HyBP: Hybrid Isolation-Randomization Secure Branch Predictor
Lutan Zhao, Peinan Li, Rui Hou, Michael C. Huang, Xuehai Qian, Lixin Zhang, Dan Meng
Abstract
Recently exposed vulnerabilities reveal the necessity to improve the security of branch predictors. Branch predictors record history about the execution of different processes, and such information from different processes are stored in the same structure and thus accessible to each other. This leaves the attackers with the opportunities for malicious training and malicious perception. Physical or logical isolation mechanisms such as using dedicated tables and flushing during context-switch can provide security but incur non-trivial costs in space and/or execution time. Randomization mechanisms incurs the performance cost in a different way: those with higher securities add latency to the critical path of the pipeline, while the simpler alternatives leave vulnerabilities to more sophisticated attacks.
This paper proposes HyBP, a practical hybrid protection and effective mechanism for building secure branch predictors. The design applies the physical isolation and randomization in the right component to achieve the best of both worlds. We propose to protect the smaller tables with physically isolation based on (thread, privilege) combination; and protect the large tables with randomization. Surprisingly, the physical isolation also significantly enhances the security of the last-level tables by naturally filtering out accesses, reducing the information flow to these bigger tables. As a result, key changes can happen less frequently and be performed conveniently at context switches. Moreover, we propose a latency hiding design for a strong cipher by precomputing the "code book" with a validated, cryptographically strong cipher. Overall, our design incurs a performance penalty of 0.5% compared to 5.1% of physical isolation under the default context switching interval in Linux.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5488ad49-7de0-457f-bb84-d2647b08eff0Cited by top-tier papers5
- Indirector: High-Precision Branch Target Injection Attacks Exploiting the Indirect Branch PredictorLuyi Li, Hosein Yavarzadeh, Dean M. TullsenUSENIX Security 2024 · 18 citations
- Conjuring: Leaking Control Flow via Speculative Fetch AttacksAli Hajiabadi, Trevor E. CarlsonDAC 2024 · 5 citations
- CryptoBTB: A Secure Hierarchical BTB for Diverse Instruction Footprint WorkloadsDebpratim Adak, Eric Rotenberg, Amro Awad, Huiyang ZhouMICRO 2025 · 1 citation
- OCCUPY+PROBE: Cross-Privilege Branch Target Buffer Side-Channel Attacks at Instruction GranularityKaiyuan Rong, Junqi Fang, Haixia Wang, Dapeng Ju et al.NDSS 2026
- BunnyHop: Exploiting the Instruction PrefetcherZhiyuan Zhang, Mingtian Tao, Sioli O'Connell, Chitchanok Chuengsatiansup et al.USENIX Security 2023
Builds on6
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim et al.USENIX Security 2017 · 536 citations
- ScatterCache: Thwarting Cache Attacks via Cache Set RandomizationMario Werner, Thomas Unterluggauer, Lukas Giner, Michael Schwarz et al.USENIX Security 2019 · 221 citations
- Systematic Analysis of Randomization-based Protected Cache ArchitecturesAntoon Purnal, Lukas Giner, Daniel Gruss, Ingrid VerbauwhedeS&P 2021 · 93 citations
- Exploring Branch Predictors for Constructing Transient Execution TrojansTao Zhang, Kenneth Koltermann, Dmitry EvtyushkinASPLOS 2020 · 32 citations
Related papers
- A Lightweight Isolation Mechanism for Secure Branch PredictorsLutan Zhao, Peinan Li, Rui Hou, Michael C. Huang et al.DAC 2021 · 29 citations
- HybCache: Hybrid Side-Channel-Resilient Caches for Trusted Execution EnvironmentsGhada Dessouky, Tommaso Frassetto, Ahmad-Reza SadeghiUSENIX Security 2020
- Branch Privilege Injection: Compromising Spectre v2 Hardware Mitigations by Exploiting Branch Predictor Race ConditionsSandro Rüegge, Johannes Wikner, Kaveh RazaviUSENIX Security 2025
- Half&Half: Demystifying Intel's Directional Branch Predictors for Fast, Secure Partitioned ExecutionHosein Yavarzadeh, Mohammadkazem Taram, Shravan Narayan, Deian Stefan et al.S&P 2023
- SCARF - A Low-Latency Block Cipher for Secure Cache-RandomizationFederico Canale, Tim Güneysu, Gregor Leander, Jan Philipp Thoma et al.USENIX Security 2023
