{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T15:10:05Z","timestamp":1755961805901,"version":"3.44.0"},"reference-count":42,"publisher":"Association for Computing Machinery (ACM)","issue":"3","funder":[{"DOI":"10.13039\/501100000269","name":"Economic and Social Research Council","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100000269","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Priv. Secur."],"published-print":{"date-parts":[[2025,8,31]]},"abstract":"<jats:p>\n            This article explores the software security potential of ARM\u2019s Morello experimental hardware platform, an embodiment of the Capability Hardware Enhanced RISC Instructions (CHERI) model. We navigate the intricacies of Morello adoption, uncovering both the promise and the challenges it presents for bolstering software security assurance. Employing the Juliet Test Suite, we conduct a rigorous security assessment of Morello\u2019s operational modes\u2014Purecap and Hybrid\u2014shedding light on the ramifications for the software development lifecycle and assurance processes. Our findings affirm the robust spatial safety Morello confers, especially in its Purecap mode, while also underscoring the persisting temporal vulnerabilities in the CheriBSD\n            <jats:italic toggle=\"yes\">version used<\/jats:italic>\n            in our experiments. We discuss the novel challenges associated with Morello adoption, including the management of CHERI violation exceptions, the imperative of software-hardware co-validation, and the specialized training requisites for development and assurance teams. We draw attention to potential risks, like crashes from CHERI violations potentially metamorphosing into Denial of Service (DoS) attacks. Transitioning to the Morello model could necessitate substantial alterations in software design principles, development methodologies, and security assurance protocols.\n          <\/jats:p>","DOI":"10.1145\/3728360","type":"journal-article","created":{"date-parts":[[2025,4,7]],"date-time":"2025-04-07T07:29:23Z","timestamp":1744010963000},"page":"1-41","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Security Implications of the Morello Platform: An Empirical Threat Model-Based Analysis"],"prefix":"10.1145","volume":"28","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5332-2914","authenticated-orcid":false,"given":"Sami","family":"Ullah","sequence":"first","affiliation":[{"name":"Department of Computer Science, University of Bristol","place":["Bristol, United Kingdom of Great Britain and Northern Ireland"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0109-1341","authenticated-orcid":false,"given":"Awais","family":"Rashid","sequence":"additional","affiliation":[{"name":"Depart of Computer Science, University of Bristol","place":["Bristol, United Kingdom of Great Britain and Northern Ireland"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,8,23]]},"reference":[{"key":"e_1_3_3_2_2","first-page":"174","volume-title":"European Symposium on Programming","author":"Bauereiss Thomas","year":"2022","unstructured":"Thomas Bauereiss, Brian Campbell, Thomas Sewell, Alasdair Armstrong, Lawrence Esswood, Ian Stark, Graeme Barnes, Robert N. M. Watson, and Peter Sewell. 2022. Verified security for the Morello capability-enhanced prototype Arm architecture. In European Symposium on Programming. Springer International Publishing, Cham, 174\u2013203."},{"issue":"6","key":"e_1_3_3_3_2","doi-asserted-by":"crossref","first-page":"158","DOI":"10.1145\/1133255.1134000","article-title":"DieHard: Probabilistic memory safety for unsafe languages","volume":"41","author":"Berger Emery D.","year":"2006","unstructured":"Emery D. Berger and Benjamin G. Zorn. 2006. DieHard: Probabilistic memory safety for unsafe languages. ACM SIGPLAN Not. 41, 6 (2006), 158\u2013168.","journal-title":"ACM SIGPLAN Not."},{"key":"e_1_3_3_4_2","first-page":"1","volume-title":"23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID\u201920)","author":"Bhattacharyya Atri","year":"2020","unstructured":"Atri Bhattacharyya, Andr\u00e9s S\u00e1nchez, Esmaeil M. Koruyeh, Nael Abu-Ghazaleh, Chengyu Song, and Mathias Payer. 2020. SpecROP: Speculative exploitation of ROP chains. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID\u201920). 1\u201316."},{"key":"e_1_3_3_5_2","unstructured":"Joe Bialek Ken Johnson and Matt Miller. 2022. Security analysis of memory tagging. Retrieved from https:\/\/github.com\/microsoft\/MSRC-Security-Research\/blob\/master\/papers\/2020\/Security_analysis_of_memory_tagging.pdf"},{"key":"e_1_3_3_6_2","first-page":"133","volume-title":"International Symposium on Software Testing and Analysis","author":"Caballero Juan","year":"2012","unstructured":"Juan Caballero, Gustavo Grieco, Mark Marron, and Antonio Nappa. 2012. Undangle: Early detection of dangling pointers in use-after-free and double-free vulnerabilities. In International Symposium on Software Testing and Analysis. 133\u2013143."},{"key":"e_1_3_3_7_2","first-page":"146","volume-title":"USENIX Security Symposium","author":"Chen Shuo","year":"2005","unstructured":"Shuo Chen, Jun Xu, Emre Can Sezer, Prachi Gauriar, and Ravishankar K. Iyer. 2005. Non-control-data attacks are realistic threats. In USENIX Security Symposium, Vol. 5. 146."},{"key":"e_1_3_3_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/2786763.2694367"},{"key":"e_1_3_3_9_2","unstructured":"MITRE Corporation. 2023. CWE top 25 Most dangerous software weaknesses. Retrieved from https:\/\/cwe.mitre.org\/top25\/archive\/2023\/2023_top25_list.html"},{"key":"e_1_3_3_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/DISCEX.2000.821514"},{"key":"e_1_3_3_11_2","first-page":"83","volume-title":"USENIX Security Symposium","author":"Criswell John","year":"2009","unstructured":"John Criswell, Nicolas Geoffray, and Vikram S. Adve. 2009. Memory safety for low-level software\/hardware interactions. In USENIX Security Symposium. 83\u2013100."},{"key":"e_1_3_3_12_2","first-page":"379","volume-title":"24th International Conference on Architectural Support for Programming Languages and Operating Systems","author":"Davis Brooks","year":"2019","unstructured":"Brooks Davis, Robert N. M. Watson, Alexander Richardson, Peter G. Neumann, Simon W. Moore, John Baldwin, David Chisnall, Jessica Clarke, Nathaniel Wesley Filardo, Khilan Gudka et\u00a0al. 2019. CheriABI: Enforcing valid pointer provenance and minimizing pointer privilege in the POSIX C run-time environment. In 24th International Conference on Architectural Support for Programming Languages and Operating Systems. 379\u2013393."},{"key":"e_1_3_3_13_2","first-page":"69","volume-title":"ACM SIGPLAN Conference on Language, Compiler, and Tool for Embedded Systems","author":"Dhurjati Dinakar","year":"2003","unstructured":"Dinakar Dhurjati, Sumant Kowshik, Vikram Adve, and Chris Lattner. 2003. Memory safety without runtime checks or garbage collection. In ACM SIGPLAN Conference on Language, Compiler, and Tool for Embedded Systems. 69\u201380."},{"key":"e_1_3_3_14_2","first-page":"608","volume-title":"IEEE Symposium on Security and Privacy (SP\u201920)","author":"Filardo Nathaniel Wesley","year":"2020","unstructured":"Nathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Sam Ainsworth, Lucian Paul-Trifu, Brooks Davis, Hongyan Xia, Edward Tomasz Napierala, Alexander Richardson, John Baldwin et\u00a0al. 2020. Cornucopia: Temporal safety for CHERI heaps. In IEEE Symposium on Security and Privacy (SP\u201920). IEEE, 608\u2013625."},{"key":"e_1_3_3_15_2","first-page":"2373","volume-title":"ACM SIGSAC Conference on Computer and Communications Security","author":"Jeon Yuseok","year":"2017","unstructured":"Yuseok Jeon, Priyam Biswas, Scott Carr, Byoungyoung Lee, and Mathias Payer. 2017. HexType: Efficient detection of type confusion errors for C++. In ACM SIGSAC Conference on Computer and Communications Security. 2373\u20132387."},{"key":"e_1_3_3_16_2","unstructured":"Joe Bialek. 2022. CastGuard. Retrieved from https:\/\/github.com\/microsoft\/MSRC-Security-Research\/blob\/master\/presentations\/2022_08_BlackHatUSA\/CastGuard_Blackhat_2022.pdf"},{"key":"e_1_3_3_17_2","unstructured":"Nicolas Joly Saif ElSherei and Saar Amar. 2020. Security analysis of CHERI ISA. Retrieved July 6 (2020) 2021."},{"key":"e_1_3_3_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948146"},{"key":"e_1_3_3_19_2","unstructured":"Kaspersky Lab. 2022. The potential dangers of memory vulnerabilities. Retrieved from https:\/\/www.kaspersky.com\/blog\/memory-vulnerabilities\/42342\/"},{"key":"e_1_3_3_20_2","volume-title":"Network and Distributed System Security Symposium (NDSS\u201915)","author":"Lee Byoungyoung","year":"2015","unstructured":"Byoungyoung Lee, Chengyu Song, Yeongjin Jang, Tielei Wang, Taesoo Kim, Long Lu, and Wenke Lee. 2015. Preventing use-after-free with dangling pointers nullification. In Network and Distributed System Security Symposium (NDSS\u201915)."},{"key":"e_1_3_3_21_2","doi-asserted-by":"publisher","DOI":"10.1002\/spe.515"},{"key":"e_1_3_3_22_2","unstructured":"Arm Limited. 2023. Arm GNU toolchain for Morello downloads. Retrieved from https:\/\/developer.arm.com\/downloads\/-\/arm-gnu-toolchain-for-morello-downloads"},{"key":"e_1_3_3_23_2","unstructured":"Arm Limited. 2023. CHERIseed. Retrieved from https:\/\/www.morello-project.org\/"},{"key":"e_1_3_3_24_2","first-page":"1963","volume-title":"ACM SIGSAC Conference on Computer and Communications Security","author":"Lin Zhenpeng","year":"2022","unstructured":"Zhenpeng Lin, Yuhang Wu, and Xinyu Xing. 2022. DirtyCred: Escalating privilege in Linux kernel. In ACM SIGSAC Conference on Computer and Communications Security. 1963\u20131976."},{"key":"e_1_3_3_25_2","doi-asserted-by":"publisher","DOI":"10.1145\/3617651.3622991"},{"key":"e_1_3_3_26_2","first-page":"280","volume-title":"22nd ACM SIGSAC Conference on Computer and Communications Security","author":"Lu Kangjie","year":"2015","unstructured":"Kangjie Lu, Chengyu Song, Byoungyoung Lee, Simon P. Chung, Taesoo Kim, and Wenke Lee. 2015. ASLR-Guard: Stopping address space leakage for code reuse attacks. In 22nd ACM SIGSAC Conference on Computer and Communications Security. 280\u2013291."},{"key":"e_1_3_3_27_2","article-title":"Trends and challenges in the vulnerability mitigation landscape","author":"Miller Matt","year":"2019","unstructured":"Matt Miller. 2019. Trends and challenges in the vulnerability mitigation landscape. In 13th USENIX Workshop on Offensive Technologies. USENIX Association.","journal-title":"13th USENIX Workshop on Offensive Technologies. USENIX Association"},{"issue":"3","key":"e_1_3_3_28_2","doi-asserted-by":"crossref","first-page":"189","DOI":"10.1145\/2366231.2337181","article-title":"Watchdog: Hardware for safe and secure manual memory management and full memory safety","volume":"40","author":"Nagarakatte Santosh","year":"2012","unstructured":"Santosh Nagarakatte, Milo M. K. Martin, and Steve Zdancewic. 2012. Watchdog: Hardware for safe and secure manual memory management and full memory safety. ACM SIGARCH Comput. Archit. News 40, 3 (2012), 189\u2013200.","journal-title":"ACM SIGARCH Comput. Archit. News"},{"key":"e_1_3_3_29_2","unstructured":"Tim Newsham. 2000. Format String Attacks. (2000)."},{"key":"e_1_3_3_30_2","article-title":"Intel MPX explained: An empirical study of intel MPX and software-based bounds checking approaches","author":"Oleksenko Oleksii","year":"2017","unstructured":"Oleksii Oleksenko, Dmitrii Kuvaiskii, Pramod Bhatotia, Pascal Felber, and Christof Fetzer. 2017. Intel MPX explained: An empirical study of intel MPX and software-based bounds checking approaches. arXiv preprint arXiv:1702.00719 (2017).","journal-title":"arXiv preprint arXiv:1702.00719"},{"key":"e_1_3_3_31_2","volume-title":"Complete Spatial Safety for C and C++ Using CHERI Capabilities","author":"Richardson Alexander","year":"2020","unstructured":"Alexander Richardson. 2020. Complete Spatial Safety for C and C++ Using CHERI Capabilities. Technical Report. University of Cambridge, Computer Laboratory."},{"key":"e_1_3_3_32_2","doi-asserted-by":"publisher","DOI":"10.5555\/1098700"},{"key":"e_1_3_3_33_2","article-title":"Memory tagging and how it improves C\/C++ memory safety","author":"Serebryany Kostya","year":"2018","unstructured":"Kostya Serebryany, Evgenii Stepanov, Aleksey Shlyapnikov, Vlad Tsyrklevich, and Dmitry Vyukov. 2018. Memory tagging and how it improves C\/C++ memory safety. arXiv preprint arXiv:1802.09517 (2018).","journal-title":"arXiv preprint arXiv:1802.09517"},{"key":"e_1_3_3_34_2","volume-title":"Accepted for publication in the IEEE Symposium on Security and Privacy (EuroS&P\u201924)","author":"Ullah Sami","year":"2024","unstructured":"Sami Ullah and Awais Rashid. 2024. Porting to Morello: An in-depth study on compiler behaviors, CERT guideline violations, and security implications. In Accepted for publication in the IEEE Symposium on Security and Privacy (EuroS&P\u201924). IEEE. Accepted for publication."},{"key":"e_1_3_3_35_2","unstructured":"Perry Wagle and Crispin Cowan. 2003. Stackguard: Simple stack smash protection for GCC. In Proceedings of the GCC Developers Summit. 243\u2013255."},{"key":"e_1_3_3_36_2","volume-title":"An Introduction to CHERI","author":"Watson Robert N. M.","year":"2019","unstructured":"Robert N. M. Watson, Simon W. Moore, Peter Sewell, and Peter G. Neumann. 2019. An Introduction to CHERI. Technical Report. University of Cambridge, Computer Laboratory."},{"key":"e_1_3_3_37_2","volume-title":"Capability Hardware Enhanced RISC Instructions: CHERI Instruction-set Architecture (Version 7)","author":"Watson Robert N. M.","year":"2019","unstructured":"Robert N. M. Watson, Peter G. Neumann, Jonathan Woodruff, Michael Roe, Hesham Almatary, Jonathan Anderson, John Baldwin, David Chisnall, Brooks Davis, Nathaniel Wesley Filardo et\u00a0al. 2019. Capability Hardware Enhanced RISC Instructions: CHERI Instruction-set Architecture (Version 7). Technical Report. University of Cambridge, Computer Laboratory."},{"key":"e_1_3_3_38_2","volume-title":"CHERI C\/C++ Programming Guide","author":"Watson Robert N. M.","year":"2020","unstructured":"Robert N. M. Watson, Alexander Richardson, Brooks Davis, John Baldwin, David Chisnall, Jessica Clarke, Nathaniel Filardo, Simon W. Moore, Edward Napierala, Peter Sewell et\u00a0al. 2020. CHERI C\/C++ Programming Guide. Technical Report. University of Cambridge, Computer Laboratory."},{"key":"e_1_3_3_39_2","doi-asserted-by":"publisher","unstructured":"Robert N. M. Watson Jonathan Woodruff Alexandre Joannou Simon W. Moore Peter Sewell and Arm Limited. 2020. DSbD CHERI and Morello Capability Essential IP (Version 1). University of Cambridge Computer Laboratory. DOI:10.48456\/tr-953","DOI":"10.48456\/tr-953"},{"key":"e_1_3_3_40_2","first-page":"20","volume-title":"IEEE Symposium on Security and Privacy","author":"Watson Robert N. M.","year":"2015","unstructured":"Robert N. M. Watson, Jonathan Woodruff, Peter G. Neumann, Simon W. Moore, Jonathan Anderson, David Chisnall, Nirav Dave, Brooks Davis, Khilan Gudka, Ben Laurie et\u00a0al. 2015. CHERI: A hybrid capability-system architecture for scalable software compartmentalization. In IEEE Symposium on Security and Privacy. IEEE, 20\u201337."},{"key":"e_1_3_3_41_2","volume-title":"Capability Hardware Enhanced RISC Instructions (CHERI): Notes on the Meltdown and Spectre Attacks","author":"Watson Robert N. M.","year":"2018","unstructured":"Robert N. M. Watson, Jonathan Woodruff, Michael Roe, Simon W. Moore, and Peter G. Neumann. 2018. Capability Hardware Enhanced RISC Instructions (CHERI): Notes on the Meltdown and Spectre Attacks. Technical Report. University of Cambridge, Computer Laboratory."},{"issue":"3","key":"e_1_3_3_42_2","doi-asserted-by":"crossref","first-page":"457","DOI":"10.1145\/2678373.2665740","article-title":"The CHERI capability model: Revisiting RISC in an age of risk","volume":"42","author":"Woodruff Jonathan","year":"2014","unstructured":"Jonathan Woodruff, Robert N. M. Watson, David Chisnall, Simon W. Moore, Jonathan Anderson, Brooks Davis, Ben Laurie, Peter G. Neumann, Robert Norton, and Michael Roe. 2014. The CHERI capability model: Revisiting RISC in an age of risk. ACM SIGARCH Comput. Archit. News 42, 3 (2014), 457\u2013468.","journal-title":"ACM SIGARCH Comput. Archit. News"},{"key":"e_1_3_3_43_2","first-page":"283","volume-title":"IEEE\/ACM 39th International Conference on Software Engineering: Software Engineering in Practice Track (ICSE-SEIP\u201917)","author":"Wu Jingzheng","year":"2017","unstructured":"Jingzheng Wu, Shen Liu, Shouling Ji, Mutian Yang, Tianyue Luo, Yanjun Wu, and Yongji Wang. 2017. Exception beyond exception: Crashing Android system by trapping in \u201cUncaught Exception.\u201d In IEEE\/ACM 39th International Conference on Software Engineering: Software Engineering in Practice Track (ICSE-SEIP\u201917). IEEE, 283\u2013292."}],"container-title":["ACM Transactions on Privacy and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3728360","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T14:47:40Z","timestamp":1755960460000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3728360"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,23]]},"references-count":42,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2025,8,31]]}},"alternative-id":["10.1145\/3728360"],"URL":"https:\/\/doi.org\/10.1145\/3728360","relation":{},"ISSN":["2471-2566","2471-2574"],"issn-type":[{"type":"print","value":"2471-2566"},{"type":"electronic","value":"2471-2574"}],"subject":[],"published":{"date-parts":[[2025,8,23]]},"assertion":[{"value":"2024-01-05","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-02-24","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-08-23","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}