SYSTEM Cited by 1 source
Dynamic Process Isolation (DyPrIs)¶
Dynamic Process Isolation (DyPrIs) is Cloudflare's production defense against in-process Spectre attacks on Cloudflare Workers. It watches hardware performance counters and, once a script looks like a Spectre attack, isolates that script into its own separate OS process — trading away the shared-process density for that tenant in exchange for a hard memory boundary. DyPrIs shipped after Cloudflare's 2021 Spectre assessment of Workers.
How it works¶
- Behavioral detection over hardware performance counters. Rather than trying to identify specific gadgets, DyPrIs monitors microarchitectural counters (notably branch mispredictions) for the signature of a Spectre attack in progress.
- Normalization. Branch mispredictions are normalized by the number of iTLB accesses to produce a ratio that discriminates attack-shaped execution from ordinary code.
- Response = separate process. When a script crosses the detection threshold, it is moved into its own process sandbox, so a transient cross-tenant read can no longer reach a co-resident isolate's heap.
The limitation this work exposed (2024–25)¶
Cloudflare's re-assessment demonstrated a remote Spectre attack that stayed under DyPrIs's radar for two structural reasons (Source: sources/2026-08-19-cloudflare-a-revisit-of-remote-spectre-attacks-on-cloudflare-workers):
- Post-invocation isolation is too late for long-lived sessions. DyPrIs isolated a script only after its invocation finished. But a Durable Object WebSocket keep-alive holds a single invocation open for hours — the attack leaked the secret long before post-execution isolation would have kicked in.
- The remote-timer I/O loop skews the normalization. The attack's remote timer is one large I/O loop; that WebSocket traffic inflates iTLB activity, which pushes the branch-misprediction-per-iTLB ratio below the detection threshold. The attack looks like an ordinary I/O-heavy Worker.
Improved DyPrIs (the fix)¶
Cloudflare hardened DyPrIs so that:
- Long-lived executions and I/O-heavy workloads are first-class security cases — detection cannot happen only after a script finishes, because a Durable-Object / WebSocket-heavy Worker can run long enough that post-execution isolation arrives too late.
- Remote-timer behavior is being investigated as an additional detection dimension. Cloudflare can't eliminate communication with attacker-controlled infrastructure, but the timing data reveals distinctive exfiltration bit-patterns; the better approach is to treat repeated timer-like I/O around compute-heavy sections as part of the behavioral signal, not background noise.
DyPrIs is one of three layers in the hardened defense, alongside the V8 Sandbox (remove raw 64-bit heap pointers) and MPK-based in-process isolation — see concepts/defense-in-depth.
Seen in¶
- sources/2026-08-19-cloudflare-a-revisit-of-remote-spectre-attacks-on-cloudflare-workers — canonical wiki instance: DyPrIs's design (perf-counter behavioral detection + process isolation), the two evasions that defeated it (post-invocation timing + iTLB-normalized ratio), and the fix (long-lived/I/O-heavy workloads as first-class, remote-timer behavior as a candidate signal).
Related¶
- systems/cloudflare-workers — the multi-tenant platform DyPrIs protects.
- systems/v8-javascript-engine — the isolate engine whose heaps DyPrIs protects across.
- systems/v8-sandbox — sibling defense layer (raw-pointer removal).
- spectre-attack — the attack DyPrIs detects.
- speculative-execution — the underlying CPU behavior.
- memory-protection-keys — sibling hardware isolation layer.
- concepts/tenant-isolation — the boundary DyPrIs enforces via process separation.
- concepts/defense-in-depth — DyPrIs as one composed layer.
- companies/cloudflare — author.