Stop Panicking Over Patching: CHERI Morello Memory Safety
Mo Javadi
S4x24 - ICS Security Conference · Day 2 · Main Stage
Overview
In this insightful talk at S4, Mo Javadi presented a compelling case for a paradigm shift in operational technology (OT) cybersecurity, moving away from the perpetual cycle of reactive patching towards a more proactive, hardware-rooted security posture. Titled "Stop Panicking Over Patching: CHERI Morello Memory Safety," the presentation introduced CHERI (Capability Hardware Enhanced RISC Instructions) implemented on ARM's Morello chip as a transformative technology designed to fundamentally address the pervasive issue of memory-related vulnerabilities. Javadi likened the current state of OT cybersecurity to the myth of Sisyphus, where every patch applied is quickly followed by the discovery of new vulnerabilities, forcing organizations back to square one.

Key moments
- 0:00 The Sisyphus problem: 70% of vulnerabilities are memory related
- 2:00 OT challenges: distributed assets and Modbus dependency
- 4:00 Real-world impact: BadAlloc affecting critical systems, Mars Rover
- 6:00 Introducing CHERI/Morello: Hardware-enhanced memory safety
- 6:30 How CHERI works: Fat pointers and fine-grained permissions
- 8:00 CHERI's scope: Hardware-level protection for all memory, including OS
Stop Panicking Over Patching: CHERI Morello Memory Safety
Speakers: Mo Javadi
Conference: S4
YouTube: https://www.youtube.com/watch?v=8Pn6i8PPPaM
Overview
In this insightful talk at S4, Mo Javadi presented a compelling case for a paradigm shift in operational technology (OT) cybersecurity, moving away from the perpetual cycle of reactive patching towards a more proactive, hardware-rooted security posture. Titled "Stop Panicking Over Patching: CHERI Morello Memory Safety," the presentation introduced CHERI (Capability Hardware Enhanced RISC Instructions) implemented on ARM's Morello chip as a transformative technology designed to fundamentally address the pervasive issue of memory-related vulnerabilities. Javadi likened the current state of OT cybersecurity to the myth of Sisyphus, where every patch applied is quickly followed by the discovery of new vulnerabilities, forcing organizations back to square one.
The talk underscored the critical importance of this shift by highlighting the staggering financial and operational costs associated with maintaining acceptable cybersecurity levels in regulated industries. With studies indicating that approximately 70% of all existing software vulnerabilities stem from memory management issues, the speaker argued that traditional patching efforts are an unsustainable drain on resources, particularly in complex, distributed OT environments. CHERI Morello offers a radical departure by embedding fine-grained memory protection directly into the hardware, promising to mitigate a vast majority of these vulnerabilities at their architectural root.
This technology holds immense significance for critical infrastructure sectors, where the integrity and availability of systems underpin national economies and public safety. By tackling memory safety at the chip level, CHERI Morello aims to provide a robust foundation for secure computing that could dramatically reduce the attack surface for advanced persistent threats, enhance system resilience, and ultimately free OT organizations from the Sisyphean task of endless patching.
Background
▶ Watch: The Sisyphus problem: 70% of vulnerabilities are memory related (0:00)
The current landscape of cybersecurity, particularly within operational technology, is characterized by a reactive and often overwhelming struggle against an ever-growing tide of vulnerabilities. Mo Javadi vividly illustrated this challenge with the analogy of Sisyphus, perpetually rolling a boulder uphill only for it to tumble back down – a fitting metaphor for the relentless cycle of discovering, patching, and re-patching systems. This reactive approach is not only inefficient but also incredibly costly. Javadi cited figures from the UK, where an estimated $12 billion is projected to be spent between 2021 and 2025 on maintaining and achieving acceptable cybersecurity standards in the regulated gas and electricity markets, with a substantial portion of this budget allocated to patching and updates.
A significant driver of this expenditure and complexity is the prevalence of memory-related vulnerabilities. Independent studies by tech giants like Microsoft and Google have consistently shown that these vulnerabilities account for roughly 70% of all software flaws. This statistic underscores a fundamental architectural weakness in how modern computing systems manage memory, leading to issues such as buffer overflows, use-after-free errors, and integer overflows, which are frequently exploited by attackers. The problem is particularly acute in OT environments, which often feature geographically distributed assets, legacy systems, and a historical neglect of advanced memory management capabilities that are more common in traditional IT.
Javadi provided a concrete example from the gas distribution industry, where the accurate measurement of gas quality is crucial for calculating its calorific value and, consequently, its economic worth. In the UK alone, $55 billion worth of gas was transported last year, with its valuation dependent on gas quality measuring systems that often rely on vulnerable protocols like Modbus. This is not an isolated issue; memory safety problems are endemic across the OT landscape, affecting everything from industrial protocols and drivers to runtimes. A notable incident, BadAlloc, surfaced in 2021, revealing critical vulnerabilities in memory allocation that impacted a vast array of OT systems, including industrial controllers, Emergency Shut Down (ESD) systems, protective relays, and even high-profile assets like the Mars Perseverance Rover, the humanoid robot Asimo, and military aircraft. Such widespread impact highlights that the problem extends beyond specific industries, posing a systemic risk to the digital economy that supports billions globally. Recognizing the severity and systemic nature of these vulnerabilities, the UK government initiated a significant investment of approximately £100 million in 2019 to foster the development of new technologies, specifically new memory access architectures, aimed at resolving these inherent security flaws at a foundational level.
Key Findings
▶ Watch: Real-world impact: BadAlloc affecting critical systems, Mars Rover (4:00)
The core revelation of Mo Javadi's talk is that the prevailing "Sisyphus problem" of reactive patching, particularly for memory-related vulnerabilities, can be fundamentally addressed through a proactive, hardware-level security paradigm. The central innovation presented is the implementation of CHERI (Capability Hardware Enhanced RISC Instructions) on ARM's Morello chip. CHERI itself is an architectural concept that has been researched for decades, but its novel implementation directly into the hardware of a System-on-Chip (SoC) by ARM, in collaboration with Cambridge University, marks a significant breakthrough.
The key finding is that CHERI Morello transforms the traditional model of memory access. In conventional architectures, possessing a memory address is akin to having a master key to a building: once inside, access to various memory cells and the data within them is largely unrestricted. CHERI Morello, however, introduces fat pointers. These are not just memory addresses; they are extended pointers that also encapsulate permissions and capabilities. These capabilities define the exact bounds within which a pointer can operate and the specific operations (e.g., read, write, execute) it is permitted to perform.
Crucially, these permissions and capabilities are not merely enforced by software at runtime, which can be bypassed or exploited. Instead, they are continuously monitored and assessed directly at the hardware level by the Morello chip itself. This hardware-enforced, fine-grained memory protection is the talk's primary contribution, offering a robust defense against 70% of vulnerabilities that typically arise from memory safety violations. By shifting the enforcement mechanism from software to hardware, CHERI Morello promises to fundamentally alter the attack surface, making it exponentially more difficult for attackers to exploit common memory bugs.
Technical Deep Dive
▶ Watch: Introducing CHERI/Morello: Hardware-enhanced memory safety (6:00)
The technical innovation at the heart of Mo Javadi's presentation lies in the CHERI (Capability Hardware Enhanced RISC Instructions) architecture, specifically its implementation on the ARM Morello chip. CHERI is a hardware-software co-design approach that enhances traditional CPU instruction sets with the ability to manage capabilities. These capabilities are cryptographically strong, unforgeable pointers that not only specify a memory address but also define a specific memory region (bounds) and the permitted operations (read, write, execute) within that region.
Javadi clarified that while the CHERI concept has existed for decades, its implementation directly into the hardware of a modern System-on-Chip (SoC) by ARM, with foundational research from Cambridge University, is what makes Morello revolutionary. The current computing paradigm operates on a principle where a memory address is akin to a "key to a building." Once an attacker gains control of an address, they often gain near-unrestricted access to the data within that memory region, leading to widespread vulnerabilities like buffer overflows, heap corruptions, and use-after-free errors.
Morello fundamentally alters this by introducing fat pointers. A fat pointer in the CHERI architecture is an extended data type that combines the traditional memory address with additional metadata: its bounds (the start and end addresses of the memory region it can access) and a set of permissions (what operations it can perform). This is analogous to entering a building with an access card that not only grants entry but also specifies precisely which rooms you can access and what facilities (like a coffee machine or microwave) you are authorized to use within those rooms. This provides fine-grained memory protection.
The critical differentiator is that the enforcement of these capabilities and permissions happens entirely at the hardware level. During runtime, every memory access made by any software component—from the operating system kernel to user applications and firmware—is continuously checked against the capabilities embedded within the fat pointer by the Morello chip itself. If a program attempts to access memory outside its designated bounds or perform an unauthorized operation (e.g., write to a read-only region), the hardware immediately detects and prevents it. This contrasts sharply with traditional software-based memory protections, which can often be bypassed or are subject to their own vulnerabilities.
This hardware-level enforcement means that common memory safety bugs that typically lead to exploitation are caught and prevented before they can cause harm. The scope of this protection is comprehensive, covering "everything" that runs on the hardware. Javadi emphasized that "all the memory access are challenged at the hardware level," representing a fundamental shift in how memory security is managed. The development of this ecosystem has been a collaborative effort, involving ARM and Cambridge University for the core chip design and architecture, alongside other organizations such as the University of Strathclyde and the speaker's own organization, which have been instrumental in porting and developing supporting software to enable widespread adoption and utility of the Morello platform.
Demo / Proof of Concept
▶ Watch: How CHERI works: Fat pointers and fine-grained permissions (6:30)
While Mo Javadi's presentation at S4 provided a thorough conceptual and technical overview of the CHERI Morello architecture and its profound implications for cybersecurity, it did not feature a live, real-time demonstration or a hands-on proof of concept of the technology in action. The talk focused on explaining the fundamental principles, the problem it addresses, and the architectural solution CHERI Morello provides.
Instead of a live demo, Javadi elaborated on the mechanism of fat pointers and hardware-enforced capabilities, using clear analogies to convey how Morello fundamentally changes memory access security. He described how the chip validates every memory operation against embedded permissions and bounds, preventing unauthorized access or modification at the lowest hardware level. The discussion centered on the design and functionality of CHERI Morello, highlighting its ability to mitigate a vast percentage of memory-related vulnerabilities by design, rather than showcasing specific exploits being thwarted. The emphasis was on the architectural shift and the collaborative efforts to build a supporting software ecosystem around this novel hardware.
Defensive Implications
▶ Watch: CHERI's scope: Hardware-level protection for all memory, including OS (8:00)
The advent of CHERI Morello introduces a profound shift in defensive cybersecurity strategies, particularly for OT environments. Its hardware-enforced memory safety capabilities offer a proactive solution that can fundamentally alter the current reactive patching paradigm.
Firstly, CHERI Morello directly addresses the root cause of approximately 70% of all software vulnerabilities: memory safety issues. By preventing common errors like buffer overflows, use-after-free, and out-of-bounds access at the hardware level, it drastically shrinks the attack surface available to adversaries. This means that many exploits that rely on corrupting memory to gain control or escalate privileges would simply fail, as the hardware would prevent the malicious operation before it could take effect.
For OT defenders, this translates into a significant reduction in the patching burden. The "Sisyphus problem" of endless patching, particularly challenging in distributed, geographically dispersed, and often air-gapped OT systems, could be substantially alleviated. Instead of constantly reacting to newly discovered memory corruption vulnerabilities, organizations can deploy systems with an inherent, architectural resilience against these classes of attacks. This frees up valuable resources that can then be redirected towards other critical security initiatives, such as threat intelligence, incident response, and securing the remaining 30% of vulnerabilities.
The technology promises to enhance the resilience and reliability of critical infrastructure. Systems controlling gas distribution, electricity grids, water treatment, and manufacturing processes, which are currently vulnerable to sophisticated memory-based attacks (like those seen with BadAlloc), would become inherently more robust. This is crucial for maintaining operational continuity and preventing catastrophic failures or disruptions.
Furthermore, CHERI Morello encourages a "security by design" philosophy. Software developers targeting CHERI-enabled hardware would be forced to write more memory-safe code, as many common programming errors would result in immediate hardware-level traps rather than exploitable vulnerabilities. While this might require adjustments to development practices and tooling, the long-term benefit is a more secure software ecosystem from the ground up.
In essence, CHERI Morello represents a strategic shift from trying to fix software vulnerabilities after they emerge to preventing them at the foundational hardware level. OT operators and cybersecurity professionals should actively monitor the development and adoption of CHERI-enabled hardware, advocating for its integration into future industrial control systems and embedded devices. Early adoption could provide a significant defensive advantage, fundamentally strengthening the security posture of critical infrastructure against a broad spectrum of sophisticated cyber threats.
Key Takeaways
- The "Sisyphus Problem" of Patching: Current OT cybersecurity is plagued by a reactive patching cycle, where new vulnerabilities emerge as fast as old ones are fixed, consuming billions in resources.
- Memory Vulnerabilities Dominate: Approximately 70% of all software vulnerabilities are attributed to memory safety issues, making them a primary target for attackers and a major driver of the patching burden.
- CHERI Morello: A Hardware-Level Solution: The ARM Morello chip, implementing CHERI (Capability Hardware Enhanced RISC Instructions), offers a proactive, architectural solution to memory safety.
- Fat Pointers & Fine-Grained Protection: Morello uses fat pointers that combine memory addresses with hardware-enforced capabilities (permissions and bounds), enabling unprecedented fine-grained memory protection.
- Shift from Reactive to Proactive: This technology shifts the security paradigm from detecting and patching vulnerabilities after they are found to preventing a vast class of vulnerabilities at the fundamental hardware level.
- Profound Impact on OT Security: CHERI Morello promises to significantly reduce the attack surface for critical infrastructure, enhance system resilience, and alleviate the immense burden of memory-related patching in distributed OT environments.
About the Speaker(s)
Mo Javadi is a professional actively involved in advancing cybersecurity, particularly within the operational technology (OT) domain. As indicated in his talk, he is part of a collaborative effort, including ARM, Cambridge University, and the University of Strathclyde, focused on developing and porting supporting software for the CHERI Morello platform. His work contributes to building the ecosystem necessary for the widespread adoption and utilization of this novel hardware-enhanced memory safety technology. His expertise lies in understanding the challenges of OT cybersecurity, particularly in critical infrastructure sectors like gas and electricity distribution, and in advocating for innovative, proactive solutions to these complex problems.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
Mo Javadi's presentation on CHERI Morello is a groundbreaking exposition of a hardware-rooted solution to the pervasive issue of memory safety vulnerabilities, which constitute approximately 70% of all software flaws. The talk expertly navigates from the systemic problem of reactive patching in OT to the elegant architectural answer offered by CHERI's fat pointers and hardware-enforced capabilities. This technology represents a fundamental shift from perpetual vulnerability management to a proactive, silicon-level defense, promising to drastically reduce the attack surface for critical infrastructure.
Heather Calloway (CISO) — MUST SEE
Mo Javadi's session on CHERI Morello presents a critical, paradigm-shifting solution to the pervasive and costly problem of memory-related vulnerabilities, which account for roughly 70% of all software flaws. By introducing hardware-enforced memory safety, this technology offers a proactive architectural defense that fundamentally redefines how we manage a vast percentage of our institutional risk. This is not merely a technical advancement; it's a strategic imperative for CISOs and boards to understand, offering a path to true resilience and a dramatic reduction in the unsustainable 'Sisyphus problem' of endless patching, particularly within critical infrastructure.