SpecTaint: Speculative Taint Analysis for Discovering Spectre Gadgets
SpecTaint: Speculative Taint Analysis for Discovering Spectre Gadgets
复制标题
SpecTaint:用于发现 Spectre 小工具的推测性污点分析
DOI:
10.14722/ndss.2021.24466
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
Tao Wei
中科院分区:
文献类型:
--
作者:
Zhenxiao Qi;Qian Feng;Yueqiang Cheng;Mengjia Yan;Peng Li;Heng Yin;Tao Wei
—Software patching is a crucial mitigation approach against Spectre-type attacks. It utilizes serialization instructions to disable speculative execution of potential Spectre gadgets in a program. Unfortunately, there are no effective solutions to detect gadgets for Spectre-type attacks. In this paper, we propose a novel Spectre gadget detection technique by enabling dynamic taint analysis on speculative execution paths. To this end, we simulate and explore speculative execution at system level (within a CPU emulator). We have implemented a prototype called SpecTaint to demonstrate the efficacy of our proposed approach. We evaluated SpecTaint on our Spectre Samples Dataset, and compared SpecTaint with existing state-of-the-art Spectre gadget detection approaches on real-world applications. Our experimental results demonstrate that SpecTaint outperforms existing methods with respect to detection precision and recall by large margins, and it also detects new Spectre gadgets in real-world applications such as Caffe and Brotli. Besides, SpecTaint significantly reduces the performance overhead after patching the detected gadgets, compared with other approaches.
DOI:
10.1145/3359789.3359837
发表时间:
2019-12
期刊:
Proceedings of the 35th Annual Computer Security Applications Conference
影响因子:
--
作者:
Andrea Mambretti;M. Neugschwandtner;A. Sorniotti;E. Kirda;William K. Robertson;Anil Kurmus
通讯作者:
Andrea Mambretti;M. Neugschwandtner;A. Sorniotti;E. Kirda;William K. Robertson;Anil Kurmus