Intel announced today that its experimental CET security feature will be available for the first time in the company's upcoming Tiger Lake mobile CPUs.

Intel has been working on CET, which stands for Control-flow Enforcement Technology, since 2016, when it first published the first version of the CET specification.
As its name suggests, CET deals with “control flow,” a technical term used to describe the order in which operations are executed within the CPU.
Malware running on a device can use vulnerabilities in other applications to violate their control flow and insert its malicious code to execute within the context of another application.
In Intel's upcoming Tiger Lake mobile , CET will protect control flow through two new security mechanisms, called shadow stack and indirect branch tracking.
Shadow stack refers to creating a copy of an application's intended control flow, storing the shadow stack in a secure area of the CPU, and using it to ensure that no unauthorized changes are made to an application's intended execution sequence.
Intel says the CET shadow stack will protect users from a technique called Return Oriented Programming (ROP), where malware abuses the RET (return) command to append its malicious code to the legitimate application control flow.
On the other hand, the technique of “indirect branch tracking” refers to limiting and adding additional safeguards to an application’s ability to use CPU “jump tables,” which are tables containing memory locations (re)used throughout an application’s control flow.
Intel says that the "indirect branch tracking" technique protects against two techniques called Jump Oriented Programming (JOP) and Call Oriented Programming (COP), where malware abuses JMP or CALL instructions to invade legitimate application jump tables.
Because Intel published the CET specification in 2016, software developers had time to adapt their code for the first line of Intel processors that would support it.
CET support has already been ported to Glibc, and Microsoft has also added CET support to Windows Insiders, with a feature called Stack Protection.
All that's needed now is for Intel to release processors that support CET instructions, so applications and operating systems can enable support and opt in to the protection that CET provides.
CET was released today for Intel's line of mobile CPUs using the Tiger Lake microarchitecture, but the technology will also be available on desktop and server platforms , said Tom Garrison, vice president of the Client Computing Group and general manager of security strategies and initiatives (SSI) at Intel Corporation.
