CacheOut: Leaking Data on Intel CPUs via Cache Evictions

CacheOut: Leaking Data on Intel CPUs via Cache Evictions
复制标题

DOI:
10.1109/sp40001.2021.00064
复制
发表时间:
2020-06
期刊:
2021 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
S. V. Schaik;Marina Minkin;Andrew Kwong;Daniel Genkin;Y. Yarom
S. V. Schaik;Marina Minkin;Andrew Kwong;Daniel Genkin;Y. Yarom
中科院分区:
其他
文献类型:
--
作者:
S. V. Schaik;Marina Minkin;Andrew Kwong;Daniel Genkin;Y. Yarom

文献摘要

被引文献

相似文献

最近的瞬态执行攻击,例如RIDL,Altout和Zombieload,表明攻击者可以通过微体系式缓冲区泄漏信息,以示为Microarchitectural Data Sampling(MDS)。由于攻击者对观察到的数据几乎没有控制,并且从哪些原点无法防止缓冲区泄漏,因此英特尔通过Microcode更新发布了对策能够绕过Intel的缓冲区对策的微体系攻击。我们观察到数据被从CPU的L1缓存中驱逐出来,通常会将其转移回泄漏的CPU缓冲区。攻击者允许攻击者选择从CPU的L1缓存泄漏的数据,以及要泄漏的缓存线的哪一部分。和内核空间,以及来自SGX飞地。
Recent transient-execution attacks, such as RIDL, Fallout, and ZombieLoad, demonstrated that attackers can leak information while it transits through microarchitectural buffers. Named Microarchitectural Data Sampling (MDS) by Intel, these attacks are likened to "drinking from the firehose", as the attacker has little control over what data is observed and from what origin. Unable to prevent the buffers from leaking, Intel issued countermeasures via microcode updates that overwrite the buffers when the CPU changes security domains.In this work we present CacheOut, a new microarchitectural attack that is capable of bypassing Intel’s buffer overwrite countermeasures. We observe that as data is being evicted from the CPU’s L1 cache, it is often transferred back to the leaky CPU buffers where it can be recovered by the attacker. CacheOut improves over previous MDS attacks by allowing the attacker to choose which data to leak from the CPU’s L1 cache, as well as which part of a cache line to leak. We demonstrate that CacheOut can leak information across multiple security boundaries, including those between processes, virtual machines, user and kernel space, and from SGX enclaves.