Towards Practical Interrupt Side-Channel Attacks on macOS for Apple Silicon
Xin Zhang, Chang Liu, Jiajun Zou, Yi Yang, Qingni Shen, Zhi Zhang, Trevor E. Carlson
Abstract
In recent years, the high-end CPU landscape has shifted from an x86-dominated market to one increasingly featuring heavyweight Arm designs, most notably Apple's Mseries. While prior work has examined side-channel resilience in the Apple ecosystem, interrupt-based channels remain an open and unexplored area. This is due to Apple's proprietary hardware and software implementation, the practicality of interrupt side channel attacks are constrained by two open challenges: precise interrupt detection and having a clear understanding of the interrupt delivery mechanism. In this paper, we propose TIDE, a precise interrupt detection technique that exploits an explicit macOS behavior arising from Apple's Double Map mitigation. Specifically, Double Map overwrites the user-visible x18 register during kernel mapping restoration and interrupt handler branching on user-to-kernel transitions. To prevent kernel information from being accessed by user-space, macOS further clears x18 on kernel-to-user transitions in a subsequent update. Leveraging this behavior, TIDE enables two primitives without reliance on architectural timers: measuring intervals between consecutive interrupts and filtering interrupt-induced noise. Using TIDE, we reverse-engineer Apple's closed-source interrupt delivery mechanism and reveal that, unlike Linux, Apple's interrupt controller uniformly distributes shared peripheral interrupts across all active cores. We then demonstrate the benefits of both TIDE itself and the reverse-engineering results through three case studies. First, we fingerprint websites running on Safari with an accuracy of 93.8% in a closed-world setting and 91.2% in an open-world setting, and video fingerprinting with an accuracy of 78.1%. Next, we use TIDE to filter out interrupt noise in countingthread timers, where TIDE tracks the number of noisy interrupts and only introduces an overhead of only 0.06%. With this, we have sigificiantly improved the SysBumps attack by increasing its success rate from 54% to 81%. Third, we examine the effect of our reverse-engineering results on the loop-counting attack, and find that a compute-intensive thread that generates no interrupts can reduce its accuracy from 94.8% to only 39.3%. By augmenting the training dataset with the number of active cores, we successfully enhance the robustness of the attack, achieving accuracies to 92.8% and 93.6% with and without noise, respectively. Further, we apply TIDE to build a timer-less covert channel with a high bandwidth of 111.65 b/s. Finally, TIDE successfully extracts the keys from Cloudflare's Interoperable Reusable Cryptographic Library (CIRCL) v1.1.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 87871a20-1769-47cb-8883-a43fcd12563eBuilds on36
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice et al.USENIX Security 2016 · 451 citations
- Prime+Abort: A Timer-Free High-Precision L3 Cache Attack using Intel TSXCraig Disselkoen, David Kohlbrenner, Leo Porter, Dean M. TullsenUSENIX Security 2017 · 186 citations
- Robust Website Fingerprinting Through the Cache Occupancy ChannelAnatoly Shusterman, Lachlan Kang, Yarden Haskal, Yosef Meltser et al.USENIX Security 2019 · 159 citations
- Trusted Browsers for Uncertain TimesDavid Kohlbrenner, Hovav ShachamUSENIX Security 2016 · 83 citations
- No Pardon for the Interruption: New Inference Attacks on Android Through Interrupt Timing AnalysisWenrui Diao, Xiangyu Liu, Zhou Li, Kehuan ZhangS&P 2016 · 79 citations
Related papers
- iLeakage: Browser-based Timerless Speculative Execution Attacks on Apple DevicesJason Kim, Stephan van Schaik, Daniel Genkin, Yuval YaromCCS 2023 · 16 citations
- SegScope: Probing Fine-grained Interrupts via Architectural FootprintsXin Zhang, Zhi Zhang, Qingni Shen, Wenhao Wang et al.HPCA 2024 · 15 citations
- SysBumps: Exploiting Speculative Execution in System Calls for Breaking KASLR in macOS for Apple SiliconHyerean Jang, Taehun Kim, Youngjoo ShinCCS 2024 · 6 citations
- Synchronization Storage Channels (S2C): Timer-less Cache Side-Channel Attacks on the Apple M1 via Hardware Synchronization InstructionsJiyong Yu, Aishani Dutta, Trent Jaeger, David Kohlbrenner et al.USENIX Security 2023
- The Danger of Minimum Exposures: Understanding Cross-App Information Leaks on iOS through Multi-Side-Channel LearningZihao Wang, Jiale Guan, XiaoFeng Wang, Wenhao Wang et al.CCS 2023 · 2 citations
