- Starts: 2:00 pm on Wednesday, September 9, 2026
- Ends: 4:00 pm on Wednesday, September 9, 2026
ECE PhD Thesis Defense: Chathura Rajapaksha
Title: Securing Hardware-Software Interfaces: Systematic Discovery and Mitigation of Cross-Layer Vulnerabilities
Presenter: Chathura Rajapaksha
Advisors: Professors Ajay Joshi & Manuel Egele
Chair: Professor Janusz Konrad
Committee: Professor Ajay Joshi, Professor Manuel Egele, Professor Martin Herbordt, Professor Yigong Hu
Google Scholar Link: https://scholar.google.com/citations?user=RZUQEcoAAAAJ
Abstract: Modern computing systems rely on hardware-software interfaces through which hardware and software components interact according to shared architectural specifications. These specifications define required interface behavior while deliberately abstracting implementation details. Cross-layer vulnerabilities can emerge when hardware implementation choices and software usage patterns interact in ways that hardware designers and software developers did not adequately anticipate. This dissertation examines this problem at three interfaces and presents distinct approaches to vulnerability discovery, empirical characterization, and mitigation.
First, we present SIGFuzz, an automated framework for discovering microarchitectural timing side channels during processor design. Discovering these side channels is challenging because they can arise from subtle interactions among many instructions or from operand-dependent timing behavior. SIGFuzz explores these interactions using long, randomized instruction sequences, differential substitution, and microarchitectural signatures to isolate and group timing behaviors. Applied to Rocket and BOOM, SIGFuzz discovered previously unknown timing side channels, and we demonstrated the exploitability of one such side channel through a novel Spectre-style attack.
Second, we present xSMMU, an IOMMU security mode that enforces I/O memory safety against two known DMA vulnerabilities while addressing the performance and scalability limitations of existing protections. A major obstacle to practical I/O memory safety is the high latency of IOMMU invalidation, which substantially reduces the throughput of existing software protections. To determine where this latency originates, we profile the invalidation path and find that communication between the operating system and IOMMU dominates the cost. Guided by this insight, xSMMU amortizes expensive synchronization across batches of completed I/O operations and enforces fine-grained access control by checking each DMA request against its intended buffer boundaries. In our evaluation, xSMMU achieves 1.6 to 2.5 times the network throughput of the combined Linux software protections for temporal and spatial DMA memory safety.
Third, we present RASCrash, a new class of PCIe configuration-space-induced fault-containment failures in cloud systems. RASCrash arises in deployments that expose a device's configuration space to untrusted tenant software for near-bare-metal performance, such as PCIe device passthrough. In these environments, architecturally legal tenant writes can drive a device into error states whose effects escape the assigned device, potentially disrupting workloads belonging to other tenants on the same host. We develop RAS-Strike, a black-box tool that characterizes these failures without access to device firmware or internal state. Using RAS-Strike, we identify RASCrash failures in GPUs, NVMe devices, NICs, and SmartNICs.
- Location:
- PHO 428
