Fractal: An Operating System Designed for Microarchitecture Reverse Engineering
Joseph Ravichandran, Mengjia Yan
Abstract
Modern microarchitecture security research requires a deep understanding of the microarchitecture designs of commodity hardware, specifically how the hardware is isolated between privilege domains. Since these details are usually undocumented, researchers must conduct reverse engineering experiments to learn the microarchitecture parameters of various processors. Currently, the state of the art approach is to modify commodity operating systems in an ad-hoc manner to enable these experiments. Our objective is to systematize the requirements of microarchitecture security research workflows, and to create new lightweight system software precisely tailored to these requirements. We present Fractal, a new operating system kernel built from the ground up to enable practical low-noise microarchitecture reverse engineering research at the user to kernel hardware boundary. Fractal enables seamless concurrency between privilege levels and a user-controlled scheduler for fine-grained thread ordering to enable new microarchitecture reverse engineering workflows with minimal noise. We ported Fractal to a variety of real systems and evaluate Fractal by using it to analyze the Apple M1 CPU. We uncovered a number of new insights about the branch predictor on M1, demonstrating for the first time evidence that limited Phantom speculation is present on Apple Silicon.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- SysBumps: Exploiting Speculative Execution in System Calls for Breaking KASLR in macOS for Apple SiliconHyerean Jang, Taehun Kim, Youngjoo ShinCCS 2024 · 6 citations
- Demystifying Pointer Authentication on Apple M1Zechao Cai, Jiaxun Zhu, Wenbo Shen, Yutian Yang et al.USENIX Security 2023
- PACMAN: attacking ARM pointer authentication with speculative executionJoseph Ravichandran, Weon Taek Na, Jay Lang, Mengjia YanISCA 2022 · 68 citations
- Opening Pandora's Box: A Systematic Study of New Ways Microarchitecture Can Leak Private DataJose Rodrigo Sanchez Vicarte, Pradyumna Shome, Nandeeka Nayak, Caroline Trippel et al.ISCA 2021 · 29 citations
- Augury: Using Data Memory-Dependent Prefetchers to Leak Data at RestJose Rodrigo Sanchez Vicarte, Michael Flanders, Riccardo Paccagnella, Grant Garrett-Grossman et al.S&P 2022 · 66 citations
