{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T14:07:25Z","timestamp":1784038045126,"version":"3.55.0"},"reference-count":38,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2022,2,11]],"date-time":"2022-02-11T00:00:00Z","timestamp":1644537600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Korea government(MSIT)","award":["2021-0-00724"],"award-info":[{"award-number":["2021-0-00724"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>In recent decades, there has been an increasing number of studies on control flow integrity (CFI), particularly those implementing hardware-assisted CFI solutions that utilize a special instruction set extension. More recently, ARM and Intel, which are prominent processor architectures, also announced instruction set extensions for CFI called branch target identification (BTI) and control-flow enhancement technology (CET), respectively. However, according to our preliminary analysis, they do not support various CFI solutions in an efficient and scalable manner. In this study, we propose Bratter, a new instruction set extension for forward CFI solutions on RISC-V. At the center of Bratter, there are Branch Tag Registers and dedicated instructions for these registers. We implemented well-known CFI solutions (i.e., branch regulation and function signature check) using Bratter to evaluate its performance. Our experimental results show that, by using Bratter, even when these two solutions work together, they impose only 1.20% and 5.99% overhead for code size and execution time, respectively.<\/jats:p>","DOI":"10.3390\/s22041392","type":"journal-article","created":{"date-parts":[[2022,2,13]],"date-time":"2022-02-13T20:34:45Z","timestamp":1644784485000},"page":"1392","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":10,"title":["Bratter: An Instruction Set Extension for Forward Control-Flow Integrity in RISC-V"],"prefix":"10.3390","volume":"22","author":[{"given":"Seonghwan","family":"Park","sequence":"first","affiliation":[{"name":"Computer Security Laboratory, School of Computer Science & Engineering, Pusan National University, Busan 609-735, Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dongwook","family":"Kang","sequence":"additional","affiliation":[{"name":"Cyber Security Research Division, Electronics and Telecommunications Research Institute, Daejeon 305-700, Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7567-0530","authenticated-orcid":false,"given":"Jeonghwan","family":"Kang","sequence":"additional","affiliation":[{"name":"Computer Security Laboratory, School of Computer Science & Engineering, Pusan National University, Busan 609-735, Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7507-3111","authenticated-orcid":false,"given":"Donghyun","family":"Kwon","sequence":"additional","affiliation":[{"name":"Computer Security Laboratory, School of Computer Science & Engineering, Pusan National University, Busan 609-735, Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,2,11]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Burow, N., Zhang, X., and Payer, M. (2019, January 19\u201323). SoK: Shining light on shadow stacks. Proceedings of the 2019 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA.","DOI":"10.1109\/SP.2019.00076"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/1609956.1609960","article-title":"Control-flow integrity principles, implementations, and applications","volume":"13","author":"Abadi","year":"2009","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Van Der Veen, V., G\u00f6ktas, E., Contag, M., Pawoloski, A., Chen, X., Rawat, S., Bos, H., Holz, T., Athanasopoulos, E., and Giuffrida, C. (2016, January 22\u201326). A tough call: Mitigating advanced code-reuse attacks at the binary level. Proceedings of the 2016 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2016.60"},{"key":"ref_4","unstructured":"ARM (2022, February 09). Arm Armv9-A A64 Instruction Set Architecture. Available online: https:\/\/developer.arm.com\/documentation\/ddi0602."},{"key":"ref_5","unstructured":"Patel, B.V. (2022, February 09). A Technical Look at Intel\u2019s Control-Flow Enforcement Technology. Available online: https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/technical-look-control-flow-enforcement-technology.html?wapkw=control-flow%20enforcement%20technology."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Sullivan, D., Arias, O., Davi, L., Larsen, P., Sadeghi, A.R., and Jin, Y. (2016, January 5\u20139). Strategy without tactics: Policy-agnostic hardware-enhanced control-flow integrity. Proceedings of the 2016 53nd ACM\/EDAC\/IEEE Design Automation Conference (DAC), Austin, TX, USA.","DOI":"10.1145\/2897937.2898098"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Davi, L., Hanreich, M., Paul, D., Sadeghi, A.R., Koeberl, P., Sullivan, D., Arias, O., and Jin, Y. (2015, January 8\u201312). HAFIX: Hardware-assisted flow integrity extension. Proceedings of the 2015 52nd ACM\/EDAC\/IEEE Design Automation Conference (DAC), San Francisco, CA, USA.","DOI":"10.1145\/2744769.2744847"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Christoulakis, N., Christou, G., Athanasopoulos, E., and Ioannidis, S. (2016, January 9\u201311). HCFI: Hardware-enforced control-flow integrity. Proceedings of the Sixth ACM Conference on Data and Application Security and Privacy, Louisiana, NO, USA.","DOI":"10.1145\/2857705.2857722"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"De, A., Basu, A., Ghosh, S., and Jaeger, T. (2019, January 25\u201329). FIXER: Flow integrity extensions for embedded RISC-V. Proceedings of the 2019 Design, Automation & Test in Europe Conference & Exhibition (DATE), Florence, Italy.","DOI":"10.23919\/DATE.2019.8714980"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"3165","DOI":"10.1109\/TCAD.2020.3012640","article-title":"ABCFI: Fast and Lightweight Fine-Grained Hardware-Assisted Control-Flow Integrity","volume":"39","author":"Li","year":"2020","journal-title":"IEEE Trans. Comput. Aided Des. Integr. Circuits Syst."},{"key":"ref_11","unstructured":"Waterman, A., and Asanovic, K. (2017). The RISC-V Instruction Set Manual, Volume I: User-Level ISA, RISC-V Foundation. Document Version 2.2."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2133375.2133377","article-title":"Return-oriented programming: Systems, languages, and applications","volume":"15","author":"Roemer","year":"2012","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Bletsch, T., Jiang, X., Freeh, V.W., and Liang, Z. (2011, January 22\u201324). Jump-oriented programming: A new class of code-reuse attack. Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security, Hong Kong, China.","DOI":"10.1145\/1966913.1966919"},{"key":"ref_14","unstructured":"Carlini, N., and Wagner, D. (2014, January 20\u201322). ROP is still dangerous: Breaking modern defenses. Proceedings of the 23rd USENIX Security Symposium (USENIX Security 14), San Diego, CA, USA."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Guo, Y., Chen, L., and Shi, G. (June, January 30). Function-oriented programming: A new class of code reuse attack in c applications. Proceedings of the 2018 IEEE Conference on Communications and Network Security (CNS), Beijing, China.","DOI":"10.1109\/CNS.2018.8433189"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Kayaalp, M., Ozsoy, M., Abu-Ghazaleh, N., and Ponomarev, D. (2012, January 9\u201313). Branch regulation: Low-overhead protection from code reuse attacks. Proceedings of the 2012 39th Annual International Symposium on Computer Architecture (ISCA), Portland, OR, USA.","DOI":"10.1109\/ISCA.2012.6237009"},{"key":"ref_17","unstructured":"llvm (2022, February 09). llvm-Project. Available online: https:\/\/github.com\/llvm\/llvm-project."},{"key":"ref_18","unstructured":"RISC-V (2022, February 09). Spike, a RISC-V ISA Simulator. Available online: https:\/\/github.com\/riscv\/riscv-isa-sim."},{"key":"ref_19","unstructured":"Pallister, J., Hollis, S., and Bennett, J. (2013). BEEBS: Open Benchmarks for Energy Measurements on Embedded Platforms. arXiv."},{"key":"ref_20","unstructured":"(2022, February 09). RISC-V Software Collaboration Riscv-Gnu-Toolchain. Available online: https:\/\/github.com\/riscv-collab\/riscv-gnu-toolchain."},{"key":"ref_21","unstructured":"Pappas, V., Polychronakis, M., and Keromytis, A.D. (2013, January 14\u201316). Transparent ROP exploit mitigation using indirect branch tracing. Proceedings of the 22nd USENIX Security Symposium (USENIX Security 13), Washington, DC, USA."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Cheng, Y., Zhou, Z., Miao, Y., Ding, X., and Deng, R.H. (2014, January 23\u201326). ROPecker: A generic and practical approach for defending against ROP attack. Proceedings of the 21st Network and Distributed System Security Symposium, San Diego, CA, USA.","DOI":"10.14722\/ndss.2014.23156"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Yao, F., Chen, J., and Venkataramani, G. (2013, January 6\u20139). Jop-alarm: Detecting jump-oriented programming-based anomalies in applications. Proceedings of the 2013 IEEE 31st International Conference on Computer Design (ICCD), Asheville, NC, USA.","DOI":"10.1109\/ICCD.2013.6657084"},{"key":"ref_24","unstructured":"Carlini, N., Barresi, A., Payer, M., Wagner, D., and Gross, T.R. (2015, January 12\u201314). Control-flow bending: On the effectiveness of control-flow integrity. Proceedings of the 24th USENIX Security Symposium (USENIX Security 15), Washington, DC, USA."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Schuster, F., Tendyck, T., Liebchen, C., Davi, L., Sadeghi, A.R., and Holz, T. (2015, January 17\u201321). Counterfeit object-oriented programming: On the difficulty of preventing code reuse attacks in C++ applications. Proceedings of the 2015 IEEE Symposium on Security and Privacy, San Jose, CA, USA.","DOI":"10.1109\/SP.2015.51"},{"key":"ref_26","unstructured":"Telesklav, M., and Tauner, S. (2021). Comparative Analysis and Enhancement of CFG-based Hardware-Assisted CFI Schemes. arXiv."},{"key":"ref_27","unstructured":"ARM (2022, February 09). Embedded Trace Macrocell Architecture Specification ETMv4.0 to ETM4.6. Available online: https:\/\/developer.arm.com\/documentation\/ihi0064\/h."},{"key":"ref_28","first-page":"1","article-title":"Efficient security monitoring with the core debug interface in an embedded processor","volume":"22","author":"Lee","year":"2016","journal-title":"ACM Trans. Des. Autom. Electron. Syst. (TODAES)"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"186517","DOI":"10.1109\/ACCESS.2019.2961416","article-title":"Actimon: Unified JOP and ROP detection with active function lists on an SoC FPGA","volume":"7","author":"Oh","year":"2019","journal-title":"IEEE Access"},{"key":"ref_30","unstructured":"Guide, P. (2021, December 30). Intel\u00ae 64 and ia-32 Architectures Software Developer\u2019s Manual Volume 3B: System Programming Guide, Part 2. Available online:https:\/\/www.semanticscholar.org\/paper\/Intel-%C2%AE-64-and-IA-32-Architectures-Software-%E2%80%99-s-3-A-License-Disclaims\/08293a1041fd2d513f2cb71b30da0434f6bb04f4."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Hu, H., Qian, C., Yagemann, C., Chung, S.P.H., Harris, W.R., Kim, T., and Lee, W. (2018, January 15\u201319). Enforcing unique code target property for control-flow integrity. Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, Toronto, Canada.","DOI":"10.1145\/3243734.3243797"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Kwon, D., Seo, J., Baek, S., Kim, G., Ahn, S., and Paek, Y. (2018). VM-CFI: Control-flow integrity for virtual machine kernel using Intel PT. International Conference on Computational Science and Its Applications, Springer.","DOI":"10.1007\/978-3-319-95174-4_10"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Gu, Y., Zhao, Q., Zhang, Y., and Lin, Z. (2017, January 22\u201324). PT-CFI: Transparent backward-edge control flow violation detection using intel processor trace. Proceedings of the Seventh ACM on Conference on Data and Application Security and Privacy, Scottsdale, AZ, USA.","DOI":"10.1145\/3029806.3029830"},{"key":"ref_34","unstructured":"Ding, R., Qian, C., Song, C., Harris, B., Kim, T., and Lee, W. (2017, January 16\u201318). Efficient protection of path-sensitive control security. Proceedings of the 26th USENIX Security Symposium (USENIX Security 17), Vancouver, Canada."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"585","DOI":"10.1145\/3093336.3037716","article-title":"Griffin: Guarding control flows using intel processor trace","volume":"52","author":"Ge","year":"2017","journal-title":"ACM SIGPLAN Not."},{"key":"ref_36","unstructured":"Asanovic, K., Avizienis, R., Bachrach, J., Beamer, S., Biancolin, D., Celio, C., Cook, H., Dabbelt, D., Hauser, J., and Izraelevitz, A. (2016). The Rocket Chip Generator, EECS Department, University of California. Technical Reports UCB\/EECS-2016-17."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Lee, Y., Lee, J., Heo, I., Hwang, D., and Paek, Y. (2016, January 14\u201318). Integration of ROP\/JOP monitoring IPs in an ARM-based SoC. Proceedings of the 2016 Design, Automation & Test in Europe Conference & Exhibition (DATE), Dresden, Germany.","DOI":"10.3850\/9783981537079_0550"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Chaudhari, A., and Abraham, J.A. (2018, January 2\u20134). Effective control flow integrity checks for intrusion detection. Proceedings of the 2018 IEEE 24th International Symposium on On-Line Testing Furthermore, Robust System Design (IOLTS), Platja d\u2019Aro, Spain.","DOI":"10.1109\/IOLTS.2018.8474130"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/4\/1392\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T22:17:40Z","timestamp":1760134660000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/4\/1392"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,2,11]]},"references-count":38,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2022,2]]}},"alternative-id":["s22041392"],"URL":"https:\/\/doi.org\/10.3390\/s22041392","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,2,11]]}}}