Exploring Branch Predictors for Constructing Transient Execution Trojans

Exploring Branch Predictors for Constructing Transient Execution Trojans
复制标题

探索用于构建瞬态执行木马的分支预测器

DOI:
10.1145/3373376.3378526
复制
发表时间:
2020
期刊:
ASPLOS '20: Proceedings of the Twenty-Fifth International Conference on Architectural Support for Programming Languages and Operating Systems
影响因子:
--
通讯作者:
Evtyushkin, Dmitry
Evtyushkin, Dmitry
中科院分区:
--
文献类型:
--
作者:
Zhang, Tao;Koltermann, Kenneth;Evtyushkin, Dmitry

文献摘要

参考文献

被引文献

相似文献

瞬态执行是CPU中用于实现高性能的最关键特性之一。最近的Spectre攻击展示了如何操纵此功能以迫使应用程序泄露敏感数据。业界迅速采取了一系列软件和硬件缓解措施,其中微码补丁是最普遍和最受信任的。在本文中,我们认为,目前部署的保护措施仍然为构建攻击留下了空间。我们这样做是通过提出瞬时木马,软件模块,隐藏其恶意活动在瞬时执行模式。它们看起来完全是良性的,通过静态和动态分析检查,但在触发时会泄露敏感数据。要构建这些木马,我们执行一个详细的分析,目前在今天的系统中存在的攻击面相对于建议的缓解技术。我们逆向工程分支预测在最近的几个x86_64处理器,使我们能够发现以前未知的剥削技术。使用这些技术,我们构建了三种类型的瞬时木马,并展示了它们的隐蔽性和实用性。
Transient execution is one of the most critical features used in CPUs to achieve high performance. Recent Spectre attacks demonstrated how this feature can be manipulated to force applications to reveal sensitive data. The industry quickly responded with a series of software and hardware mitigations among which microcode patches are the most prevalent and trusted. In this paper, we argue that currently deployed protections still leave room for constructing attacks. We do so by presenting transient trojans, software modules that conceal their malicious activity within transient execution mode. They appear completely benign, pass static and dynamic analysis checks, but reveal sensitive data when triggered. To construct these trojans, we perform a detailed analysis of the attack surface currently present in today's systems with respect to the recommended mitigation techniques. We reverse engineer branch predictors in several recent x86_64 processors which allows us to uncover previously unknown exploitation techniques. Using these techniques, we construct three types of transient trojans and demonstrate their stealthiness and practicality.
通过随机数生成器的隐蔽通道:机制、容量估计和缓解措施
DOI: 10.1145/2976749.2978374
发表时间: 2016
期刊: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Dmitry Evtyushkin;D. Ponomarev
通讯作者: D. Ponomarev
分支目标缓冲区设计与优化
DOI: 10.1109/12.214687
发表时间: 1993
期刊: IEEE Trans. Computers
影响因子: --
作者:
Chris H. Perleberg;A. Smith
通讯作者: A. Smith
衡量幽灵和崩溃的影响
DOI: 10.1109/hpec.2018.8547554
发表时间: 2018
期刊: 2018 IEEE High Performance extreme Computing Conference (HPEC)
影响因子: --
作者:
Andrew Prout;W. Arcand;David Bestor;Bill Bergeron;C. Byun;V. Gadepally;Michael Houle;M. Hubbell;Michael Jones;Anna Klein;P. Michaleas;Lauren Milechin;J. Mullen;Antonio Rosa;S. Samsi;Charles Yee;A. Reuther;J. Kepner
通讯作者: J. Kepner
利用硬件事务内存进行缓存侧通道防御
DOI: 10.1145/3196494.3196501
发表时间: 2018
期刊: Proceedings of the 2018 on Asia Conference on Computer and Communications Security
影响因子: --
作者:
Sanchuan Chen;Fangfei Liu;Zeyu Mi;Yinqian Zhang;R. Lee;Haibo Chen;Xiaofeng Wang
通讯作者: Xiaofeng Wang
DOI: 10.1145/1315245.1315313
发表时间: 2007-10
期刊: --
影响因子: --
作者:
H. Shacham
通讯作者: H. Shacham