{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T01:45:46Z","timestamp":1760060746098,"version":"build-2065373602"},"reference-count":50,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2025,9,17]],"date-time":"2025-09-17T00:00:00Z","timestamp":1758067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>Prior work has shown that Translation Lookaside Buffer (TLB) data contains valuable behavioral information. Many existing methodologies rely on timing features or focus solely on workload classification. In this study, we propose a novel approach to malware classification using only TLB-related Hardware Performance Counters (HPCs), explicitly excluding any dependence on timing features such as task execution duration or memory access timing. Our methodology evaluates whether TLB data alone, without any timing information, can effectively distinguish between malicious and benign programs. We test this across three classification scenarios: (1) A binary classification problem involving distinguishing malicious from benign tasks, (2) a 4-way classification problem designed to improve separability, and (3) a 10-way classification problem with classes of individual benign and malware tasks. Our results demonstrate that even without execution time or memory access timing, TLB events achieve up to 81% accuracy for the binary, and 72% accuracy for the 4-class grouping, and 61% accuracy for the 10-class grouping. These findings demonstrate that time-independent TLB patterns can serve as robust behavioral signatures. This work expands the understanding of microarchitectural side effects by demonstrating that TLB-only features, independent of timing-based techniques, can be effectively used for real-world malware detection.<\/jats:p>","DOI":"10.3390\/jcp5030075","type":"journal-article","created":{"date-parts":[[2025,9,17]],"date-time":"2025-09-17T08:03:47Z","timestamp":1758096227000},"page":"75","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Microarchitectural Malware Detection via Translation Lookaside Buffer (TLB) Events"],"prefix":"10.3390","volume":"5","author":[{"given":"Cristian","family":"Agredo","sequence":"first","affiliation":[{"name":"Air Force Institute of Technology, 2950 Hobson Way, Wright-Patterson AFB, OH 45433, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6477-2646","authenticated-orcid":false,"given":"Daniel F.","family":"Koranek","sequence":"additional","affiliation":[{"name":"Air Force Institute of Technology, 2950 Hobson Way, Wright-Patterson AFB, OH 45433, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christine M. Schubert","family":"Kabban","sequence":"additional","affiliation":[{"name":"Air Force Institute of Technology, 2950 Hobson Way, Wright-Patterson AFB, OH 45433, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jose A. Gutierrez del","family":"Arroyo","sequence":"additional","affiliation":[{"name":"Air Force Institute of Technology, 2950 Hobson Way, Wright-Patterson AFB, OH 45433, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Scott R.","family":"Graham","sequence":"additional","affiliation":[{"name":"Air Force Institute of Technology, 2950 Hobson Way, Wright-Patterson AFB, OH 45433, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,9,17]]},"reference":[{"key":"ref_1","unstructured":"Hennessy, J.L., and Patterson, D.A. (2017). Computer Architecture: A Quantitative Approach, Morgan Kaufmann Publishers Inc.. [6th ed.]."},{"key":"ref_2","unstructured":"Disselkoen, C., Kohlbrenner, D., Porter, L., and Tullsen, D. (2017, January 16\u201318). Prime+Abort: A Timer-Free High-Precision L3 Cache Attack Using Intel TSX. Proceedings of the 26th USENIX Security Symposium (USENIX Security 17), Vancouver, BC, Canada."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"93","DOI":"10.1145\/3399742","article-title":"Spectre attacks: Exploiting speculative execution","volume":"63","author":"Kocher","year":"2020","journal-title":"Commun. ACM"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"46","DOI":"10.1145\/3357033","article-title":"Meltdown: Reading kernel memory from user space","volume":"63","author":"Lipp","year":"2020","journal-title":"Commun. ACM"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Liu, F., Yarom, Y., Ge, Q., Heiser, G., and Lee, R.B. (2015, January 17\u201321). Last-level cache side-channel attacks are practical. Proceedings of the 2015 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2015.43"},{"key":"ref_6","unstructured":"Yarom, Y., and Falkner, K. (2014, January 20\u201322). Flush+ Reload: A High Resolution, Low Noise, L3 Cache Side-Channel Attack. Proceedings of the USENIX Security Symposium, San Diego, CA, USA."},{"key":"ref_7","unstructured":"Percival, C. (2005, January 13\u201314). Cache missing for fun and profit. Proceedings of the Free BSD Presentations and Papers (2005), Ottawa, ON, Canada."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/11605805_1","article-title":"Cache Attacks and Countermeasures: The Case of AES","volume":"Volume 3860","author":"Hutchison","year":"2006","journal-title":"Topics in Cryptology\u2014CT-RSA 2006"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Gullasch, D., Bangerter, E., and Krenn, S. (2011, January 22\u201325). Cache Games\u2013Bringing Access-Based Cache Attacks on AES to Practice. Proceedings of the Security and Privacy (SP), 2011 IEEE Symposium On, Oakland, CA, USA.","DOI":"10.1109\/SP.2011.22"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"111199","DOI":"10.1109\/ACCESS.2025.3583115","article-title":"Exploring the Translation Lookaside Buffer (TLB) for Low-Level Task Differentiation and Classification","volume":"13","author":"Agredo","year":"2025","journal-title":"IEEE Access"},{"key":"ref_11","unstructured":"Braun, B.A., Jana, S., and Boneh, D. (2015). Robust and efficient elimination of cache and timing side channels. arXiv."},{"key":"ref_12","unstructured":"Gruss, D., Schuster, F., Ohrimenko, O., Haller, I., Lettner, J., and Costa, M. (2017, January 16\u201318). Strong and efficient cache side-channel protection using hardware transactional memory. Proceedings of the 26th USENIX Security Symposium (USENIX Security 17), Vancouver, BC, Canada."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Liu, F., Ge, Q., Yarom, Y., Mckeen, F., Rozas, C., Heiser, G., and Lee, R.B. (2016, January 12\u201316). Catalyst: Defeating last-level cache side channel attacks in cloud computing. Proceedings of the 2016 IEEE International Symposium on High Performance Computer Architecture (HPCA), Barcelona, Spain.","DOI":"10.1109\/HPCA.2016.7446082"},{"key":"ref_14","unstructured":"Sprabery, R., Evchenko, K., Raj, A., Bobba, R.B., Mohan, S., and Campbell, R.H. (2017). A novel scheduling framework leveraging hardware cache partitioning for cache-side-channel elimination in clouds. arXiv."},{"key":"ref_15","unstructured":"Gras, B., Razavi, K., Bos, H., and Giuffrida, C. (2018, January 15\u201317). Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB Attacks. Proceedings of the USENIX Security Symposium, USENIX, Baltimore, MD, USA."},{"key":"ref_16","unstructured":"Holmes, N. (2023). Not Lost in Translation: Implementing Side Channel Attacks Through the Translation Lookaside Buffer. [Master\u2019s Thesis, Department of Computer Science, University of Warwick]."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"63865","DOI":"10.1109\/ACCESS.2024.3395491","article-title":"Ransomware Classification Using Hardware Performance Counters on a Non-Virtualized System","volume":"12","author":"Hill","year":"2024","journal-title":"IEEE Access"},{"key":"ref_18","first-page":"43","article-title":"HiPeR\u2014Early Detection of a Ransomware Attack using Hardware Performance Counters","volume":"4","author":"Anand","year":"2023","journal-title":"Digit. Threat. Res. Pract."},{"key":"ref_19","unstructured":"Pundir, N., Tehranipoor, M., and Rahman, F. (2020). RanStop: A Hardware-assisted Runtime Crypto-Ransomware Detection Technique. arXiv."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Sayadi, H., He, Z., Makrani, H.M., and Homayoun, H. (2024, January 3\u20135). Intelligent Malware Detection based on Hardware Performance Counters: A Comprehensive Survey. Proceedings of the 25th International Symposium on Quality Electronic Design (ISQED), San Francisco, CA, USA.","DOI":"10.1109\/ISQED60706.2024.10528369"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3464306","article-title":"Classifying Co-resident Computer Programs Using Information Revealed by Resource Contention","volume":"4","author":"Langehaug","year":"2023","journal-title":"Digit. Threat. Res. Pract."},{"key":"ref_22","unstructured":"Stallings, W. (2014). Operating Systems: Internals and Design Principles, Pearson."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"951","DOI":"10.3390\/jcp4040044","article-title":"Inferring TLB Configuration with Performance Tools","volume":"4","author":"Agredo","year":"2024","journal-title":"J. Cybersecur. Priv."},{"key":"ref_24","unstructured":"Chollet, F. (2018). Deep Learning with Python, Manning Publications Co."},{"key":"ref_25","unstructured":"Shrivastava, A. (2025, January 09). COMP 642\u2014Machine Learning Lecture 5: Deep Learning: Logistic Regression. Online, 2022. Scribed by Kristina Sanclemente, James Kafer, Tess Houlette, and Sarah McDonnell. Available online: https:\/\/www.cs.rice.edu\/~as143\/COMP642Spring22\/Scribes\/Lect5."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1023\/A:1010933404324","article-title":"Random Forests","volume":"45","author":"Breiman","year":"2001","journal-title":"Mach. Learn."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"533","DOI":"10.1038\/323533a0","article-title":"Learning Representations by Back-Propagating Errors","volume":"323","author":"Rumelhart","year":"1986","journal-title":"Nature"},{"key":"ref_28","unstructured":"Cire\u0219an, D.C., Meier, U., Masci, J., Gambardella, L.M., and Schmidhuber, J. (2011, January 16\u201322). Flexible, High Performance Convolutional Neural Networks for Image Classification. Proceedings of the Twenty-Second International Joint Conference on Artificial Intelligence (IJCAI), Barcelona, Spain."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"574","DOI":"10.1113\/jphysiol.1959.sp006308","article-title":"Receptive fields of single neurones in the cat\u2019s striate cortex","volume":"148","author":"Wiesel","year":"1959","journal-title":"J. Physiol."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Chen, T., and Guestrin, C. (2016, January 13\u201317). XGBoost: A Scalable Tree Boosting System. Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (KDD), San Francisco, CA, USA.","DOI":"10.1145\/2939672.2939785"},{"key":"ref_31","unstructured":"Ke, G., Meng, Q., Finley, T., Wang, T., Chen, W., Ma, W., Ye, Q., and Liu, T.Y. (2017, January 4\u20139). LightGBM: A Highly Efficient Gradient Boosting Decision Tree. Proceedings of the 31st International Conference on Neural Information Processing Systems (NeurIPS), Long Beach, CA, USA."},{"key":"ref_32","first-page":"1","article-title":"Hyper-Threading Technology Architecture and Microarchitecture","volume":"6","author":"Marr","year":"2002","journal-title":"Intel Technol. J."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Das, S., Werner, J., Antonakakis, M., Polychronakis, M., and Monrose, F. (2019, January 19\u201323). SoK: The Challenges, Pitfalls, and Perils of Using Hardware Performance Counters for Security. Proceedings of the 2019 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA.","DOI":"10.1109\/SP.2019.00021"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Zeraatkar, A.A., Kamran, P.S., Kaur, I., Ramu, N., Sheaves, T., and Al-Asaad, H. (2024, January 28\u201330). On the Performance of Malware Detection Classifiers Using Hardware Performance Counters. Proceedings of the 2024 International Conference on Smart Applications, Communications and Networking (SmartNets), Harrisonburg, VA, USA.","DOI":"10.1109\/SmartNets61466.2024.10577644"},{"key":"ref_35","unstructured":"Tatar, A., Trujillo, D., Giuffrida, C., and Bos, H. (2020, January 18\u201321). TLB;DR: Enhancing TLB-based Attacks with TLB Desynchronized Reverse Engineering. Proceedings of the 2020 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Dutta, S.B., Naghibijouybari, H., Gupta, A., Abu-Ghazaleh, N., Marquez, A., and Barker, K. (2023, January 17\u201321). Spy in the GPU-box: Covert and Side Channel Attacks on Multi-GPU Systems. Proceedings of the 50th Annual International Symposium on Computer Architecture, Orlando, FL, USA.","DOI":"10.1145\/3579371.3589080"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Nayak, A., Ganapathy, V., and Basu, A. (2021, January 7\u201311). (Mis) Managed: A Novel TLB-based Covert Channel on GPUs. Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security, Hong Kong.","DOI":"10.1145\/3433210.3453077"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Deng, S., Xiong, W., and Szefer, J. (2019, January 22\u201326). Secure TLBs. Proceedings of the 46th International Symposium on Computer Architecture, Phoenix, AZ, USA.","DOI":"10.1145\/3307650.3322238"},{"key":"ref_39","unstructured":"Costan, V., Lebedev, I.A., and Devadas, S. (2016, January 10\u201312). Sanctum: Minimal Hardware Extensions for Strong Software Isolation. Proceedings of the USENIX Security Symposium, Austin, TX, USA."},{"key":"ref_40","unstructured":"Intel (2016). IA-32 Architectures Software Developer\u2019s Manual. Syst. Program. Guide, 64, 64."},{"key":"ref_41","unstructured":"Stolz, F., Thoma, J.P., G\u00fcneysu, T., and Sasdrich, P. Risky Translations: Securing TLBs against Timing Side Channels. Proceedings of the Conference on Computer and Communications Security."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"12623","DOI":"10.1109\/ACCESS.2025.3528945","article-title":"TLB Coalescing with Range Compressed Page Table for Embedded I\/O Devices","volume":"13","author":"Duong","year":"2025","journal-title":"IEEE Access"},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Sayadi, H., He, Z., Miari, T., and Aliasgari, M. (2024, January 19\u201322). Redefining Trust: Assessing Reliability of Machine Learning Algorithms in Intrusion Detection Systems. Proceedings of the 2024 IEEE International Symposium on Circuits and Systems (ISCAS), Singapore.","DOI":"10.1109\/ISCAS58744.2024.10558202"},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Islam, M.S., Alouani, I., and Khasawneh, K.N. (2023, January 9\u201313). Stochastic-HMDs: Adversarial-Resilient Hardware Malware Detectors via Undervolting. Proceedings of the 2023 60th ACM\/IEEE Design Automation Conference (DAC), San Francisco, CA, USA.","DOI":"10.1109\/DAC56929.2023.10247980"},{"key":"ref_45","unstructured":"Luk, C.K., Cohn, R., Muth, R., Patil, H., Klauser, A., Lowney, G., Wallace, S., Reddi, V.J., and Hazelwood, K. (2005, January 12\u201315). Pin: Building Customized Program Analysis Tools with Dynamic Instrumentation. Proceedings of the ACM SIGPLAN Conference on Programming Language Design and Implementation (PLDI), Chicago, IL, USA. ACM SIGPLAN Notices."},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"He, Z., Fernandes, C.W., and Sayadi, H. Obfuscation-Resistant Hardware Malware Detection: A Stacked Denoising Autoencoder Approach. Proceedings of the 2025 Research Gate. IEEE, Available online: https:\/\/www.researchgate.net\/publication\/390842933.","DOI":"10.1109\/ISQED65160.2025.11014429"},{"key":"ref_47","unstructured":"Linux Kernel Organization (2024, January 11). Perf\u2014A Performance Counting Tool. Available online: https:\/\/perf.wiki.kernel.org\/index.php\/Main_Page."},{"key":"ref_48","unstructured":"EEMBC (2025, September 10). CoreMark-Pro. GitHub Repository. Available online: https:\/\/github.com\/eembc\/coremark-pro."},{"key":"ref_49","unstructured":"PerfWiki (2025, January 05). Counting with Perf Stat. Available online: https:\/\/perfwiki.github.io\/main\/tutorial\/#counting-with-perf-stat."},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Weaver, V.M., Terpstra, D., and Moore, S. (2013, January 21\u201323). Non-Determinism and Overcount on Modern Hardware Performance Counter Implementations. Proceedings of the 2013 IEEE International Symposium on Performance Analysis of Systems and Software (ISPASS), Austin, TX, USA.","DOI":"10.1109\/ISPASS.2013.6557172"}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/75\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T18:46:50Z","timestamp":1760035610000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/75"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,17]]},"references-count":50,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2025,9]]}},"alternative-id":["jcp5030075"],"URL":"https:\/\/doi.org\/10.3390\/jcp5030075","relation":{},"ISSN":["2624-800X"],"issn-type":[{"type":"electronic","value":"2624-800X"}],"subject":[],"published":{"date-parts":[[2025,9,17]]}}}