Foreshadow-NG: Breaking the virtual memory abstraction with transient out-of-order execution

Foreshadow-NG: Breaking the virtual memory abstraction with transient out-of-order execution
复制标题

DOI:
--
复制
发表时间:
2018-08
期刊:
--
影响因子:
--
通讯作者:
Ofir Weisse;Jo Van Bulck;Marina Minkin;Daniel Genkin;Baris Kasikci;Frank Piessens;M. Silberstein;Raoul Strackx;T. Wenisch;Y. Yarom
Ofir Weisse;Jo Van Bulck;Marina Minkin;Daniel Genkin;Baris Kasikci;Frank Piessens;M. Silberstein;Raoul Strackx;T. Wenisch;Y. Yarom
中科院分区:
其他
文献类型:
--
作者:
Ofir Weisse;Jo Van Bulck;Marina Minkin;Daniel Genkin;Baris Kasikci;Frank Piessens;M. Silberstein;Raoul Strackx;T. Wenisch;Y. Yarom

文献摘要

被引文献

相似文献

在2018年1月,我们发现了针对英特尔SGX技术的预示瞬态执行攻击(USENIX SECurity'18)。当前的分析主要集中在缓解策略上,仅提供对攻击本身及其后果的洞察力。高水平的区域,而上一代的崩溃型攻击仅限于在攻击者的虚拟地址空间中读取特权主管数据,预示了攻击完全绕开虚拟内存抽象。虚拟机器。由于最近对攻击的披露,尤其是预示的攻击及其在写作时的含义,我们的理解可能是不完整的,尽管我们已经尽力验证了描述的正确性,但我们可能会陷入困境。
In January 2018, we discovered the Foreshadow transient execution attack (USENIX Security’18) targeting Intel SGX technology. Intel’s subsequent investigation of our attack uncovered two closely related variants, which we collectively call Foreshadow-NG and which Intel refers to as L1 Terminal Fault. Current analyses focus mostly on mitigation strategies, providing only limited insight into the attacks themselves and their consequences. The aim of this report is to alleviate this situation by thoroughly analyzing Foreshadow-type attacks and their implications in the light of the emerging transient execution research area. At a high level, whereas previous generation Meltdown-type attacks are limited to reading privileged supervisor data within the attacker’s virtual address space, Foreshadow-NG attacks completely bypass the virtual memory abstraction by directly exposing cached physical memory contents to unprivileged applications and guest virtual machines. We review mitigation strategies proposed by Intel, and explain how Foreshadow-NG necessitates additional OS and hypervisor-level defense mechanisms on top of existing Meltdown mitigations. Disclaimer. This is an evolving document, which presents our understanding of Foreshadow / L1 Terminal Fault attacks and their implications at the time of writing. Due to the recent disclosure of the attacks, and in particular of Foreshadow-NG, our understanding may be incomplete, and while we have done our best to verify the correctness of the description, inaccuracies may have fallen. We aim to correct such inaccuracies and omissions in future revisions of this document.