Speculative Execution Attacks and Hardware Defenses

Speculative Execution Attacks and Hardware Defenses
复制标题

推测执行攻击和硬件防御

DOI:
10.1145/3474376.3487404
复制
发表时间:
2021
期刊:
ASHES '21: Proceedings of the 5th Workshop on Attacks and Solutions in Hardware Security
影响因子:
--
通讯作者:
Lee, Ruby B.
Lee, Ruby B.
中科院分区:
--
文献类型:
--
作者:
Lee, Ruby B.

文献摘要

相似文献

像Spectre和Meltdown这样的投机性执行攻击利用硬件性能优化功能非法获取机密,然后将机密泄露给未经授权的接收者。在过去的几年里,已经提出了许多投机性执行攻击(也称为瞬时执行攻击)的变体,并且不断地发现新的攻击。虽然已经提出了针对某些攻击的软件缓解措施,但它们通常会导致非常显著的性能下降。研究界也在积极提出硬件解决方案,特别是因为这些解决方案是对硬件微体系结构的攻击。在这次演讲中,我们将确定投机性攻击的关键步骤,以及成功攻击的根本原因。我们定义了“安全依赖”的概念,应该实施这一概念以防止数据泄露和其他安全漏洞。我们提出了防御战略的分类,并展示了所建议的硬件防御如何归入每种防御战略。我们将讨论安全与性能之间的权衡,这可以降低性能开销,同时仍能防止安全漏洞。我们建议了未来安全感知微体系结构的设计原则。
Speculative execution attacks like Spectre and Meltdown exploit hardware performance optimization features to illegally access a secret and then leak the secret to an unauthorized recipient. Many variants of speculative execution attacks (also called transient execution attacks) have been proposed in the last few years, and new ones are constantly being discovered. While software mitigations for some attacks have been proposed, they often cause very significant performance degradation. Hardware solutions are also being proposed actively by the research community, especially as these are attacks on hardware microarchitecture. In this talk, we identify the critical steps in a speculative attack, and the root cause of successful attacks. We define the concept of "security dependencies", which should be implemented to prevent data leaks and other security breaches. We propose a taxonomy of defense strategies and show how proposed hardware defenses fall under each defense strategy. We discuss security-performance tradeoffs, which can decrease the performance overhead while still preventing security breaches. We suggest design principles for future security-aware microarchitecture.