MoRE: Measurement of Running Executables

No ratings

Presented at BSidesDenver 2014 by

This presentation provides a cohesive overview of the work performed on the DARPA Cyber Fast Track MoRE effort. MoRE was a 4-month effort which examined the feasibility of utilizing TLB splitting as a mechanism for periodic measurement of dynamically changing binaries. The effort created a proof-of-concept system to split the TLB for target applications, allowing dynamic applications to be measured and can detect code corruption with low performance overhead. The thesis of this talk is to show that the x86 architecture has become so complex that its behavior can be modified through software.