Collected research
ASLR on the Line: Practical Cache Attacks on the MMU
Page-table walks by the memory management unit leave the page tables themselves in the shared last-level cache, so an EVICT+TIME attack on those cache lines reveals which entries a victim used and derandomizes its virtual addresses. It needs only ordinary memory accesses, so plain JavaScript broke code and heap ASLR in two browsers in about 150 seconds, on Intel, ARM and AMD alike.
Record
- Researcher
- Ben Gras, Kaveh Razavi, Erik Bosman, Herbert Bos and Cristiano Giuffrida
- Published by
- NDSS Symposium
- Topic
- Other
In the archive
Related sources
- NDSS 2017: ASLR on the Line: Practical Cache Attacks on the MMU
- NDSS 2017: ASLR on the Line: Practical Cache Attacks on the MMU
Tags
This page is the archive's own catalogue record. The research is the work of Ben Gras, Kaveh Razavi, Erik Bosman, Herbert Bos and Cristiano Giuffrida, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .