Adversarial Prefetch: New Cross-Core Cache Side Channel Attacks

Adversarial Prefetch: New Cross-Core Cache Side Channel Attacks
复制标题

DOI:
10.1109/sp46214.2022.9833692
复制
发表时间:
2021-10
期刊:
2022 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Yanan Guo;Andrew Zigerelli;Youtao Zhang;Jun Yang
Yanan Guo;Andrew Zigerelli;Youtao Zhang;Jun Yang
中科院分区:
其他
文献类型:
--
作者:
Yanan Guo;Andrew Zigerelli;Youtao Zhang;Jun Yang

文献摘要

被引文献

相似文献

现代x86处理器有许多预取指令,程序员可以使用这些指令来提高性能。然而,这些说明也可能导致安全问题。特别是,我们发现在Intel处理器上,PREFETCHW的实现存在两个安全缺陷,PREFETCHW是一种用于加速未来写入的指令。首先,此指令可以在具有只读权限的数据上执行。其次,此指令的执行时间会泄漏目标数据的当前一致性状态。基于这两个设计问题,我们构建了两种同时适用于包含性和非包含性LLC的跨核私有缓存攻击,分别称为预取+重新加载和预取+预取。我们在不同的情况下展示了我们的攻击的重要性。首先,在隐蔽通道的情况下,当发送方和接收方之间仅使用一条共享缓存线时,预取+重新加载和预取+预取达到782KB/S和822KB/S的通道容量,这是迄今为止用于CPU缓存隐蔽通道的最大单线容量。此外,在旁信道情况下,我们的攻击可以监测受害者在同一处理器上的访问模式,几乎没有误码率。我们证明了它们可以被用来泄露真实世界应用程序的私人信息,例如密钥。最后,我们的攻击可以用于瞬时执行攻击,以便在瞬时窗口内泄漏比以前的工作更多的秘密。从实验结果来看,与瞬时执行攻击中广泛使用的刷新+重新加载相比,我们的攻击允许泄漏大约2倍的秘密字节。
Modern x86 processors have many prefetch instructions that can be used by programmers to boost performance. However, these instructions may also cause security problems. In particular, we found that on Intel processors, there are two security flaws in the implementation of PREFETCHW, an instruction for accelerating future writes. First, this instruction can execute on data with read-only permission. Second, the execution time of this instruction leaks the current coherence state of the target data. Based on these two design issues, we build two cross-core private cache attacks that work with both inclusive and non-inclusive LLCs, named Prefetch+Reload and Prefetch+Prefetch. We demonstrate the significance of our attacks in different scenarios. First, in the covert channel case, Prefetch+Reload and Prefetch+Prefetch achieve 782 KB/s and 822 KB/s channel capacities, when using only one shared cache line between the sender and receiver, the largest-to-date single-line capacities for CPU cache covert channels. Further, in the side channel case, our attacks can monitor the access pattern of the victim on the same processor, with almost zero error rate. We show that they can be used to leak private information of real-world applications such as cryptographic keys. Finally, our attacks can be used in transient execution attacks in order to leak more secrets within the transient window than prior work. From the experimental results, our attacks allow leaking about 2 times as many secret bytes, compared to Flush+Reload, which is widely used in transient execution attacks.