SpecCFI: Mitigating Spectre Attacks using CFI Informed Speculation

SpecCFI: Mitigating Spectre Attacks using CFI Informed Speculation
复制标题

SpecCFI:使用 CFI 知​​情推测减轻幽灵攻击

DOI:
--
复制
发表时间:
2019
期刊:
IEEE Symposium on Security and Privacy
影响因子:
--
通讯作者:
N. Abu
N. Abu
中科院分区:
--
文献类型:
--
作者:
Esmaeil Mohammadian Koruyeh;Shirin Haji Amin Shirazi;Khaled N. Khasawneh;Chengyu Song;N. Abu

文献摘要

被引文献

相似文献

Spectre攻击及其许多后续变种是影响现代CPU的新漏洞类别。这些攻击依赖于误导推测性执行的能力,通常通过利用分支预测结构来推测性地执行易受攻击的代码序列。在本文中,我们建议使用控制流完整性(CFI),一种用于阻止控制流劫持攻击的安全技术,在提交的路径上,以防止投机控制流被劫持发动最危险的变种的幽灵攻击(幽灵BTB和幽灵RSB)。具体地说,CFI试图将间接分支的可能目标约束到由预先计算的控制流图(CFG)定义的一组法律的目标。随着CFI被商品软件(例如,Windows和Android)和商用硬件(例如,Intel的CET和ARM的BTI),CFI信息通过硬件CFI扩展变得随时可用。与CFI信息,我们应用CFI原则,也限制非法的控制流在投机执行。具体来说,我们提出的防御,SpecCFI,确保控制流指令的目标法律的目的地,以限制危险的推测正向控制流路径(间接调用和分支)。我们增加了这种保护与精确的投机意识的硬件堆栈,以限制投机的反向控制流边缘(回报)。我们将联合收割机与现有的解决方案相结合,以对抗分支目标预测攻击(Spectre-PHT),从而关闭所有已知的非特定于供应商的Spectre漏洞。我们表明,SpecCFI的结果在小开销的性能和额外的硬件复杂性。
Spectre attacks and their many subsequent variants are a new vulnerability class affecting modern CPUs. The attacks rely on the ability to misguide speculative execution, generally by exploiting the branch prediction structures, to execute a vulnerable code sequence speculatively. In this paper, we propose to use Control-Flow Integrity (CFI), a security technique used to stop control-flow hijacking attacks, on the committed path, to prevent speculative control-flow from being hijacked to launch the most dangerous variants of the Spectre attacks (Spectre-BTB and Spectre-RSB). Specifically, CFI attempts to constrain the possible targets of an indirect branch to a set of legal targets defined by a pre-calculated control-flow graph (CFG). As CFI is being adopted by commodity software (e.g., Windows and Android) and commodity hardware (e.g., Intel’s CET and ARM’s BTI), the CFI information becomes readily available through the hardware CFI extensions. With the CFI information, we apply CFI principles to also constrain illegal control-flow during speculative execution. Specifically, our proposed defense, SpecCFI, ensures that control flow instructions target legal destinations to constrain dangerous speculation on forward control-flow paths (indirect calls and branches). We augment this protection with a precise speculation-aware hardware stack to constrain speculation on backward control-flow edges (returns). We combine this solution with existing solutions against branch target predictor attacks (Spectre-PHT) to close all known non-vendor-specific Spectre vulnerabilities. We show that SpecCFI results in small overheads both in terms of performance and additional hardware complexity.