13.02.2017 Views

Talos Vulndev

Harnessing%20Intel%20Processor%20Trace%20on%20Windows%20for%20Vulnerability%20Discovery%20-%20rjohnson

Harnessing%20Intel%20Processor%20Trace%20on%20Windows%20for%20Vulnerability%20Discovery%20-%20rjohnson

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

• Trace Logging<br />

– Each block gets a unique ID<br />

– Traversed edges are indexed<br />

into a bloom filter map<br />

– Create a hash from the<br />

src and dst block IDs<br />

– Increment map for each<br />

time an edge is traversed<br />

Amercian Fuzzy Lop<br />

– Each trace is easily comparable to the<br />

entire session history

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!