Automatically Reasoning About How Systems Code Uses the CPU Cache
Rishabh R. Iyer, Katerina J. Argyraki, George Candea
Abstract
We present a technique, called CFAR, that developers can use to reason precisely about how their code, as well as thirdparty code, uses the CPU cache. Given a piece of systems code P, CFAR employs program analysis and binary instrumentation to automatically "distill" how P accesses memory, and uses "projectors" on top of the extracted distillates to answer specific questions about P's cache usage. CFAR comes with three example projectors that report (1) how P's cache footprint scales across unseen inputs; (2) the cache hits and misses incurred by P for each class of inputs; and (3) potential vulnerabilities in cryptographic code caused by secretdependent cache-access patterns.
We implemented CFAR in an eponymous tool with which we analyze a performance-critical subset of four TCP stackstwo versions of the Linux stack, a stack used by the IX kernelbypass OS, and the lwIP TCP stack for embedded systemsas well as 7 algorithm implementations from the OpenSSL cryptographic library, all 51 system calls of the Hyperkernel, and 2 hash-table implementations. We show how CFAR enables developers to not only identify performance bugs and security vulnerabilities in their own code but also understand the performance impact of incorporating third-party code into their systems without doing elaborate benchmarking.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e98ea8e0-a67c-4057-be3c-77f6057bdacfCited by top-tier papers2
- Performance Interfaces for Hardware AcceleratorsJiacheng Ma, Rishabh R. Iyer, Sahand Kashani, Mahyar Emami et al.OSDI 2024 · 3 citations
- Heuristic Analysis from Source Code via Symbolic-Guided OptimizationPantea Karimi, Siva Kesava Reddy Kakarla, Ryan Beckett, Santiago Segarra et al.NSDI 2026
Builds on13
- Verifying Constant-Time ImplementationsJosé Bacelar Almeida, Manuel Barbosa, Gilles Barthe, François Dupressoir et al.USENIX Security 2016 · 274 citations
- The Demikernel Datapath OS Architecture for Microsecond-scale Datacenter SystemsIrene Zhang, Amanda Raybuck, Pratyush Patel, Kirk Olynyk et al.SOSP 2021 · 83 citations
- Memory-harvesting VMs in cloud platformsAlexander Fuerst, Stanko Novakovic, Iñigo Goiri, Gohar Irfan Chaudhry et al.ASPLOS 2022 · 39 citations
- Automated Reasoning and Detection of Specious Configuration in Large Systems with Symbolic ExecutionYigong Hu, Gongqi Huang, Peng HuangOSDI 2020 · 31 citations
- DMon: Efficient Detection and Correction of Data Locality Problems Using Selective ProfilingTanvir Ahmed Khan, Ian Neal, Gilles Pokam, Barzan Mozafari et al.OSDI 2021 · 31 citations
Related papers
- Precise Detection of Kernel Data Races with Probabilistic Lockset AnalysisGabriel Ryan, Abhishek Shah, Dongdong She, Suman JanaS&P 2023
- GhostRace: Exploiting and Mitigating Speculative Race ConditionsHany Ragab, Andrea Mambretti, Anil Kurmus, Cristiano GiuffridaUSENIX Security 2024 · 10 citations
- CacheD: Identifying Cache-Based Timing Channels in Production SoftwareShuai Wang, Pei Wang, Xiao Liu, Danfeng Zhang et al.USENIX Security 2017 · 130 citations
- HeapHopper: Bringing Bounded Model Checking to Heap Implementation SecurityMoritz Eckert, Antonio Bianchi, Ruoyu Wang, Yan Shoshitaishvili et al.USENIX Security 2018 · 62 citations
- CPscan: Detecting Bugs Caused by Code Pruning in IoT KernelsLirong Fu, Shouling Ji, Kangjie Lu, Peiyu Liu et al.CCS 2021 · 7 citations
