Defeating Speculative-Execution Attacks on SGX with HyperRace

Defeating Speculative-Execution Attacks on SGX with HyperRace
复制标题

DOI:
10.1109/dsc47296.2019.8937682
复制
发表时间:
2019-11
期刊:
2019 IEEE Conference on Dependable and Secure Computing (DSC)
影响因子:
--
通讯作者:
Guoxing Chen;Mengyuan Li;Fengwei Zhang;Yinqian Zhang
Guoxing Chen;Mengyuan Li;Fengwei Zhang;Yinqian Zhang
中科院分区:
其他
文献类型:
--
作者:
Guoxing Chen;Mengyuan Li;Fengwei Zhang;Yinqian Zhang

文献摘要

相似文献

投机执行攻击(如SgxSpectre、Foreshadow和MDS攻击)利用最近披露的CPU硬件漏洞和微架构侧通道来破坏英特尔Software Guard eXtensions(SGX)的机密性和完整性。与传统的微架构侧信道攻击不同,推测执行攻击提取飞地内存中的任何数据,这使得它们很难从软件中击败。然而,到目前为止,英特尔还没有完全减轻硬件投机执行攻击的威胁。因此,未来的攻击变种可能会出现。本文提出了一种基于软件的解决方案,投机执行攻击,即使有很强的假设,安全区内存的机密性受到损害。我们的解决方案扩展了现有的工作称为HyperRace,这是一个编译器辅助工具,用于检测基于超线程的侧通道攻击SGX飞地,以阻止投机性执行攻击SGX飞地内。它需要来自不受信任的操作系统的支持,例如,用于暂时禁用中断,但验证操作系统的行为。需要英特尔进行额外的微码升级,以确保认证流程的安全。
Speculative-execution attacks, such as SgxSpectre, Foreshadow, and MDS attacks, leverage recently disclosed CPU hardware vulnerabilities and micro-architectural side channels to breach the confidentiality and integrity of Intel Software Guard eXtensions (SGX). Unlike traditional micro-architectural side-channel attacks, speculative-execution attacks extract any data in the enclave memory, which makes them very challenging to defeat purely from the software. However, to date, Intel has not completely mitigated the threats of speculative-execution attacks from the hardware. Hence, future attack variants may emerge. This paper proposes a software-based solution to speculative-execution attacks, even with the strong assumption that confidentiality of enclave memory is compromised. Our solution extends an existing work called HyperRace, which is a compiler-assisted tool for detecting Hyper-Threading based side-channel attacks against SGX enclaves, to thwart speculative-execution attacks from within SGX enclaves. It requires supports from the untrusted operating system, e.g., for temporarily disabling interrupts, but verifies the OS's behaviors. Additional microcode upgrades are required from Intel to secure the attestation flow.