SpectreRewind: Leaking Secrets to Past Instructions
SpectreRewind: Leaking Secrets to Past Instructions
复制标题
DOI:
10.1145/3411504.3421216
复制
发表时间:
2020-03
期刊:
影响因子:
--
通讯作者:
Jacob Fustos;M. Bechtel;H. Yun
中科院分区:
文献类型:
--
作者:
Jacob Fustos;M. Bechtel;H. Yun
Transient execution attacks use microarchitectural covert channels to leak secrets that should not have been accessible during logical program execution. Commonly used micro-architectural covert channels are those that leave lasting footprints in the micro-architectural state, for example, a cache state change, from which the secret is recovered after the transient execution is completed. In this paper, we present SpectreRewind, a new approach to create and exploit contention-based covert channels for transient execution attacks. In our approach, a covert channel is established by issuing the necessary instructions logically before the transiently executed victim code. Unlike prior contention based covert channels, which require simultaneous multi-threading (SMT), SpectreRewind supports covert channels based on a single hardware thread, making it viable on systems where the attacker cannot utilize SMT. We show that contention on the floating point division unit on commodity processors can be used to create a high-performance (~100 KB/s), low-noise covert channel for transient execution attacks instead of commonly used flush+reload based cache covert channels. We also show that the proposed covert channel works in the JavaScript sandbox environment of a Chrome browser.