Safecracker: Leaking Secrets through Compressed Caches

Safecracker: Leaking Secrets through Compressed Caches
复制标题

Safecracker:通过压缩缓存泄露秘密

DOI:
10.1145/3373376.3378453
复制
发表时间:
2020
期刊:
Proceedings of the 25th international conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS-25
影响因子:
--
通讯作者:
Sanchez, Daniel
Sanchez, Daniel
中科院分区:
--
文献类型:
--
作者:
Tsai, Po-An;Sanchez, Andres;Fletcher, Christopher W.;Sanchez, Daniel

文献摘要

参考文献

被引文献

相似文献

最近的投机性执行攻击所带来的硬件安全危机表明,采用安全意识的方法来研究架构是至关重要的,在将有前途的架构技术部署到硬件之前,分析它们的安全性。本文提供了高速缓存压缩,这样一个有前途的技术,很可能出现在未来的处理器的第一个安全分析。我们发现,高速缓存压缩是不安全的,因为一个高速缓存行的压缩性揭示了其内容的信息。压缩缓存引入了一个新的侧通道,这是特别阴险的,因为简单地存储数据传输有关它的信息。我们提出了两种技术,使压缩缓存的攻击实际。Pack+Probe允许攻击者了解受害者缓存行的可压缩性,Safecracker通过策略性地改变附近数据的值来有效地泄漏秘密数据。我们对一个概念验证应用程序的评估表明,在一个常见的压缩缓存架构上,Safecracker让攻击者在10毫秒内破解一个密钥,更糟糕的是,当与潜在的内存安全漏洞结合使用时,会泄漏大部分程序内存。我们还讨论了潜在的方法来关闭这个新的压缩引起的侧通道。我们希望这项工作可以防止不安全的缓存压缩技术进入主流处理器。
The hardware security crisis brought on by recent speculative execution attacks has shown that it is crucial to adopt a security-conscious approach to architecture research, analyzing the security of promising architectural techniques before they are deployed in hardware. This paper offers the first security analysis of cache compression, one such promising technique that is likely to appear in future processors. We find that cache compression is insecure because the compressibility of a cache line reveals information about its contents. Compressed caches introduce a new side channel that is especially insidious, as simply storing data transmits information about it. We present two techniques that make attacks on compressed caches practical. Pack+Probe allows an attacker to learn the compressibility of victim cache lines, and Safecracker leaks secret data efficiently by strategically changing the values of nearby data. Our evaluation on a proof-of-concept application shows that, on a common compressed cache architecture, Safecracker lets an attacker compromise a secret key in under 10ms, and worse, leak large fractions of program memory when used in conjunction with latent memory safety vulnerabilities. We also discuss potential ways to close this new compression-induced side channel. We hope this work prevents insecure cache compression techniques from reaching mainstream processors.
通过随机数生成器的隐蔽通道:机制、容量估计和缓解措施
DOI: 10.1145/2976749.2978374
发表时间: 2016
期刊: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Dmitry Evtyushkin;D. Ponomarev
通讯作者: D. Ponomarev
CompressPoints:压缩内存系统的评估方法
DOI: 10.1109/lca.2018.2821163
发表时间: 2018
影响因子: 2.3
作者:
Choukse, Esha;Erez, Mattan;Alameldeen, Alaa
通讯作者: Alameldeen, Alaa
重新思考现代语言的内存层次结构
DOI: --
发表时间: 2018
期刊: Micro
影响因子: --
作者:
Po;Yee Ling Gan;Daniel Sánchez
通讯作者: Daniel Sánchez
零内容增强缓存
DOI: --
发表时间: 2009
期刊: International Conference on Supercomputing
影响因子: --
作者:
J. Dusser;T. Piquet;André Seznec
通讯作者: André Seznec
DOI: 10.14722/ndss.2019.23061
发表时间: 2018
期刊: IACR Cryptol. ePrint Arch.
影响因子: --
作者:
Jiyong Yu;Lucas Hsiung;Mohamad El Hajj;Christopher W. Fletcher
通讯作者: Jiyong Yu;Lucas Hsiung;Mohamad El Hajj;Christopher W. Fletcher