5 papers
DIG: Oracle-Guided Directed Input Generation for One-Day Vulnerabilities
Andrew Bao, Haochen Zeng, Peng Chen +2
One-day vulnerabilities pose significant risks due to delayed or incomplete patch adoption. Generating proof-of-concept (PoC) inputs is therefore essential for assessing real-world…
Partitioned Tags, Shared Data: Reconciling Strict Cache Isolation with Write-Shared Coherence
Kartik Ramkrishnan, Stephen McCamant, Antonia Zhai +1
Cache partitioning is among the strongest structural defenses against eviction-based cache side channels, yet a decade-old design issue has blocked its widespread deployment in sec…
Generator-Based Fuzzers with Type-Based Targeted Mutation
Soha Hussein, Stephen McCamant, Mike Whalen
As with any fuzzer, directing Generator-Based Fuzzers (GBF) to reach particular code targets can increase the fuzzer's effectiveness. In previous work, coverage-guided fuzzers used…
Supporting Secured Integration of Microarchitectural Defenses
Kartik Ramkrishnan, Stephen McCamant, Antonia Zhai +1
There has been a plethora of microarchitectural-level attacks leading to many proposed countermeasures. This has created an unexpected and unaddressed security issue where naive in…
Shield Bash: Abusing Defensive Coherence State Retrieval to Break Timing Obfuscation
Kartik Ramkrishnan, Antonia Zhai, Stephen McCamant +1
Microarchitectural attacks are a significant concern, leading to many hardware-based defense proposals. However, different defenses target different classes of attacks, and their i…