iEnFlow: Endogenous Control-Flow Attacks via Conditional Branch Prediction on Apple Silicon
Kaiyuan Rong, Jiajie Chen, Junqi Fang, Peng Qu, Hanyin Liu, Youhui Zhang, Dapeng Ju, Dongsheng Wang
摘要
Control-flow attacks have drawn increasing attention in microarchitectural security research due to their ability to expose sensitive data by revealing or manipulating program control-flow. Prior work has primarily focused on x86 architectures, with relatively few studies exploring such attacks on ARM-based Apple silicon processors. Meanwhile, existing microarchitectural side-channels that leak control-flow information on Apple silicon either rely on microarchitectural components beyond the branch predictor or lack a detailed understanding of branch predictor designs, which limits their generality and scalability.
In this paper, we present iEnFlow, the first endogenous and finegrained control-flow attacks on Apple silicon that directly exploit control-flow information originating from the branch predictor itself. We target the conditional branch predictor (CBP) and reverseengineer its internal design, including branch history length, hashing function, and predictor-table indexing scheme. Based on these reverse-engineering results, we develop primitives to read and write branch history and predictor-table entries, enabling unprivileged leakage and manipulation of the CBP on macOS. Using these primitives, we implement two attacks to demonstrate the effectiveness of
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper39
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB AttacksBen Gras, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaUSENIX Security 2018 · 被引用 357 次
- KEPLER: Facilitating Control-flow Hijacking Primitive Evaluation for Linux Kernel VulnerabilitiesWei Wu, Yueqi Chen, Xinyu Xing, Wei ZouUSENIX Security 2019 · 被引用 75 次
- Prime+Probe 1, JavaScript 0: Overcoming Browser-based Side-Channel DefensesAnatoly Shusterman, Ayush Agarwal, Sioli O'Connell, Daniel Genkin 等USENIX Security 2021 · 被引用 73 次
- PACMAN: attacking ARM pointer authentication with speculative executionJoseph Ravichandran, Weon Taek Na, Jay Lang, Mengjia YanISCA 2022 · 被引用 68 次
相关 Paper
- SLAP: Data Speculation Attacks via Load Address Prediction on Apple SiliconJason Kim, Daniel Genkin, Yuval YaromS&P 2025
- Pathfinder: High-Resolution Control-Flow Attacks Exploiting the Conditional Branch PredictorHosein Yavarzadeh, Archit Agarwal, Max Christman, Christina Garman 等ASPLOS 2024 · 被引用 21 次
- SysBumps: Exploiting Speculative Execution in System Calls for Breaking KASLR in macOS for Apple SiliconHyerean Jang, Taehun Kim, Youngjoo ShinCCS 2024 · 被引用 6 次
- Augury: Using Data Memory-Dependent Prefetchers to Leak Data at RestJose Rodrigo Sanchez Vicarte, Michael Flanders, Riccardo Paccagnella, Grant Garrett-Grossman 等S&P 2022 · 被引用 66 次
- Conjuring: Leaking Control Flow via Speculative Fetch AttacksAli Hajiabadi, Trevor E. CarlsonDAC 2024 · 被引用 5 次
