Calibração de Latência Microarquitetural: Uma Abordagem Baseada em Serialização de Instruções e Compensação de Drift

Resumo


Este trabalho apresenta uma metodologia para calibração automática de latências de cache, eliminando ajustes manuais e empíricos em ataques de canal lateral. A abordagem utiliza instruções de serialização e o Time Stamp Counter (TSC) para garantir medições precisas no espaço de usuário. O diferencial reside no isolamento sistemático dos níveis de cache e na compensação de data drift frente a flutuações de frequência da CPU. Resultados em hardware moderno confirmam a eficácia do método ao atingir conformidade com os valores encontrados da literatura.

Referências

(2023). Intel® 64 and IA-32 Architectures Optimization Reference Manual. Intel Corporation, Santa Clara, CA. Volume 1: Basic Architecture. Available at: [link].

Abel, A. and Reineke, J. (2020). nanobench: A low-overhead tool for running micro-benchmarks on x86 systems. In 2020 IEEE International Symposium on Performance Analysis of Systems and Software (ISPASS), pages 34–46. IEEE.

Advanced Micro Devices, Inc. Amd uprof performance analysis tool. [link]. Accessed: 2026-05-07.

Ghaemi, G., Franco, G., Taram, K., and Mancuso, R. (2025). Memscope: Open-source kernel-level framework for heterogeneous memory characterization. In 2025 IEEE Real-Time Systems Symposium (RTSS), pages 500–513. IEEE.

Gorman, M. (2004). Understanding the Linux virtual memory manager, volume 352. Prentice Hall Upper Saddle River.

Intel Corporation. Intel 64 and ia-32 architectures software developer’s manual. [link]. Combined volumes. Accessed: 2026-05-07.

Intel Corporation. Intel 64 and ia-32 architectures software developer’s manual, volume 3: Performance monitoring. [link]. Accessed: 2026-05-07.

Intel Corporation. Intel performance counter monitor (pcm). [link]. Accessed: 2026-05-07.

Intel Corporation. Intel vtune profiler. [link]. Accessed: 2026-05-07.

Irazoqui, G., Eisenbarth, T., and Sunar, B. (2015). Systematic reverse engineering of cache slice selection in intel processors. In 2015 Euromicro Conference on Digital System Design, pages 629–636. IEEE.

Kocher, P., Horn, J., Fogh, A., Genkin, D., Gruss, D., Haas, W., Hamburg, M., Lipp, M., Mangard, S., Prescher, T., et al. (2020). Spectre attacks: Exploiting speculative execution. Communications of the ACM, 63(7):93–101.

Levinthal, D. Performance analysis guide for intel® core™ i7 processor and intel® xeon™ 5500 processors. . Acessed: 2026-05-07.

Linux Kernel Developers. perf: Linux profiling with performance counters. [link]. Accessed: 2026-05-07.

LinuxVox (2023). Linux zero page: Understanding the kernel’s memory optimization. Accessed: 2026-05-07.

Lipp, M., Schwarz, M., Gruss, D., Prescher, T., Haas, W., Horn, J., Mangard, S., Kocher, P., Genkin, D., Yarom, Y., et al. (2020). Meltdown: Reading kernel memory from user space. Communications of the ACM, 63(6):46–56.

Mittal, S. (2016). A survey of recent prefetching techniques for processor caches. ACM Computing Surveys (CSUR), 49(2):1–35.

Paccagnella, R., Luo, L., and Fletcher, C. W. (2021). Lord of the ring(s): Side channel attacks on the CPU On-Chip ring interconnect are practical. In 30th USENIX Security Symposium (USENIX Security 21), pages 645–662. USENIX Association.

Paoloni, G. (2010). How to benchmark code execution times on intel ia-32 and ia-64 instruction set architectures. Intel Corporation, 123(170).

Patterson, D. A. and Hennessy, J. L. (2016). Computer organization and design ARM edition: the hardware software interface. Morgan kaufmann.

Prathap, S. and others. Isolbench: A set of micro-benchmarks for evaluating multicore isolation. [link]. GitHub repository, Accessed: 2026-05-07.

Shen, C., Chen, C., and Zhang, J. (2021). Micro-architectural cache side-channel attacks and countermeasures. In Proceedings of the 26th Asia and South Pacific Design Automation Conference, pages 441–448.

Silberschatz, A., Galvin, P. B., and Gagne, G. (2019). Operating system concepts. John Wiley & Sons.

Valsan, P. K., Yun, H., and Farshchi, F. (2016). Taming non-blocking caches to improve isolation in multicore real-time systems. In 2016 IEEE Real-Time and Embedded Technology and Applications Symposium (RTAS), pages 1–12. IEEE.

Van Schaik, S., Milburn, A., Österlund, S., Frigo, P., Maisuradze, G., Razavi, K., Bos, H., and Giuffrida, C. (2019). Ridl: Rogue in-flight data load. In 2019 IEEE Symposium on Security and Privacy (SP), pages 88–105. IEEE.

Wang, Z., Mahar, S., Li, L., Park, J., Kim, J., Michailidis, T., Pan, Y., Rosing, T., Tullsen, D., Swanson, S., et al. (2024). The hitchhiker’s guide to programming and optimizing cxl-based heterogeneous systems. arXiv preprint arXiv:2411.02814.

Wikner, J. and Razavi, K. (2025). Breaking the barrier: Post-barrier spectre attacks. In 2025 IEEE Symposium on Security and Privacy (SP), pages 3516–3533. IEEE.

Yarom, Y. and Falkner, K. (2014). Flush + reload: A high resolution, low noise, l3 cache side-channel attack. In 23rd USENIX security symposium (USENIX security 14), pages 719–732.
Publicado
01/09/2026
GUERRA, Matheus B.; OLIVEIRA, José L. N. C. de; DUTRA, Diego L. C.. Calibração de Latência Microarquitetural: Uma Abordagem Baseada em Serialização de Instruções e Compensação de Drift. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 317-331. DOI: https://doi.org/10.5753/sbseg.2026.26916.