Invention Grant
- Patent Title: System and method for enabling a malware prevention module in response to a context switch within a certain process being executed by a processor
-
Application No.: US15644039Application Date: 2017-07-07
-
Publication No.: US10706180B2Publication Date: 2020-07-07
- Inventor: Gabriel Landau
- Applicant: Endgame. Inc.
- Applicant Address: US VA Arlington
- Assignee: Endgame, Inc.
- Current Assignee: Endgame, Inc.
- Current Assignee Address: US VA Arlington
- Agency: Carr & Ferrell LLP
- Main IPC: G06F21/75
- IPC: G06F21/75 ; G06F9/30 ; G06F9/38 ; G06F21/74 ; G06F21/53 ; G06F21/55

Abstract:
A performance monitoring unit in a processor is programmed to issue an interrupt when a context switch occurs within an operating system if the currently executing thread belongs to a process that is subject to the malware prevention mechanism of the present invention. The interrupt enables a module that identifies mispredictions by the branch prediction unit of the processor and analyzes the address of the branch that was not predicted correctly. If the address of the branch is not contained on an existing whitelist of permissible branch addresses, and alert is generated and/or a protective action is taken. Such protective actions may include thread suspension, thread termination, process suspension, or process termination.
Public/Granted literature
Information query