Rapid Reversing of Non-Linear CPU Cache Slice Functions: Unlocking Physical Address Leakage
Mikka Rainer, Lorenz Hetterich, Fabian Thomas, Tristan Hornetz, Leon Trampert, Lukas Gerlach, Michael Schwarz
摘要
Microarchitectural attacks are a growing threat to modern computing systems. CPU caches are an essential but complex element in many microarchitectural attacks, making it crucial to understand the inner workings. Despite progress in reverse-engineering techniques, non-linear cache-slice functions remain challenging to analyze, especially in recent Intel hybrid microarchitectures. In this paper, we introduce a novel approach towards reverse-engineering complex, non-linear cache-slice functions, particularly on modern Intel CPUs with hybrid microarchi-tectures. Our method significantly advances prior work by understanding the specific structure of microarchitectural hash functions, reducing the time required for reverse-engineering from days to minutes. In contrast to prior work, our technique successfully handles systems with 512 GB of memory and diverse slice configurations. We present 13 newly identified functions used for cache-slice addressing and extend existing functions to support systems with more DRAM for multiple CPU generations. Additionally, we introduce an unprivileged virtual-to-physical address oracle that is a direct consequence of the complexity of the non-linear slice functions. Our method is particularly effective on modern Intel hybrid CPUs, in-cluding Alder Lake and Meteor Lake, where previously used methods for measuring slices or leaking physical addresses are unavailable. In 3 case studies, we validate our approach, demonstrating its effectiveness in executing targeted Spectre attacks on non-attacker-mapped memory, enabling DRAMA attacks, and creating cache eviction sets. Our findings em-phasize the increased attack surface introduced by complex cache-slice functions in modern CPU s.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- SNPeek: Side-Channel Analysis for Privacy Applications on Confidential VMsRuiyi Zhang, Albert Cheu, Adrià Gascón, Daniel Moghimi 等NDSS 2026 · 被引用 7 次
- SSBench: Automated Characterization of Memory Dependence Predictors on Modern CPUsChang Liu, Yu Jin, Yuchen Fan, Tianrui Xiao 等ISCA 2026 · 被引用 1 次
- Principled Design of Indexing Functions for Memory ColoringStephan Dübler, Jana Hofmann, Boris Köpf, Stavros VolosUSENIX Security 2026
它引用的顶会 Paper27
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz 等USENIX Security 2016 · 被引用 500 次
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck 等CCS 2019 · 被引用 464 次
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo 等S&P 2019 · 被引用 408 次
相关 Paper
- Efficient and Generic Microarchitectural Hash-Function RecoveryLukas Gerlach, Simon Schwarz, Nicolas Faroß, Michael SchwarzS&P 2024 · 被引用 14 次
- Slice+Slice Baby: Generating Last-Level Cache Eviction Sets in the Blink of an EyeBradley Morgan, Gal Horowitz, Sioli O'Connell, Stephan van Schaik 等S&P 2025
- DRAMDig: A Knowledge-assisted Tool to Uncover DRAM Address MappingMinghua Wang, Zhi Zhang, Yueqiang Cheng, Surya NepalDAC 2020 · 被引用 42 次
- ZenLeak: Practical Last-Level Cache Side-Channel Attacks on AMD Zen ProcessorsHan Wang, Ming Tang, Quancheng Wang, Ke Xu 等DAC 2025 · 被引用 2 次
- ρHammer: Reviving RowHammer Attacks on New Architectures via PrefetchingWeijie Chen, Shan Tang, Yulin Tang, Xiapu Luo 等MICRO 2025 · 被引用 1 次
