Speculator: a tool to analyze speculative execution attacks and mitigations

Speculator: a tool to analyze speculative execution attacks and mitigations
复制标题

DOI:
10.1145/3359789.3359837
复制
发表时间:
2019-12
期刊:
Proceedings of the 35th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Andrea Mambretti;M. Neugschwandtner;A. Sorniotti;E. Kirda;William K. Robertson;Anil Kurmus
Andrea Mambretti;M. Neugschwandtner;A. Sorniotti;E. Kirda;William K. Robertson;Anil Kurmus
中科院分区:
其他
文献类型:
--
作者:
Andrea Mambretti;M. Neugschwandtner;A. Sorniotti;E. Kirda;William K. Robertson;Anil Kurmus

文献摘要

被引文献

相似文献

投机执行攻击在CPU的微体系层面上剥削漏洞,直到最近,该漏洞仍隐藏在指令集体系结构下方,在很大程度上没有CPU供应商证明。每月发布新的投机执行攻击,表明如何利用So-FAR未开发的微体系攻击表面的各个方面。在本文中,我们介绍了一种投机者,这是一种研究这些新的微体系攻击及其缓解作用的新工具,该工具旨在成为投机执行的GDB。使用投机性执行标记,我们发现的一组指令是可以通过CPU投机期间的性能计数器观察到的,投机者可以研究代码单段的微体系式行为,或更复杂的攻击者和受害者场景(例如分支目标注入(BTI)攻击)。我们还在多个CPU平台上介绍了我们的发现,以显示投机者及其模板提供的精度和灵活性。
Speculative execution attacks exploit vulnerabilities at a CPU's microarchitectural level, which, until recently, remained hidden below the instruction set architecture, largely undocumented by CPU vendors. New speculative execution attacks are released on a monthly basis, showing how aspects of the so-far unexplored microarchitectural attack surface can be exploited. In this paper, we introduce, Speculator, a new tool to investigate these new microarchitectural attacks and their mitigations, which aims to be the GDB of speculative execution. Using speculative execution markers, set of instructions that we found are observable through performance counters during CPU speculation, Speculator can study microarchitectural behavior of single snippets of code, or more complex attacker and victim scenarios (e.g. Branch Target Injection (BTI) attacks). We also present our findings on multiple CPU platforms showing the precision and the flexibility offered by Speculator and its templates.