The SEVerESt Of Them All: Inference Attacks Against Secure Virtual Enclaves

The SEVerESt Of Them All: Inference Attacks Against Secure Virtual Enclaves
复制标题

DOI:
10.1145/3321705.3329820
复制
发表时间:
2019-07
期刊:
Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Jan Werner;Joshua Mason;M. Antonakakis;M. Polychronakis;F. Monrose
Jan Werner;Joshua Mason;M. Antonakakis;M. Polychronakis;F. Monrose
中科院分区:
其他
文献类型:
--
作者:
Jan Werner;Joshua Mason;M. Antonakakis;M. Polychronakis;F. Monrose

文献摘要

相似文献

云计算的成功表明,外包基础架构,平台和软件资源的成本和便利益处超过了对机密性的关注。尽管如此,由于知识产权和隐私原因,许多企业和个人都拒绝将私人数据转移到云提供商。最近的硬件虚拟化技术浪潮旨在通过提供加密的虚拟化功能来减轻这些问题,从而支持来宾虚拟机机密性(例如,即使在最高信任的无信任的虚拟机上运行时,也可以通过透明地加密内存)。我们引入了两次新攻击,这些攻击可能违反受保护的飞地的机密性。首先,我们展示云对手如何才能明智地检查通用寄存器以揭示通过它们的计算。具体而言,我们演示了一组攻击,这些攻击可以准确地推断执行的指令,并最终捕获敏感数据,仅在间接访问CPU状态的情况下,如通过通用寄存器所观察到的。其次,我们表明,即使在更限制的环境下 - 不再可用通用寄存器的地方 - 我们可以应用不同的推理攻击来恢复未知的,运行,应用程序作为垫脚石的结构,以供应指纹指纹。我们通过展示对手如何识别不同的应用程序,甚至区分同一应用程序的版本和所使用的编译器,恢复通过加密来宾中的TLS连接传输的数据,以检索敏感数据的内容时,以确定敏感数据的内容,从而证明了这些推理攻击的实用性。客人正在从磁盘中阅读,并在来宾中注入任意数据。总体而言,这些攻击是一个警示性的故事,说明当寄存器状态(例如,在AMD的SEV中)和应用程序性能数据(例如,在AMD的SEV-ES中)不受保护。后者是旨在专门针对SEV-E的首次已知攻击。
The success of cloud computing has shown that the cost and convenience benefits of outsourcing infrastructure, platform, and software resources outweigh concerns about confidentiality. Still, many businesses and individuals resist moving private data to cloud providers due to intellectual property and privacy reasons. A recent wave of hardware virtualization technologies aims to alleviate these concerns by offering encrypted virtualization features that support data confidentiality of guest virtual machines (e.g., by transparently encrypting memory) even when running on top untrusted hypervisors. We introduce two new attacks that can breach the confidentiality of protected enclaves. First, we show how a cloud adversary can judiciously inspect the general purpose registers to unmask the computation that passes through them. Specifically, we demonstrate a set of attacks that can precisely infer the executed instructions and eventually capture sensitive data given only indirect access to the CPU state as observed via the general purpose registers. Second, we show that even under a more restrictive environment - where access to the general purpose registers is no longer available - we can apply a different inference attack to recover the structure of an unknown, running, application as a stepping stone towards application fingerprinting. We demonstrate the practicality of these inference attacks by showing how an adversary can identify different applications and even distinguish between versions of the same application and the compiler used, recover data transferred over TLS connections within the encrypted guest, retrieve the contents of sensitive data as it is being read from disk by the guest, and inject arbitrary data within the guest. Taken as a whole, these attacks serve as a cautionary tale of what can go wrong when the state of registers (e.g., in AMD's SEV) and application performance data (e.g. in AMD's SEV-ES) are left unprotected. The latter is the first known attack that was designed to specifically target SEV-ES.