Faulty Point Unit: ABI Poisoning Attacks on Intel SGX

Faulty Point Unit: ABI Poisoning Attacks on Intel SGX
复制标题

DOI:
10.1145/3427228.3427270
复制
发表时间:
2020-12
期刊:
Proceedings of the 36th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
F. Alder;Jo Van Bulck;David F. Oswald;Frank Piessens
F. Alder;Jo Van Bulck;David F. Oswald;Frank Piessens
中科院分区:
其他
文献类型:
--
作者:
F. Alder;Jo Van Bulck;David F. Oswald;Frank Piessens

文献摘要

被引文献

相似文献

本文分析了一个以前被忽视的攻击面,该攻击面允许非特权攻击者通过应用程序二进制接口(ABI)影响Intel SGX Enclaves中本应安全的浮点计算。在对7个广泛使用的行业标准和研究Enclave屏蔽运行时进行的全面研究中,我们发现,在Enclave条目上,x87浮点单元(FPU)和英特尔流SIMD扩展(SSE)的控制和状态寄存器并不总是得到适当的清理。首先,我们滥用对手对精度和舍入模式的控制,将其作为一个新颖的“ABI级错误注入”原语,以静默地破坏包围式浮点运算,从而启用一类新的隐蔽的、仅限完整性的攻击,这些攻击扰乱了SGX Enclave计算的结果。我们的分析表明,这种威胁对于使用较旧的X87FPU的应用程序尤其相关,在某些条件下,像GCC这样的现代编译器仍在使用该处理器进行高精度操作。我们在一个封闭的机器学习服务的案例研究和对SPEC基准程序的更大分析中举例说明了ABI级别质量降级攻击的潜在影响。其次,我们通过展示对手对浮点异常掩码的控制可以被滥用来作为在某些场景中检测FPU使用和恢复被包围的乘法操作数的创新受控通道来探索对Enclave保密性的影响。我们的发现影响了所研究的7个运行时中的5个,证明了在当代x86硬件上实现高保证的可信执行环境的谬误和挑战。我们负责任地向供应商披露了我们的发现,并被分配了两个CVE,导致Intel SGX-SDK、Microsoft OpenEnclave、Rust编译器的SGX目标和Go-Te中的补丁。
This paper analyzes a previously overlooked attack surface that allows unprivileged adversaries to impact supposedly secure floating-point computations in Intel SGX enclaves through the Application Binary Interface (ABI). In a comprehensive study across 7 widely used industry-standard and research enclave shielding runtimes, we show that control and state registers of the x87 Floating-Point Unit (FPU) and Intel Streaming SIMD Extensions (SSE) are not always properly sanitized on enclave entry. First, we abuse the adversary’s control over precision and rounding modes as a novel “ABI-level fault injection” primitive to silently corrupt enclaved floating-point operations, enabling a new class of stealthy, integrity-only attacks that disturb the result of SGX enclave computations. Our analysis reveals that this threat is especially relevant for applications that use the older x87 FPU, which is still being used under certain conditions for high-precision operations by modern compilers like gcc. We exemplify the potential impact of ABI-level quality-degradation attacks in a case study of an enclaved machine learning service and in a larger analysis on the SPEC benchmark programs. Second, we explore the impact on enclave confidentiality by showing that the adversary’s control over floating-point exception masks can be abused as an innovative controlled channel to detect FPU usage and to recover enclaved multiplication operands in certain scenarios. Our findings, affecting 5 out of the 7 studied runtimes, demonstrate the fallacy and challenges of implementing high-assurance trusted execution environments on contemporary x86 hardware. We responsibly disclosed our findings to the vendors and were assigned two CVEs, leading to patches in the Intel SGX-SDK, Microsoft OpenEnclave, the Rust compiler’s SGX target, and Go-TEE.