Spectres, virtual ghosts, and hardware support

Spectres, virtual ghosts, and hardware support
复制标题

DOI:
10.1145/3214292.3214297
复制
发表时间:
2018-06
期刊:
Proceedings of the 7th International Workshop on Hardware and Architectural Support for Security and Privacy
影响因子:
--
通讯作者:
Xiaowan Dong;Zhuojia Shen;J. Criswell;A. Cox;S. Dwarkadas
Xiaowan Dong;Zhuojia Shen;J. Criswell;A. Cox;S. Dwarkadas
中科院分区:
其他
文献类型:
--
作者:
Xiaowan Dong;Zhuojia Shen;J. Criswell;A. Cox;S. Dwarkadas

文献摘要

相似文献

利用投机性执行的旁渠道攻击,例如幽灵和崩溃,对计算系统构成了严重威胁。更糟糕的是,此类攻击可以通过折衷的操作系统(OS)内核进行绕过保护应用程序免受OS内核的防御措施进行犯罪。这项工作评估了三种不同防御措施对虚拟幽灵范围内的内核内部渠道攻击的性能影响,该系统保护用户数据免受损害的OS内核:Intel MPX界限检查,需要存储器围栏;地址位掩盖和测试,这在界限检查与负载/存储之间产生了依赖性;以及用于应用程序,OS内核和虚拟幽灵虚拟机的单独的虚拟地址空间,迫使投机边界。我们的结果表明,一种基于仪器的位掩蔽方法可以通过最大程度地减少投机界限来造成最少的开销。我们的工作还强调了英特尔MPX的可能改进,这可以帮助以较低的成本减轻猜测侧通道攻击。
Side-channel attacks, such as Spectre and Meltdown, that leverage speculative execution pose a serious threat to computing systems. Worse yet, such attacks can be perpetrated by compromised operating system (OS) kernels to bypass defenses that protect applications from the OS kernel. This work evaluates the performance impact of three different defenses against in-kernel speculation side-channel attacks within the context of Virtual Ghost, a system that protects user data from compromised OS kernels: Intel MPX bounds checks, which require a memory fence; address bit-masking and testing, which creates a dependence between the bounds check and the load/store; and the use of separate virtual address spaces for applications, the OS kernel, and the Virtual Ghost virtual machine, forcing a speculation boundary. Our results indicate that an instrumentation-based bit-masking approach to protection incurs the least overhead by minimizing speculation boundaries. Our work also highlights possible improvements to Intel MPX that could help mitigate speculation side-channel attacks at a lower cost.