ARM64 Control Flow Integrity (BTI & PAC) Simulator ARMv8.3 / ARMv8.5 Hardware Defense

속도:
Simulation Active: ARM64 Hardware CFI Pipeline
🛡️ 시나리오 1: ARM64 BTI (Branch Target Identification) 전방향 무결성
간접 분기(BLR x20) 발생 시 CPU는 PSTATE.BTYPE을 0b10으로 설정하고, 타깃 메모리가 Guarded Page(PTE_GP)인지 확인합니다.
타깃의 첫 명령어가 유효한 Landing Pad(bti c 또는 paciasp)이면 정상이지만, 가젯 중간이나 비인가 위치로 점프하면 즉각 Branch Target Exception (ESR_EL1.EC=0x0D / Oops - BTI)을 발생시킵니다.
Dispatcher (BLR x20) mov x20, target_addr blr x20 (Indirect Call) PSTATE.BTYPE = 0b10 (Awaiting BTI Landing Pad) ARM64 Hardware BTI Logic 1. Page Table PTE_GP Check 2. Target Insn == BTI / PACIASP? Status: Ready Target A: Legit Function (with BTI) 0x...: paciasp / bti c Landing Pad Valid -> Clears BTYPE Target B: Gadget Middle (NO BTI) 0x...: str x0, [x1] (Arbitrary) No Landing Pad -> Oops: BTI Trap!
[System Ready] ARM64 BTI simulator ready. Notice dynamic particles tracking the branch instruction fetch.