Patent · US Active

System and method for enabling a malware prevention module in response to a context switch within a certain process being executed by a processor

US10706180B2 · kind B2 · utility

0Cited by
6References
25Claims
0Family size

Assignee

Inventor

Key dates

Filing dateJul 7, 2017
Grant dateJul 7, 2020
Priority date
Expiry dateDec 15, 2037

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F21/74
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

A performance monitoring unit in a processor is programmed to issue an interrupt when a context switch occurs within an operating system if the currently executing thread belongs to a process that is subject to the malware prevention mechanism of the present invention. The interrupt enables a module that identifies mispredictions by the branch prediction unit of the processor and analyzes the address of the branch that was not predicted correctly. If the address of the branch is not contained on an existing whitelist of permissible branch addresses, and alert is generated and/or a protective action is taken. Such protective actions may include thread suspension, thread termination, process suspension, or process termination.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.