
Table of Contents
Modern computing systems often feature tightly integrated CPU and GPU components with shared memory and microarchitectural resources. While this integration delivers immense performance benefits, it also brings significant risks in the form of side channels and covert channels. These allow attackers to exfiltrate information cross-component, bypassing traditional process isolation.
This post offers an in-depth technical review of cross-component covert channels on integrated CPUs, especially focusing on those that exploit shared microarchitectural components—caches, branch predictors, and others. We'll explore theoretical backgrounds, real-world feasibility, code demonstrations, and current mitigation strategies. Whether you're a security beginner or an advanced researcher, this guide will cover threat models, practical PoCs, and defense best-practices.
A covert channel is a communication path that was not designed for information transfer. In computing, the term often refers to scenarios where one process (the sender, or "high" process) deliberately transmits information to another process (the receiver, or "low" process) in a way that's forbidden by security policy.
Covert channels are not limited to network traffic. Many exist at lower system layers, including storage channels (using files, memory timing, etc.) and timing channels (differences in resource availability).
Modern CPUs and GPUs use shared resources for expediency:
When two processes share these, they can signal information using changes in the state or timing of shared hardware, even when no direct communication is allowed.
The most notorious covert channels are cache-based:
Both attacks exploit the shared nature of multi-level CPU caches, especially the last-level cache (LLC).
Modern CPUs use branch predictors to speed up execution. These predictors are shared between processes and sometimes across cores. If a sender trains the predictor, the receiver can probe and observe changes in prediction, enabling data transmission.
See: "Covert channels through branch predictors: a feasibility study"
Integrated CPU-GPU systems share DRAM and sometimes even more fine-grained components (e.g., LLC, system buses). This cross-component resource sharing opens up new, largely unexplored, attack surfaces:
Academic research examines attacks where the CPU and GPU, or different processes running on either, form a covert channel through shared cache lines or memory bandwidth (Leaky Buddies).
clflush instruction).Key Point: Timing differences reveal the sender’s actions.
Used mostly in cloud settings, where shared memory may not exist.
See "Covert channels through branch predictors: a feasibility study" for attack demonstration.
Start by gathering CPU cache and branch predictor information.
# List CPU cache details
lscpu | grep -i cache
# Advanced: parse CPU cache sizes directly
cat /proc/cpuinfo | grep -E 'cache size|model name'
# List shared libraries mmap'ed by a process
pidof firefox # For example
cat /proc/<pid>/maps | grep r-xp | grep 'lib'
# Python: Parse to seek shared object regions
import os
pid = <your_pid>
with open(f"/proc/{pid}/maps") as f:
for line in f:
if 'lib' in line and 'r-xp' in line:
print(line.strip())
// gcc -O2 -o flush_reload flush_reload.c
#include <stdio.h>
#include <stdint.h>
#include <x86intrin.h>
uint64_t measure_access_time(volatile char *addr) {
uint64_t start = __rdtscp(&start);
*(volatile char *)addr;
uint64_t end = __rdtscp(&end);
return end - start;
}
int main() {
char *ptr = ...; // map to shared object
while (1) {
_mm_clflush(ptr); // Sender: or skip for Receiver
uint64_t t = measure_access_time(ptr);
printf("Access time: %lu\n", t);
}
}
import ctypes
import time
# Map a shared library/file, e.g., via mmap
libc = ctypes.CDLL("libc.so.6")
address = ctypes.c_void_p(...)
def measure_access_time(addr):
t1 = time.perf_counter_ns()
dummy = ctypes.c_char.from_address(addr.value)
val = dummy.value
t2 = time.perf_counter_ns()
return t2 - t1
while True:
t = measure_access_time(address)
print(f"Access time: {t}ns")
// Pseudocode for sender and receiver in branch predictor attack
// Data bit to communicate: 0 or 1
// Sender: "train" branch predictor
if (bit_to_send == 1) {
for (int i = 0; i < 1000; i++) { if (cond) foo(); }
} else {
for (int i = 0; i < 1000; i++) { if (!cond) foo(); }
}
// Receiver: measure branch mispredict timing
uint64_t t1 = rdtscp();
if (cond) foo();
uint64_t t2 = rdtscp();
uint64_t elapsed = t2 - t1;
if (elapsed > THRESHOLD) decode as bit 1 else 0;
Note: No mitigation is perfect—trade-offs involve performance/security.
These represent a superset of side/covert channels, exploiting speculative execution (Spectre, Meltdown) and other transiently executed instructions to leak state via microarchitectural channels:
See the "Side Channels and Transient Execution" lecture series for visual/timing breakdowns.
perf stat ...)# Monitor cache misses and branch mispredictions
sudo perf stat -e cache-misses,branch-misses ./your_app
import psutil
# Monitor every process's cache and CPU usage over time
for proc in psutil.process_iter(['pid', 'name', 'cpu_percent']):
print(proc.info)
Cross-component covert channels highlight a critical and persistent risk in microarchitectural security. As CPUs and GPUs become more tightly integrated, the boundary over which secret data can leak widens, from shared CPU caches to sophisticated branch predictors and onto cross-CPU-GPU resources.
Defenses require coordinated hardware, OS, and software efforts—and always come with performance costs. The deeper the attack, the harder the choice.
For researchers, continuing to enumerate, model, and mitigate new cross-component covert channel techniques is an ongoing process. For organizations, threat modeling and situation awareness are vital.
For latest research and vulnerability disclosures, frequently monitor trusted academic/conference sites and CVE advisories.
If you found this content valuable, imagine what you could achieve with our comprehensive 47-week elite training program. Join 1,200+ students who've transformed their careers with Unit 8200 techniques.