Till Schlüter

dblp:284/0400 · DBLP profile ↗
← Back
4ranked-venue papers
3as first author
3since 2021 · last 2025
0009-0003-0134-7946ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 3 first-author · 3 since 2021
YearPublicationVenuePosition
2025 PreFence: A Fine-Grained and Scheduling-Aware Defense Against Prefetching-Based Attacks
abstract
Speculative loading of memory, called hardware prefetching, is common in modern CPUs and may cause microarchitectural side-channel vulnerabilities. As prior work has shown, prefetching can be exploited to bypass process isolation and leak secrets. However, to this date, no effective and efficient countermeasure has been presented that secures software on affected systems. Often, disabling prefetching permanently is considered the only reasonable defense, despite the significant performance penalties this entails.In this work, we propose PreFence, a fine-grained and scheduling-aware defense against prefetching-based attacks for any platform where the prefetcher can be disabled. PreFence extends the process scheduler to be aware of security requirements of individual processes and to manage the prefetcher’s state to protect against malicious parallel processes, even on SMT-enabled platforms. This allows us to efficiently disable the prefetcher only during security-critical operations, with a single system call. Library and application developers can protect their code with minimal changes, and users can protect entire legacy applications using a wrapper program.We implement our countermeasure for an x86 64 and an ARM processor. We evaluate PreFence on two attacks from prior work and find that it reliably stops prefetch leakage with low performance overhead (less than 3%) on the vulnerable functions. In addition, we observe that PreFence causes only negligible performance impact when no security-relevant code is executed. Finally, we evaluate the performance of a real-world web-server application that uses PreFence to protect security-critical code for HTTPS handling. Compared to disabling the prefetcher permanently, we find that our countermeasure allows the application to significantly benefit from the prefetcher (running up to 15.8% (Intel) and 7.2% (ARM) faster on average), while at the same time achieving the same security.
Till Schlüter, Nils Ole Tippenhauer
EuroS&P1
2023 FetchBench: Systematic Identification and Characterization of Proprietary Prefetchers
abstract
Prefetchers speculatively fetch memory using predictions on future memory use by applications. Different CPUs may use different prefetcher types, and two implementations of the same prefetcher can differ in details of their characteristics, leading to distinct runtime behavior. For a few implementations, security researchers showed through manual analysis how to exploit specific prefetchers to leak data. Identifying such vulnerabilities required tedious reverse-engineering, as prefetcher implementations are proprietary and undocumented. So far, no systematic study of prefetchers in common CPUs is available, preventing further security assessment.
Till Schlüter, Amit Choudhari, Lorenz Hetterich, Leon Trampert, Hamed Nemati, Ahmad Ibrahim 0002, Michael Schwarz 0001, Christian Rossow, Nils Ole Tippenhauer
CCS1
2022 Microarchitectural Leakage Templates and Their Application to Cache-Based Side Channels
abstract
The complexity of modern processor architectures has given rise to sophisticated interactions among their components. Such interactions may result in potential attack vectors in terms of side channels, possibly available to userland exploits to leak secret data. Exploitation and countering of such side channels requires a detailed understanding of the target component. However, such detailed information is commonly unpublished for many CPUs.
Ahmad Ibrahim 0002, Hamed Nemati, Till Schlüter, Nils Ole Tippenhauer, Christian Rossow
CCS3
2020 Differential Analysis and Fingerprinting of ZombieLoads on Block Ciphers
Till Schlüter, Kerstin Lemke-Rust
CARDIS1