encoding at least a portion of the return address with a cipher with a key from the key array, comprising using a portion of the return address as an index to the key array after a call to a subroutine from a parent routine; and

placing the return encoded address in a return address location of a memory stack.

21. The method of claim 20 , further comprising decoding the return encoded address after a return from the subroutine to the parent routine.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2014
From: CROWE, SIMON
To: MCAFEE, INC.
Reel/Frame 033827/0432 →