arXiv · 2502.05429
SMaCk: Efficient Instruction Cache Attacks via Self-Modifying Code Conflicts
Abstract
Self-modifying code (SMC) allows programs to alter their own instructions, optimizing performance and functionality on x86 processors. Despite its benefits, SMC introduces unique microarchitectural behaviors that can be exploited for malicious purposes. In this paper, we explore the security implications of SMC by examining how specific x86 instructions affecting instruction cache lines lead to measurable timing discrepancies between cache hits and misses. These discrepancies facilitate refined cache attacks, making them less noisy and more effective. We introduce novel attack techniques that leverage these timing variations to enhance existing methods such as Prime+Probe and Flush+Reload. Our advanced techniques allow adversaries to more precisely attack cryptographic keys and create covert channels akin to Spectre across various x86 platforms. Finally, we propose a dynamic detection methodology utilizing hardware performance counters to mitigate these enhanced threats.
Explore related subjects
Keep this discovery
Seonghun Son, Daniel Moghimi, Berk Gulmezoglu. 2025-02-08. SMaCk: Efficient Instruction Cache Attacks via Self-Modifying Code Conflicts. https://doi.org/10.1145/3676641.3716274
Cite the original work for its findings. Save a collection to share your selection of sources.