PIBE: practical kernel control-flow hardening with profile-guided indirect branch elimination
Victor Duta, Cristiano Giuffrida, Herbert Bos, Erik van der Kouwe
摘要
Control-flow hijacking, which allows an attacker to execute arbitrary code, remains a dangerous software vulnerability. Controlflow hijacking in speculated or transient execution is particularly insidious as it allows attackers to leak data from operating system kernels and other targets on commodity hardware, even in the absence of software bugs. Having made the jump from regular to transient execution in recent attacks, control-flow hijacking has become a top priority for developers. While powerful defenses against control-flow hijacking in regular execution are now sufficiently low-overhead to see wide-spread adoption, this is not the case for defenses in transient execution. Unfortunately, current techniques for mitigating attacks in transient execution exhibit high overheadsÐrequiring a costly combination of defenses for every indirect branch.
We show that the high overhead incurred by state-of-the-art mitigations is mostly due to the effect of hardening frequently executed branches. We propose PIBE, which offers comprehensive protection against control-flow hijacking at a fraction of the cost of existing solutions, by revisiting design choices in the compiler's optimization passes. For every indirect branch, it decides whether to harden it with instrumentation code or elide it altogether using code transformations. By specifically removing the heavy hitters among the indirect branches through tailored profile-guided optimization, PIBE aggressively reduces the number of vulnerable branches to allow the simultaneous application of multiple state-ofthe-art defenses on the remaining branches with practical overhead. Demonstrating our solution on the Linux kernel, one of the largest, most complex and most security-critical code bases on modern systems, we show that PIBE reduces the overhead of comprehensive defenses against transient control flow hijacking by an order of magnitude, from 149% to 10.6% on microbenchmarks and from 40% to around 6% on several application benchmarks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Verified programs can party: optimizing kernel extensions via post-verification mergingHsuan-Chi Kuo, Kai-Hsun Chen, Yicheng Lu, Dan Williams 等EuroSys 2022 · 被引用 17 次
- BeeBox: Hardening BPF against Transient Execution AttacksDi Jin, Alexander J. Gaidis, Vasileios P. KemerlisUSENIX Security 2024 · 被引用 10 次
- Branch History Injection: On the Effectiveness of Hardware Mitigations Against Cross-Privilege Spectre-v2 AttacksEnrico Barberis, Pietro Frigo, Marius Muench, Herbert Bos 等USENIX Security 2022
- Predictive Context-sensitive FuzzingPietro Borrello, Andrea Fioraldi, Daniele Cono D'Elia, Davide Balzarotti 等NDSS 2024
- Retrofitting XoM for Stripped Binaries without Embedded Data RelocationChenke Luo, Jiang Ming, Mengfei Xie, Guojun Peng 等NDSS 2025
它引用的顶会 Paper10
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck 等CCS 2019 · 被引用 464 次
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp 等USENIX Security 2019 · 被引用 442 次
相关 Paper
- System Register Hijacking: Compromising Kernel Integrity By Turning System Registers Against the SystemJennifer Miller, Manas Ghandat, Kyle Zeng, Hongkai Chen 等USENIX Security 2025
- Perspective: A Principled Framework for Pliable and Secure Speculation in Operating SystemsTae Hoon Kim, David Rudo, Kaiyang Zhao, Zirui Neil Zhao 等ISCA 2024 · 被引用 6 次
- SpecCFI: Mitigating Spectre Attacks using CFI Informed SpeculationEsmaeil Mohammadian Koruyeh, Shirin Haji Amin Shirazi, Khaled N. Khasawneh, Chengyu Song 等S&P 2020 · 被引用 74 次
- Defeating Transient Execution Attacks by Limiting Secret Reachability Through Register Hiding and ShadowCFIDaniël Trujillo, Jagadish Kotra, David Kaplan, Mengjia YanS&P 2026 · 被引用 1 次
- Kasper: Scanning for Generalized Transient Execution Gadgets in the Linux KernelBrian Johannesmeyer, Jakob Koschel, Kaveh Razavi, Herbert Bos 等NDSS 2022
