You Shall Not Pass into Ring-0! A User Privacy-Friendly Anti-Cheat Architecture for Personal Computers
Santosh Gokul Narayanan, Giovanni Paladino, Chuqi Zhang, Sangho Lee, Zhenkai Liang, Adil Ahmad
Abstract
Kernel-level anti-cheats are effective against malicious player behavior in competitive video games, but raise significant user privacy concerns regarding installing unverifiable components at privileged modes (i.e., ring-0 in x86). While existing research has focused on improving the effectiveness of anti-cheats, the user privacy concern has been largely ignored. Tirith is an anti-cheat architecture that addresses this problem using two key ideas. First, instead of running video games within regular processes that players (as root admins) have control over, Tirith executes video games in Protected Virtual Machines that naturally sandbox computations from untrusted admins. Second, to monitor user behavior outside the sandbox (e.g., see if they are running malicious drivers), Tirith leverages a virtualization monitor that is trusted by both players and developers. Together, these ideas remove the need to run untrusted kernel-level anti-cheats, while providing the same level of protection compared to such solutions against a wide-range of common cheating mechanisms. The main challenge we face in implementing these ideas, however, is that the existing software stack for virtual machines is not designed to run video games and creates significant security and performance problems. We address these problems by proposing a security-focused Library OS kernel for games and an efficient graphics sharing pipeline for near-native rendering and display performance. In summary, without compromising on cheating behavior detection or performance, this work makes user privacy a first-class citizen in personal computers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ad78c3c4-a60f-4e92-ba42-4e12ca8f68e3Builds on15
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Plundervolt: Software-based Fault Injection Attacks against Intel SGXKit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck et al.S&P 2020 · 369 citations
- Panoply: Low-TCB Linux Applications With SGX EnclavesShweta Shinde, Dat Le Tien, Shruti Tople, Prateek SaxenaNDSS 2017 · 274 citations
- Firecracker: Lightweight Virtualization for Serverless ApplicationsAlexandru Agache, Marc Brooker, Alexandra Iordache, Anthony Liguori et al.NSDI 2020 · 197 citations
Related papers
- Micro-Virtualization Memory Tracing to Detect and Prevent Spraying AttacksStefano Cristalli, Mattia Pagnozzi, Mariano Graziano, Andrea Lanzi et al.USENIX Security 2016 · 10 citations
- PIkit: A New Kernel-Independent Processor-Interconnect RootkitWonJun Song, Hyunwoo Choi, Junhong Kim, Eunsoo Kim et al.USENIX Security 2016 · 13 citations
- Efficient Linkage-Based Compartmentalization on CHERIDapeng Gao, John Baldwin, Jessica Clarke, Nicholas C. Connolly et al.CCS 2026
- Veil: A Protected Services Framework for Confidential Virtual MachinesAdil Ahmad, Botong Ou, Congyu Liu, Xiaokuan Zhang et al.ASPLOS 2023 · 12 citations
- SoK: Another Arms Race -- 20 Years of (Anti-)Cheating in Video GamesPhilip Klostermeyer, Jan-Ulrich Holtgrave, Jacques Suray, Anne Vonderheide et al.USENIX Security 2026
