IP Library › Granted Patent US 12,417,106
Granted Patent B2
US 12,417,106 · App. 17/245,511 · Granted Sep 16, 2025

Control flow integrity enforcement at scale

Inventors: Richard John Black (Cambridge, GB); Timothy William Burrell (Cheltenham, GB); Miguel Oom Temudo de Castro (Cambridge, GB); Manuel Silverio da Silva Costa (Cambridge, GB); Kenneth Johnson (Bellevue, WA); Matthew Ryan Miller (Seattle, WA)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
G06F9/44589G06F8/433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,417,106
App. No.
17/245,511
Granted
Sep 16, 2025
Kind
B2
Abstract

Various technologies described herein pertain to enforcing control flow integrity by adding instrumentation when source code is compiled or binary code is rewritten. An indirect call to a control transfer target (e.g., in the source code, in the binary code, etc.) can be identified. Moreover, the instrumentation can be inserted prior to the indirect call. The instrumentation can use a bit from a bitmap maintained by a runtime to verify whether the control transfer target is valid. When an executable image that includes the inserted instrumentation runs, execution can be terminated and/or other appropriate actions can be taken when the control transfer target is determined to be invalid; alternatively, execution can continue when the control transfer target is determined to be valid.

Claims (45)

1. A method of running an executable image, the method executed by a processor and comprising:

loading the executable image;

initializing a portion of a bitmap managed by a runtime, wherein the portion of the bitmap is initialized based on metadata embedded in the executable image;

determining validity of a control transfer target of an indirect call in the executable image based on whether a corresponding bit in the bitmap is set, wherein the validity of the control transfer target is determined by detecting corruption of a return address from the control transfer target on a stack by verifying a function signature of the control transfer target being called by the indirect call responsive to the corresponding bit in the bitmap being set, wherein the bitmap comprises two bits per aligned address, and wherein a state of one of the two bits indicates that the corresponding aligned address has the function signature to be checked;

terminating execution of the executable image when the control transfer target is determined to be invalid; and

continuing the execution of the executable image when the control transfer target is determined to be valid.

2. The method of claim 1 , wherein the bitmap is shared for determining validity of a disparate control transfer target of a disparate executable image.

3. The method of claim 1 , further comprising:

creating a pagefile-backed section to be used for the bitmap during operating system initialization;

mapping a reserved, read-only view of the pagefile-backed section into address space of a process during creation of the process;

determining whether the executable image is loaded at a chosen base address;

setting a bit associated with the executable image in the bitmap based on the metadata embedded in the executable image when the executable image is loaded at the chosen base address; and

creating a private page in the bitmap when the executable image is loaded at a disparate base address that differs from the chosen base address, wherein the private page in the bitmap corresponds to the disparate base address.

4. The method of claim 1 , wherein the validity of the control transfer target is determined by instrumentation included in the executable image.

5. The method of claim 4 , wherein the instrumentation included in the executable image is a call to an external check routine, and wherein the external check routine determines whether the bit from the bitmap is set for the control transfer target.

6. The method of claim 4 , wherein the instrumentation included in the executable image is an inline bitmap check that directly determines whether the bit from the bitmap is set for the control transfer target.

7. The method of claim 1 , further comprising detecting the corruption of the return address from the control transfer target on the stack using a check inserted in the executable image.

8. The method of claim 7 , further comprising detecting the corruption of the return address on the stack using a security cookie for a function that calls the control transfer target, wherein a value of the security cookie is computed based on an intended return address of the function.

9. The method of claim 1 , wherein the function signature is verified using a versioned function signature that is represented by a data structure that includes one or more possible function signatures for a function being called by the indirect call in an array, and wherein the possible function signatures correspond to values computed using different versions of a function signature computation algorithm.

10. The method of claim 1 , wherein a bit in the bitmap identifies a range of addresses for indirect control transfer, and wherein a code pattern of a function provides that only a first byte in the function is possibly called.

11. A system that executes an executable image, comprising:

at least one processor; and

memory that comprises computer-executable instructions that, when executed by the at least one processor, cause the at least one processor to perform acts including:

loading the executable image;

initializing a portion of a bitmap managed by a runtime, wherein the portion of the bitmap is initialized based on metadata embedded in the executable image;

determining validity of a control transfer target of an indirect call in the executable image based on whether a corresponding bit in the bitmap is set, wherein the validity of the control transfer target is determined by detecting corruption of a return address from the control transfer target on a stack by verifying a function signature of the control transfer target being called by the indirect call responsive to the corresponding bit in the bitmap being set, wherein the bitmap comprises two bits per aligned address, and wherein a state of one of the two bits indicates that the corresponding aligned address has the function signature to be checked;

terminating execution of the executable image when the control transfer target is determined to be invalid; and

continuing the execution of the executable image when the control transfer target is determined to be valid.

12. The system of claim 11 , wherein the bitmap is shared for determining validity of a disparate control transfer target of a disparate executable image.

13. The system of claim 11 , wherein the validity of the control transfer target is determined by instrumentation included in the executable image.

14. The system of claim 11 , the memory further comprising computer-executable instructions that, when executed by the at least one processor, cause the at least one processor to perform acts including:

detecting the corruption of the return address from the control transfer target on the stack using a check inserted in the executable image.

15. The system of claim 11 , wherein a bit in the bitmap identifies a range of addresses for indirect control transfer, and wherein a code pattern of a function provides that only a first byte in the function is possibly called.

16. The system of claim 11 , wherein loading the executable image comprises:

checking whether a base address has been chosen for the executable image; and

setting a corresponding bit in the bitmap pertaining to the base address when the base address has been chosen.

17. The system of claim 11 , wherein the function signature is verified using a versioned function signature that is represented by a data structure that includes one or more possible function signatures for a function being called by the indirect call in an array, and wherein the possible function signatures correspond to values computed using different versions of a function signature computation algorithm.

18. A computer-readable storage medium including computer-executable instructions that, when executed by a processor, cause the processor to perform acts including:

loading an executable image;

initializing a portion of a bitmap managed by a runtime, wherein the portion of the bitmap is initialized based on metadata embedded in the executable image;

determining validity of a control transfer target of an indirect call in the executable image based on whether a corresponding bit in the bitmap is set, wherein the validity of the control transfer target is determined by detecting corruption of a return address from the control transfer target on a stack by verifying a function signature of the control transfer target being called by the indirect call responsive to the corresponding bit in the bitmap being set, wherein the bitmap comprises two bits per aligned address, and wherein a state of one of the two bits indicates that the corresponding aligned address has the function signature to be checked;

terminating execution of the executable image when the control transfer target is determined to be invalid; and

continuing the execution of the executable image when the control transfer target is determined to be valid.

19. The computer-readable storage medium of claim 18 , wherein the bitmap is shared for determining validity of a disparate control transfer target of a disparate executable image.

20. The computer-readable storage medium of claim 18 , wherein the validity of the control transfer target is determined by instrumentation included in the executable image.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2021
From: BLACK, RICHARD JOHN; BURRELL, TIMOTHY WILLIAM; DE CASTRO, MIGUEL OOM TEMUDO; COSTA, MANUEL SILVERIO DA SILVA; JOHNSON, KENNETH; MILLER, MATTHEW RYAN
To: MICROSOFT CORPORATION
Reel/Frame 056791/0189 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2021
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 056791/0240 →
Continuity (2)
Continuation 13450487 · Apr 19, 2012
Related Publication 20210326153A1 · Oct 21, 2021
References Cited (62)
US 6026234A · Hanson et al. · 2000 [cited by applicant]
US 6026239A · Patrick et al. · 2000 [cited by applicant]
US 6052797A · Ofek · 2000 [cited by examiner]
US 7337291B2 · Abadi et al. · 2008 [cited by applicant]
US 7577992B2 · Abadi et al. · 2009 [cited by applicant]
US 8161453B2 · Chrabieh · 2012 [cited by applicant]
US 8434073B1 · Satish et al. · 2013 [cited by applicant]
US 8600943B1 · Fitzgerald et al. · 2013 [cited by applicant]
US 8812819B1 · Langhammer · 2014 [cited by examiner]
US 8949777B2 · Ni · 2015 [cited by examiner]
US 11003464B2 · Black et al. · 2021 [cited by applicant]
US 20020032718A1 · Yates · 2002 [cited by examiner]
US 20020199073A1 · Tamura · 2002 [cited by examiner]
US 20050055360A1 · Chang · 2005 [cited by examiner]
US 20070006170A1 · Hasse · 2007 [cited by examiner]
US 20080172624A1 · Matsutsuka · 2008 [cited by examiner]
US 20090019221A1 · Kessler · 2009 [cited by examiner]
US 20090052804A1 · Lewis · 2009 [cited by applicant]
US 20090171652A1 · Ishii et al. · 2009 [cited by applicant]
US 20090249289A1 · Akritidis · 2009 [cited by examiner]
US 20090282393A1 · Costa et al. · 2009 [cited by applicant]
US 20090327607A1 · Tetrick et al. · 2009 [cited by applicant]
US 20100107149A1 · Hsu · 2010 [cited by examiner]
US 20100107249A1 · Krig · 2010 [cited by examiner]
US 20110138476A1 · Black et al. · 2011 [cited by applicant]
US 20110208694A1 · Bitar et al. · 2011 [cited by applicant]
US 20110231824A1 · Chabbi et al. · 2011 [cited by applicant]
US 20120030412A1 · Dhakshinamurthy et al. · 2012 [cited by applicant]
US 20120047342A1 · Grusy · 2012 [cited by examiner]
US 20120185863A1 · Krstic · 2012 [cited by examiner]
US 20120222014A1 · Peretz · 2012 [cited by examiner]
US 20130145076A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130242935A1 · Lim · 2013 [cited by examiner]
US 20130283245A1 · Black et al. · 2013 [cited by applicant]
US 20130318511A1 · Tian · 2013 [cited by examiner]
Mao, et al., “Software fault isolation with API integrity and multi-principal modules”, Retrieved at <<http://people.csail.mit.edu/nickolai/papers/mao-lxfi.pdf>>, Proceedings of SOSP, Oct. 23, 2011, pp. 1-14. [cited by applicant]
Chang, et al., “Efficient and Extensible Security Enforcement Using Dynamic Data Flow Analysis”, Retrieved at <<http://www.cs.utexas.edu/users/lin/papers/ccs08.pdf>>, Proceedings of CCS, Oct. 27, 2008, pp. 1-12. [cited by applicant]
Abadi, et al., “Control-Flow Integrity: Principles, Implementations, and Applications”, Retrieved at <<http://research.microsoft.com/en-us/um/people/mbudiu/cfi.pdf.>>, Nov. 1, 2004, pp. 1-33. [cited by applicant]
Wang, et al., “FP-Validator: Validating Type Equivalence of Function Pointers on the Fly”, Retrieved at <<http://www.acsac.org/2009/openconf/modules/request.php?module=oc_program&action=view.php&id=204>>, Computer Secur… [cited by applicant]
Costa, et al., “Vigilante: End-to-End Containment of Internet Worm Epidemics”, Retrieved at <<http://research.microsoft.com/pubs/80640/a9-costa-TOCS.pdf>>, ACM Transactions on Computer Systems, Dec. 4, 2008, pp. 1-68. [cited by applicant]
Davi, et al., “MOCFI: A Framework to Mitigate Control-Flow Attacks on Smartphones”, Retrieved at <<http://www.informatik.tu-darmstadt.de/fileadmin/user_upload/Group_TRUST/PubsPDF/MoCFI-NDSS-2012.pdf>>, 19th Annual Netwo… [cited by applicant]
“Non-Final Office Action for U.S. Appl. No. 13/450,487”, Mailed Date: Nov. 6, 2013, 12 Pages. [cited by applicant]
“Reply to Non-Final Office Action for U.S. Appl. No. 13/450,487”, Filed Date: Apr. 5, 2014, 14 Pages. [cited by applicant]
“Non-Final Office Action for U.S. Appl. No. 13/450,487”, Mailed Date: Jul. 28, 2014, 14 Pages. [cited by applicant]
“Reply to Non-Final Office Action for U.S. Appl. No. 13/450,487”, Filed Date: Oct. 27, 2014, 16 Pages. [cited by applicant]
“Non-Final Office Action for U.S. Appl. No. 13/450,487”, Mailed Date: Apr. 9, 2015, 15 Pages. [cited by applicant]
“Reply to Non-Final Office Action for U.S. Appl. No. 13/450,487”, Filed Date: Sep. 7, 2015, 16 Pages. [cited by applicant]
“Non-Final Office Action for U.S. Appl. No. 13/450,487”, Mailed Date: Dec. 16, 2015, 16 Pages. [cited by applicant]
“Reply to Non-Final Office Action for U.S. Appl. No. 13/450,487”, Filed Date: May 16, 2016, 14 Pages. [cited by applicant]
“Final Office Action for U.S. Appl. No. 13/450,487”, Mailed Date: Aug. 18, 2016, 17 Pages. [cited by applicant]
“Non-Final Office Action for U.S. Appl. No. 13/450,487”, Mailed Date: Feb. 15, 2017, 22 Pages. [cited by applicant]
“Reply to Non-Final Office Action for U.S. Appl. No. 13/450,487”, Filed Date: Aug. 15, 2017, 15 Pages. [cited by applicant]
“Final Office Action for U.S. Appl. No. 13/450,487”, Mailed Date: Nov. 30, 2017, 20 Pages. [cited by applicant]
“Reply to Final Office Action for U.S. Appl. No. 13/450,487”, Filed Date: Feb. 2, 2018, 11 Pages. [cited by applicant]
“Advisory Action for U.S. Appl. No. 13/450,487”, Mailed Date: Mar. 1, 2018, 2 Pages. [cited by applicant]
“Non-Final Office Action for U.S. Appl. No. 13/450,487”, Mailed Date: Aug. 16, 2018, 20 Pages. [cited by applicant]
“Reply to Non-Final Office Action for U.S. Appl. No. 13/450,487”, Filed Date: Jan. 16, 2019, 12 Pages. [cited by applicant]
“Final Office Action for U.S. Appl. No. 13/450,487”, Mailed Date: May 14, 2019, 21 Pages. [cited by applicant]
“Reply to Final Office Action for U.S. Appl. No. 13/450,487”, Filed Date: Oct. 14, 2019, 16 Pages. [cited by applicant]
“Non-Final Office Action for U.S. Appl. No. 13/450,487”, Mailed Date: Apr. 30, 2020, 31 Pages. [cited by applicant]
“Reply to Non-Final Office Action for U.S. Appl. No. 13/450,487”, Filed Date: Sep. 30, 2020, 17 Pages. [cited by applicant]
“Notice of Allowance and Fees Due for U.S. Appl. No. 13/450,487”, Mailed Date: Jan. 7, 2021, 5 Pages. [cited by applicant]