SpectreRewind: Leaking Secrets to Past Instructions

SpectreRewind: Leaking Secrets to Past Instructions
复制标题

DOI:
10.1145/3411504.3421216
复制
发表时间:
2020-03
期刊:
Proceedings of the 4th ACM Workshop on Attacks and Solutions in Hardware Security
影响因子:
--
通讯作者:
Jacob Fustos;M. Bechtel;H. Yun
Jacob Fustos;M. Bechtel;H. Yun
中科院分区:
其他
文献类型:
--
作者:
Jacob Fustos;M. Bechtel;H. Yun

文献摘要

被引文献

相似文献

瞬态执行攻击使用微体系式秘密通道来泄漏在逻辑程序执行过程中不应访问的秘密。常用的微构造秘密渠道是那些在微构造状态下留下持久足迹的渠道,例如,缓存状态变化,在暂时执行完成后,秘密从中恢复了秘密。在本文中,我们提出了SpectrereWind,这是一种创建和利用基于竞争的秘密频道的新方法,以进行瞬态执行攻击。在我们的方法中,通过在瞬时执行受害者代码之前逻辑地发布必要的说明来建立秘密渠道。与需要同时进行多线程(SMT)的基于争夺的秘密通道不同,SpectrereWind支持基于单个硬件线程的掩护通道,这使其可行在攻击者无法利用SMT的系统上。我们表明,可以使用商品处理器对浮点分区单位的争论来创建高性能(〜100 kb/s),用于短暂执行攻击的低噪声掩护通道,而不是常用的flush+基于常用的flush+基于重新加载的cache covert Channel 。我们还表明,拟议的秘密频道在Chrome浏览器的JavaScript沙盒环境中起作用。
Transient execution attacks use microarchitectural covert channels to leak secrets that should not have been accessible during logical program execution. Commonly used micro-architectural covert channels are those that leave lasting footprints in the micro-architectural state, for example, a cache state change, from which the secret is recovered after the transient execution is completed. In this paper, we present SpectreRewind, a new approach to create and exploit contention-based covert channels for transient execution attacks. In our approach, a covert channel is established by issuing the necessary instructions logically before the transiently executed victim code. Unlike prior contention based covert channels, which require simultaneous multi-threading (SMT), SpectreRewind supports covert channels based on a single hardware thread, making it viable on systems where the attacker cannot utilize SMT. We show that contention on the floating point division unit on commodity processors can be used to create a high-performance (~100 KB/s), low-noise covert channel for transient execution attacks instead of commonly used flush+reload based cache covert channels. We also show that the proposed covert channel works in the JavaScript sandbox environment of a Chrome browser.