IP Library Granted Patent US 10,025,930
Granted Patent B2
US 10,025,930 · App. 14/998,155 · Granted Jul 17, 2018

Hardware assisted branch transfer self-check mechanism

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,025,930
App. No.
14/998,155
Granted
Jul 17, 2018
Kind
B2
Abstract

Embodiments of the present disclosure are directed to a self-check application to determine whether an indirect branch execution is permissible for an executable application. The self-check application uses one or more parameters received from an execution profiling module to determine whether the indirect branch execution is permitted by one or more self-check policies.

Claims (35)

1. A computer program product tangibly embodied on non-transient computer readable media, the computer program product comprising instructions operable when executed to:

receive, from an execution profiler implemented at least partially in hardware, execution control of an indirect branch for a function call in an executable application;

execute a callback to a self-check policy associated with the executable application for the indirect branch, wherein the self-check policy comprises at least one of a defense to a control-flow attack and a white list of authorized memory address locations for the indirect branch; and

determine, by a self-check application module implemented at least partially in hardware, whether to execute the indirect branch based on the self-check policy associated with the executable application, by:

evaluating one or more parameters for the indirect branch provided to the self-check application module by the execution profiler; and

determining whether the one or more parameters are permitted for execution based on the self-check policy;

wherein:

the parameters comprise one or both of a source register location from which the indirect call originated or a destination register location for the indirect branch call; and

the self-check application module determines whether the self-check policy permits an indirect branch from the source register to the destination register.

2. The computer program product of claim 1 , wherein the indirect branch comprises one of a near indirect call, a near indirect jump, or a near return.

3. A system comprising:

a processor implemented at least partially in hardware;

a memory;

an execution profiler module implemented at least partially in hardware to:

receive, from an execution profiler implemented at least partially in hardware, execution control of an indirect branch for a function call in an executable application; and

determine, by a self-check handler module, whether to execute the indirect branch based on a self-check policy associated with the executable application, wherein the self-check police comprises at least one of a defense to a control-flow attack and a white list of authorized memory address locations for the indirect branch, by:

evaluating one or more parameters for the indirect branch provided to a self-check handler by the execution profiler; and

determining whether the one or more parameters are permitted for execution based on the self-check policy;

wherein:

the parameters comprise one or both of a source register location from which the indirect call originated or a destination register location for the indirect call; and

the self-check handler module determines whether the self-check policies permits an indirect branch from the source register to the destination register.

4. The system of claim 3 , wherein the indirect branch comprises one of a near indirect call, a near indirect jump, or a near return.

5. A system for control flow protection, the system comprising:

a processor implemented at least partially in hardware;

a memory;

an execution profiler module implemented at least partially in hardware to:

assemble an execution profile of a executable application execution;

monitor the executable application execution for an indirect branch instruction; and

identify one or more parameters associated with the indirect branch instruction; and

a self-check application module implemented at least partially in hardware to determine whether the indirect branch is permitted by performing a self-check using the parameters identified by the execution profiler module, by:

evaluating one or more parameters for the indirect branch provided to a self-check handler by the execution profiler; and

determining whether the one or more parameters are permitted for execution based on a self-check policy, wherein the self-check policy comprises at least one of a defense to a control-flow attack and a white list of authorized memory address locations for the indirect branch;

wherein:

the parameters comprise one or both of a source register location from which the indirect call originated or a destination register location for the indirect call; and

the self-check application module determines whether the self-check policies permits an indirect branch from the source register to the destination register.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2016
From: SAHITA, RAVI; LI, XIAONING; LU, LIXIN
To: MCAFEE, INC.
Reel/Frame 038455/0860 →