USENIX Security2024Top-tier venue
On Bridging the Gap between Control Flow Integrity and Attestation Schemes
Mahmoud Ammar, Ahmed Abdelraoof, Silviu Vlasceanu
Abstract
Control-flow hijacking attacks remain a significant challenge in software security. Several means of protection and detection have been proposed but gaps still exist. To address such gaps, leading processor manufacturers have introduced new extensions in their latest-generation architectures, such as Pointer Authentication (PA) and Branch Target Identification (BTI) technologies in the ARMv8.5-A processor architecture. However, simply enabling these technologies would offer only limited security guarantees without trustworthy evidence of runtime integrity. To bridge this gap, we propose CFA+, a practical hardwareassisted control flow attestation mechanism with prevention capabilities. CFA+ leverages ARMv8.5-A's BTI security extension in combination with selective software instrumentation to enable lightweight always-on monitoring of the execution state without the need for maintaining in-memory control flow logs. The hybrid policy of CFA+ enables immediate prevention or quick detection of control-flow violations while providing trustworthy evidence of runtime integrity. CFA+ offers strong security guarantees for complex software stacks while maintaining high efficiency and scalability. Evaluation results demonstrate that CFA+ incurs an average runtime overhead of less than 3% when applied to various benchmark applications, including the SPEC CPU2006 suite and nginx.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e708e372-00ee-48b2-845e-46516c21b61eCited by top-tier papers5
- SoK: Integrity, Attestation, and Auditing of Program ExecutionMahmoud Ammar, Adam Caulfield, Ivan De Oliveira NunesS&P 2025
- SoK: On the Fragility of Memory Error Exploit MitigationsAdriaan Jacobs, Mahmoud Ammar, Stijn VolckaertUSENIX Security 2026
- EXIA: Trusted Transitions for Enclaves via External-Input AttestationZhen Huang, Yidi Kao, Sanchuan Chen, Guoxing Chen et al.NDSS 2026
- XCFI: Comprehensive Control-Flow Integrity for Arm TrustZone-MYunju Gu, Jaeyeol Park, Donghyun KwonUSENIX Security 2026
- ARTO: Efficient Execution Integrity Attestation for Real-Time Operation of Cyber-Physical SystemsRuizhe Zhao, Cong Sun, Zongzhen Li, Tiantian Wang et al.USENIX Security 2026
Builds on25
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- C-FLAT: Control-Flow Attestation for Embedded Systems SoftwareTigist Abera, N. Asokan, Lucas Davi, Jan-Erik Ekberg et al.CCS 2016 · 311 citations
- PAC it up: Towards Pointer Integrity using ARM Pointer AuthenticationHans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez et al.USENIX Security 2019 · 168 citations
- Enforcing Unique Code Target Property for Control-Flow IntegrityHong Hu, Chenxiong Qian, Carter Yagemann, Simon Pak Ho Chung et al.CCS 2018 · 142 citations
- Efficient Protection of Path-Sensitive Control SecurityRen Ding, Chenxiong Qian, Chengyu Song, William Harris et al.USENIX Security 2017 · 123 citations
Related papers
- Camouflage: Hardware-assisted CFI for the ARM Linux kernelRémi Denis-Courmont, Hans Liljestrand, Carlos Chinea Perez, Jan-Erik EkbergDAC 2020 · 18 citations
- ACFA: Secure Runtime Auditing & Guaranteed Device Healing via Active Control Flow AttestationAdam Caulfield, Norrathep Rattanavipanon, Ivan De Oliveira NunesUSENIX Security 2023
- In-Kernel Control-Flow Integrity on Commodity OSes using ARM Pointer AuthenticationSungbae Yoo, Jinbum Park, Seolheui Kim, Yeji Kim et al.USENIX Security 2022
- RAP-Track: Efficient Control Flow Attestation via Parallel Tracking in Commodity MCUsAntonio Joia Neto, Adam Caulfield, Ivan De Oliveira NunesDAC 2025 · 1 citation
- Tiktag: Breaking ARM's Memory Tagging Extension with Speculative ExecutionJuhee Kim, Jinbum Park, Sihyeon Roh, Jaeyoung Chung et al.S&P 2025
