Defeating Transient Execution Attacks by Limiting Secret Reachability Through Register Hiding and ShadowCFI
Daniël Trujillo, Jagadish Kotra, David Kaplan, Mengjia Yan
Abstract
Modern processors incorporate aggressive branch prediction mechanisms for indirect branches, offering various unanticipated ways to influence speculative behavior during a transient execution attack. Existing mitigations against these so-called Spectre v2-style attacks are often ad-hoc, highly specific to the discovered attack and the targeted microarchitecture, and thus fail to generalize. In this paper, we identify a core requirement previously overlooked that all of these attacks share: secret reachability. Building upon this, we propose Register Hiding and ShadowCFI, two complementary but independent software-based and hardware-agnostic techniques which target the attacker's ability to reach secrets in registers and memory. Register Hiding hides the architectural register state before a misprediction can occur, while ShadowCFI ensures the architectural register state can only be restored at the correct target. To demonstrate their merit, we implement a fully functional patch for Linux kernel version 6.8.0, protecting against known and futuristic Spectre v2-style attacks, including all those which target indirect jumps, indirect calls and returns. We provide a security analysis and corresponding scanner to verify that an attacker cannot restore the register state during misprediction in our proof-of-concept. Replacing the most recently deployed Spectre v2 defenses with Register Hiding and ShadowCFI reduces the overall mitigation overhead on AMD Zen 4 from 114.1% to 75.9% for LEBench, and from 33.4% to 25.8% on average across server workloads.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fb794ab8-dc85-4f3d-bdf2-b59414fe0351Builds on21
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- ret2spec: Speculative Execution Using Return Stack BuffersGiorgi Maisuradze, Christian RossowCCS 2018 · 282 citations
- SMoTherSpectre: Exploiting Speculative Execution through Port ContentionAtri Bhattacharyya, Alexandra Sandulescu, Matthias Neugschwandtner, Alessandro Sorniotti et al.CCS 2019 · 267 citations
- Spectector: Principled Detection of Speculative Information FlowsMarco Guarnieri, Boris Köpf, José F. Morales, Jan Reineke et al.S&P 2020 · 177 citations
- Hardware-Software Contracts for Secure SpeculationMarco Guarnieri, Boris Köpf, Jan Reineke, Pepe VilaS&P 2021 · 111 citations
Related papers
- SpecCFI: Mitigating Spectre Attacks using CFI Informed SpeculationEsmaeil Mohammadian Koruyeh, Shirin Haji Amin Shirazi, Khaled N. Khasawneh, Chengyu Song et al.S&P 2020 · 74 citations
- RETBLEED: Arbitrary Speculative Code Execution with Return InstructionsJohannes Wikner, Kaveh RazaviUSENIX Security 2022
- SoK: Shining Light on Shadow StacksNathan Burow, Xinping Zhang, Mathias PayerS&P 2019 · 170 citations
- Breaking the Barrier: Post-Barrier Spectre AttacksJohannes Wikner, Kaveh RazaviS&P 2025
- VMSCAPE: Exposing and Exploiting Incomplete Branch Predictor Isolation in Cloud EnvironmentsJean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, Kaveh RazaviS&P 2026 · 4 citations
