IP Library Granted Patent US 11,899,797
Granted Patent B2
US 11,899,797 · App. 16/347,596 · Granted Feb 13, 2024

System and method for detecting and for alerting of exploits in computerized systems

Inventors: Shlomi Levin (Ra'anana, IL); Michael Aminov (Tel-Aviv, IL)
Assignee: PERCEPTION POINT LTD
G06F21/577G06F21/44G06F21/52G06F21/552G06F21/56G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,899,797
App. No.
16/347,596
Granted
Feb 13, 2024
Kind
B2
Abstract

Systems and methods of detecting an exploit of a vulnerability of a computing device, including receiving an execution flow of at least one process running in a processor of the computing device, wherein the execution flow is received from a performance monitoring unit (PMU) of the processor, receiving memory pages from a memory of the computing device, reconstructing the execution flow of the process on another processor based on PMU data and the memory pages, running at least one exploit detection algorithm on the reconstructed process in order to identify an exploit attempt and issuing an alert.

Claims (27)

1. A method of detecting an exploit of a vulnerability of a computing device, the method comprising:

receiving an execution flow of at least one process running in a first physical processor of the computing device, wherein the execution flow is received from a performance monitoring unit (PMU) of the first physical processor;

receiving memory pages from a memory of the computing device;

continuously checking, by another physical processor which is physically separate from the first processor, the execution flow of the first processor, to identify a memory value that is mapped to stack memory by the another physical processor;

reconstructing the execution flow of the process on the another physical processor based on the execution flow received from the PMU and the memory pages;

running at least one exploit detection algorithm on the reconstructed execution flow of the process in order to identify an exploit attempt; and

issuing an alert.

2. The method of claim 1 , further comprising interrupting the process running on the first physical processor of the computing device when an exploit is detected.

3. The method of claim 1 , further comprising maintain map of addresses in memory of the first physical processor.

4. The method of claim 1 , further comprising mapping a structured exception handler (SEH) of the operating system of the first physical processor.

5. The method of claim 4 , further comprising adding a memory address of the SEH.

6. The method of claim 4 , further comprising checking if the structured exception handler (SEH) is registered.

7. The method of claim 1 , further comprising mapping at least one of memory allocation addresses and memory deallocation addresses.

8. The method of claim 7 , further comprising checking if at least one of memory allocation function and memory deallocation function is called.

9. The method of claim 7 , further comprising increasing at least one of allocation counter and deallocation counter.

10. The method of claim 7 , further comprising checking if difference of allocation counter and deallocation counter is greater than a predefined value.

11. The method of claim 1 , further comprising receiving at least one instruction.

12. The method of claim 1 , further comprising maintaining a shadow stack.

13. The method of claim 12 , further comprising checking if a call instruction in the execution flow has been executed.

14. The method of claim 12 , further comprising pushing expected return address to the shadow stack.

15. The method of claim 12 , further comprising checking if a return instruction has been executed.

16. The method of claim 12 , further comprising checking if target address is different from top address on shadow stack.

17. The method of claim 12 , further comprising popping an address from the stack.

18. The method of claim 1 , further comprising:

maintaining a database of legal addresses to transfer control indirectly to; and

receiving instructions for indirect branch from the reconstructed execution flow.

19. The method of claim 18 , further comprising checking if the received instruction corresponds to the database of legal addresses to transfer control indirectly to.

Assignments (2)
SECURITY INTEREST Recorded Mar 26, 2023
From: PERCEPTION POINT LTD
To: KREOS CAPITAL VII AGGREGATOR SCSP
Reel/Frame 063103/0450 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2019
From: LEVIN, SHLOMI; AMINOV, MICHAEL
To: PERCEPTION POINT LTD
Reel/Frame 049747/0209 →
Continuity (3)
Provisional Application 62516126 · Jun 7, 2017
Provisional Application 62418294 · Nov 7, 2016
Related Publication 20190258806A1 · Aug 22, 2019