Two methods for exploiting speculative control flow hijacks

Two methods for exploiting speculative control flow hijacks
复制标题

利用推测性控制流劫持的两种方法

DOI:
--
复制
发表时间:
2019
期刊:
WOOT @ USENIX Security Symposium
影响因子:
--
通讯作者:
Anil Kurmus
Anil Kurmus
中科院分区:
--
文献类型:
--
作者:
Andrea Mambretti;A. Sandulescu;M. Neugschwandtner;A. Sorniotti;Anil Kurmus

文献摘要

被引文献

相似文献

Spectre和Meltdown被吹捧为时代的缓冲区溢出,引起了人们对微体系结构漏洞的极大兴趣,并有助于发现新的攻击类别。然而,到目前为止,现实世界中的漏洞攻击还很少见,因为它们要么需要难以定位的小工具,要么需要攻击者注入代码的能力。在这项工作中,我们发现了两类新的小工具,它们的结构限制非常少,使它们适合于现实世界的开发。我们通过POC演示了它们在每次成功攻击时分别泄漏1比特和1字节的适宜性,从而在构建的副信道上实现了高成功率和低噪声。我们在启用了默认缓解的各种内核上测试了我们的攻击PoC,显示了它们如何不足以防御它们。我们还表明,强化缓解的配置可以成功地防止利用漏洞,从而为更广泛地采用它们提供了理由。
Touted as the buffer overflows of the age, Spectre and Meltdown have created significant interest around microarchitectural vulnerabilities and have been instrumental for the discovery of new classes of attacks. Yet, todate, real-world exploits are rare since they often either require gadgets that are difficult to locate, or they require the ability of the attacker to inject code. In this work, we uncover two new classes of gadgets with very few restrictions on their structure, making them suitable for real-world exploitation. We demonstrate – through PoCs – their suitability to leak one bit and one byte respectively per successful attack, achieving high success rates and low noise on the constructed side-channel. We test our attack PoC on various kernels with default mitigations enabled, showing how they are insufficient to protect against them. We also show that hardening the configuration of mitigations successfully prevents exploitation, making a case for their wider adoption.