Gnanambikai Krishnakumar

dblp:195/5558 · DBLP profile ↗
← Back
3ranked-venue papers
2as first author
2since 2021 · last 2026
0000-0002-3817-1548ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author
YearPublicationVenuePosition
2026 POSTER: HASFire - Hardware-Software Co-design for Accurate Packet Filtering at Line-Rate
Arun Krishna AMS, Surya Prasad S, Megna Premkumar, Naveen Babu Devarakonda, Athish Pranav Dharmalingam, Gnanambikai Krishnakumar, Sareena Karapoola
AsiaCCS6
2025 Systematic Analysis of Moving Target Defenses for Branch Prediction Attacks
abstract
While branch predictors play a crucial role in high-performance processors, they are easy targets for micro-architectural attacks. A promising direction to counter these attacks is to randomize the branch predictor's state periodically to create moving targets for the attacker. While such approaches have been successfully applied to mitigate similar attacks in cache memories, applying them in branch predictors offers a unique set of challenges. Unlike cache memories, branch predictors differ widely in architecture. Their proximity to the processor's pipeline requires the countermeasures to be highly efficient to minimize overheads. In this paper, we present a systematic analysis of the moving target countermeasure on branch predictors. To capture different branch predictor architectures, we propose a generic branch predictor model. We use the model to formally define various attack strategies on branch predictors and then use the attack complexities to systematically derive randomization intervals for various mitigation techniques. We then identify the appropriate mitigation to be applied for a branch predictor based on the performance overheads incurred. For evaluation, we instantiate five different branch predictors from the generic predictor model and adapt the attack models and randomization techniques for each predictor. We compute the randomization interval for mitigation strategies and show that the interval intricately depends on the branch predictor architecture and the mitigation technique. We study the performance and area overheads by extending the branch predictor in an OpenRISC processor, enhanced with the randomization countermeasure.
Gnanambikai Krishnakumar, Chester Rebeiro
IEEE Trans. Dependable Secur. Comput.1
2020 ALEXIA: A Processor with Lightweight Extensions for Memory Safety
abstract
Illegal use of memory pointers is a serious security vulnerability. A large number of malwares exploit the spatial and temporal nature of these vulnerabilities to subvert execution or glean sensitive data from an application. Recent countermeasures attach metadata to memory pointers, which define the pointer’s capabilities. The metadata is used by the hardware to validate pointer-based memory accesses. However, recent works have considerable overheads. Further, the pointer validation is decoupled from the actual memory access. We show that this could open up vulnerabilities in multithreaded applications and introduce new vulnerabilities due to speculation in out-of-order processors. In this article, we demonstrate that the overheads can be reduced considerably by efficient metadata management. We show that the hardware can be designed in a manner that would remain safe in multithreaded applications and immune to speculative vulnerabilities. We achieve these by ensuring that the pointer validations and the corresponding memory access is always done atomically and in order. To evaluate our scheme, which we call ALEXIA, we enhance an OpenRISC processor to perform the memory validation at runtime and also add compiler support. ALEXIA is the first hardware countermeasure scheme for memory protection that provides such an end-to-end solution. We evaluate the processor on an Altera FPGA and show that the runtime overhead, on average, is 14%, with negligible impact on the processor’s size and clock frequency. There is also a negligible impact on the program’s code and data sizes.
Gnanambikai Krishnakumar, Kommuru Alekhya Reddy, Chester Rebeiro
ACM Trans. Embed. Comput. Syst.1