{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:09:24Z","timestamp":1750219764288,"version":"3.41.0"},"reference-count":18,"publisher":"Association for Computing Machinery (ACM)","issue":"12","license":[{"start":{"date-parts":[[2024,11,22]],"date-time":"2024-11-22T00:00:00Z","timestamp":1732233600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"DARPA","award":["HR0011-20-C-0039"],"award-info":[{"award-number":["HR0011-20-C-0039"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Commun. ACM"],"published-print":{"date-parts":[[2024,12]]},"abstract":"<jats:p>\n            Side-channel attacks, such as Spectre, rely on properties of modern CPUs that permit discovery of microarchitectural state via timing of various operations. The Weird Machine concept is an increasingly popular model for characterization of execution that emerges from side-effects of conventional computing constructs. In this work we introduce Microarchitectural Weird Machines (\n            <jats:inline-formula>\n              <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\" display=\"inline\">\n                <mml:mi>\u03bc<\/mml:mi>\n              <\/mml:math>\n            <\/jats:inline-formula>\n            WMs): code constructions that allow performing computation through the means of side effects and conflicts between microarchitectual entities such as branch predictors and caches. The results of such computations are observed as timing variations in the execution of instructions that interact with these side effects. We demonstrate how\n            <jats:inline-formula>\n              <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\" display=\"inline\">\n                <mml:mi>\u03bc<\/mml:mi>\n              <\/mml:math>\n            <\/jats:inline-formula>\n            WMs can be used as a powerful obfuscation engine where computation operates using events unobservable to conventional anti-obfuscation tools based on emulation, debugging, static and dynamic analysis techniques. We present a practical example in which we use a\n            <jats:inline-formula>\n              <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\" display=\"inline\">\n                <mml:mi>\u03bc<\/mml:mi>\n              <\/mml:math>\n            <\/jats:inline-formula>\n            WM to obfuscate malware code such that its passive operation is invisible to an observer with full power to view the architectural state of the system until the code receives a trigger. When the trigger is received the malware decrypts and executes its payload. To show the effectiveness of obfuscation we demonstrate its use in the concealment and subsequent execution of a payload that creates a reverse shell. In the full version of this work we also demonstrate a payload that exfiltrates a shadow password file. We then demonstrate the generality of\n            <jats:inline-formula>\n              <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\" display=\"inline\">\n                <mml:mi>\u03bc<\/mml:mi>\n              <\/mml:math>\n            <\/jats:inline-formula>\n            WMs by showing that they can be used to reliably perform non-trivial computation by implementing a SHA-1 hash function.\n          <\/jats:p>","DOI":"10.1145\/3610722","type":"journal-article","created":{"date-parts":[[2024,11,22]],"date-time":"2024-11-22T15:47:32Z","timestamp":1732290452000},"page":"87-95","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Computing with Time: Microarchitectural Weird Machines"],"prefix":"10.1145","volume":"67","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9758-0712","authenticated-orcid":false,"given":"Thomas S.","family":"Benjamin","sequence":"first","affiliation":[{"name":"Peraton Labs, Basking Ridge, NJ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jeffery A.","family":"Eitel","sequence":"additional","affiliation":[{"name":"Peraton Labs, Basking Ridge, NJ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jesse","family":"Elwell","sequence":"additional","affiliation":[{"name":"Peraton Labs, Basking Ridge, NJ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dmitry","family":"Evtyushkin","sequence":"additional","affiliation":[{"name":"William and Mary, Williamsburg, VA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Abhrajit","family":"Ghosh","sequence":"additional","affiliation":[{"name":"Meta Platforms, Inc., Menlo Park, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Angelo","family":"Sapello","sequence":"additional","affiliation":[{"name":"Peraton Labs, Basking Ridge, NJ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,11,22]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/LICS.2001.932501"},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/3182657"},{"key":"e_1_3_1_4_2","unstructured":"Bangert J. Bratus S. Shapiro R. and Smith S.W. The page-fault weird machine: Lessons in instruction-less computation. Presented as part of the\u00a0USENIX Workshop on Offensive Technologies 2013; https:\/\/www.cs.dartmouth.edu\/~sergey\/wm\/woot13-bangert.pdf."},{"issue":"2015","key":"e_1_3_1_5_2","first-page":"757","article-title":"Different obfuscation techniques for code protection","volume":"70","author":"Behera C.K.","unstructured":"Behera, C.K. and Lalitha Bhaskari, D. Different obfuscation techniques for code protection. Procedia\u00a0Computer\u00a0Science, 70, 2015, 757\u2013763.","journal-title":"Procedia\u00a0Computer\u00a0Science"},{"key":"e_1_3_1_6_2","unstructured":"Benjamin T. et al. Weird circuits in CPU microarchitectures. Presentation the\u00a0Sixth\u00a0Workshop\u00a0on\u00a0Language-Theoretic\u00a0Security\u00a0(Langsec) 2020; http:\/\/spw20.langsec.org\/slides\/WeirdCircuits_LangSec2020.pdf Accessed: 2020-12-18."},{"key":"e_1_3_1_7_2","first-page":"291","article-title":"Address obfuscation: An efficient approach to combat a broad range of memory error exploits","volume":"12","author":"Bhatkar S.","year":"2003","unstructured":"Bhatkar, S., DuVarney, D.C., and Sekar, R. Address obfuscation: An efficient approach to combat a broad range of memory error exploits. In USENIX\u00a0Security\u00a0Symp. 12, (2003), 291\u2013301.","journal-title":"USENIX\u00a0Security\u00a0Symp."},{"key":"e_1_3_1_8_2","unstructured":"Bratus S. What\u00a0Are\u00a0Weird\u00a0Machines?; https:\/\/www.cs.dartmouth.edu\/~sergey\/wm\/. Accessed: 2020-12-18."},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/WiSPNET.2017.8299877"},{"key":"e_1_3_1_10_2","unstructured":"Dullien T.F. Weird machines exploitability and provable unexploitability. IEEE\u00a0Transactions\u00a0on\u00a0Emerging\u00a0Topics\u00a0in\u00a0Computing 2017."},{"key":"e_1_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2016.7783743"},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/3296957.3173204"},{"key":"e_1_3_1_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.30"},{"key":"e_1_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.1007\/10721959_2"},{"key":"e_1_3_1_15_2","unstructured":"Oakley J. and Bratus S. Exploiting the hard-working dwarf: Trojan and exploit techniques with no native executable code. In WOOT 2011 91\u2013102."},{"key":"e_1_3_1_16_2","doi-asserted-by":"crossref","unstructured":"Schwarz M. et al. Zombieload: Cross-privilege-boundary data sampling. In Proceedings\u00a0of\u00a0the\u00a02019\u00a0ACM\u00a0SIGSAC\u00a0Conf.\u00a0On\u00a0Computer\u00a0and\u00a0Communications\u00a0Security 2019 753\u2013768.","DOI":"10.1145\/3319535.3354252"},{"key":"e_1_3_1_17_2","unstructured":"Shapiro R. Bratus S. and Smith S.W. \u201cweird machines\u201d in elf: A spotlight on the underappreciated metadata. Presented as part of the\u00a0USENIX Workshop on Offensive Technologies 2013; https:\/\/www.cs.dartmouth.edu\/~sergey\/wm\/woot13-shapiro.pdf."},{"key":"e_1_3_1_18_2","unstructured":"Sharif M.I. Lanzi A. Giffin J.T. and Lee W. Impeding malware analysis using conditional code obfuscation. In NDSS 2008."},{"key":"e_1_3_1_19_2","doi-asserted-by":"publisher","DOI":"10.1007\/s41635-018-0046-1"}],"container-title":["Communications of the ACM"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3610722","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3610722","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:37:11Z","timestamp":1750178231000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3610722"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,22]]},"references-count":18,"journal-issue":{"issue":"12","published-print":{"date-parts":[[2024,12]]}},"alternative-id":["10.1145\/3610722"],"URL":"https:\/\/doi.org\/10.1145\/3610722","relation":{},"ISSN":["0001-0782","1557-7317"],"issn-type":[{"type":"print","value":"0001-0782"},{"type":"electronic","value":"1557-7317"}],"subject":[],"published":{"date-parts":[[2024,11,22]]},"assertion":[{"value":"2024-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}