5 papers
DIG: Oracle-Guided Directed Input Generation for One-Day Vulnerabilities
Andrew Bao, Haochen Zeng, Peng Chen +2
One-day vulnerabilities pose significant risks due to delayed or incomplete patch adoption. Generating proof-of-concept (PoC) inputs is therefore essential for assessing real-world…
Partitioned Tags, Shared Data: Reconciling Strict Cache Isolation with Write-Shared Coherence
Kartik Ramkrishnan, Stephen McCamant, Antonia Zhai +1
Cache partitioning is among the strongest structural defenses against eviction-based cache side channels, yet a decade-old design issue has blocked its widespread deployment in sec…
XuanJia: A Comprehensive Virtualization-Based Code Obfuscator for Binary Protection
Xianyu Zou, Xiaoli Gong, Jin Zhang +2
Virtualization-based binary obfuscation is widely adopted to protect software intellectual property, yet existing approaches leave exception-handling (EH) metadata unprotected to p…
Supporting Secured Integration of Microarchitectural Defenses
Kartik Ramkrishnan, Stephen McCamant, Antonia Zhai +1
There has been a plethora of microarchitectural-level attacks leading to many proposed countermeasures. This has created an unexpected and unaddressed security issue where naive in…
Shield Bash: Abusing Defensive Coherence State Retrieval to Break Timing Obfuscation
Kartik Ramkrishnan, Antonia Zhai, Stephen McCamant +1
Microarchitectural attacks are a significant concern, leading to many hardware-based defense proposals. However, different defenses target different classes of attacks, and their i…