Hardware-Embedded Memory Page Monitors for Unauthorized Change Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for protecting hardware computing components from unauthorized changes and execution of unauthorized programming instructions are either resource-intensive or prone to false-positive indications, making them ineffective in providing timely and accurate security breaches detection.
Innovation Solution
The implementation of hardware-embedded monitors that record and monitor executable pages in memory during periods of stability, such as after boot time, to detect unauthorized changes and generate secure interrupts for mitigating actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If monitoring all traffic sent on various communication channels within and/or between hardware computing components is implemented, then security breach detection capability is improved, but resource consumption increases excessively and false-positive indications increase
Solution Approach 1:
The patent segments the monitoring scope from all communication channels to specifically target executable memory pages. Instead of monitoring all traffic, the system divides monitoring focus into discrete memory pages with executable attributes, tracking only those specific segments that pose security risks. This segmentation reduces the monitoring burden while maintaining security effectiveness.
Solution Approach 2:
The patent applies local quality by implementing monitoring specifically at memory pages with executable attributes rather than uniformly across all memory or communication channels. The hardware-embedded monitor selectively tracks only those memory locations that contain executable code, concentrating monitoring resources where security breaches are most likely to occur without wasting resources on non-executable memory regions.
2Reliability
If monitoring all traffic sent on various communication channels within and/or between hardware computing components is implemented, then security breach detection capability is improved, but false-positive indications increase
Solution Approach 1:
The patent segments the monitoring scope from all communication channels to specifically target executable memory pages. Instead of monitoring all traffic, the system divides monitoring focus into discrete memory pages with executable attributes, tracking only those specific segments that pose security risks. This segmentation reduces the monitoring burden while maintaining security effectiveness.
Solution Approach 2:
The patent introduces hardware-embedded monitors as intermediary components that sit between the processing elements and memory, specifically at the memory page level. These intermediaries capture and analyze memory access patterns related to executable pages, providing precise security monitoring without the need to intercept and analyze all communication traffic, thereby reducing false positives.
3Loss of time
If hardware-embedded monitors record and monitor executable pages in memory during periods of stability, then early detection of unauthorized changes is achieved, but device complexity increases
Solution Approach 1:
The patent merges the monitoring functionality directly into the hardware computing component's existing memory management architecture. The hardware-embedded monitors are integrated within the same chip or processing unit that manages memory, combining security monitoring functions with existing memory control logic. This integration reduces the need for separate external monitoring devices and minimizes overall system complexity while enabling early detection of unauthorized changes.
Data Source
AI summary
Technologies are disclosed for using hardware-embedded monitors to monitor pages of local memory and detect attribute violations or other unauthorized operations relating to the memory. The attribute violations may include mismatches of attributes (e.g., designating a page as writeable versus executable or vice versa) in entries in a translation buffer that point to a same physical address or other mismatches between designations of attributes for a page in physical and virtual space. Responsive to detecting a violation, an alert or other mitigation protocol, which may include an audit of activities surrounding the violation, may be performed.


