System and method for enabling a malware prevention module in response to a context switch within a certain process being executed by a processor
US10706180B2 · kind B2 · utility
Assignee
Inventor
Key dates
| Filing date | Jul 7, 2017 |
| Grant date | Jul 7, 2020 |
| Priority date | — |
| Expiry date | Dec 15, 2037 |
Classification
- Technology area (CPC G)Physics
- CPC primaryG06F21/74
- WIPO fieldComputer technology
- WIPO sectorElectrical engineering
Abstract
A performance monitoring unit in a processor is programmed to issue an interrupt when a context switch occurs within an operating system if the currently executing thread belongs to a process that is subject to the malware prevention mechanism of the present invention. The interrupt enables a module that identifies mispredictions by the branch prediction unit of the processor and analyzes the address of the branch that was not predicted correctly. If the address of the branch is not contained on an existing whitelist of permissible branch addresses, and alert is generated and/or a protective action is taken. Such protective actions may include thread suspension, thread termination, process suspension, or process termination.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.