You Shall Not Bypass: Employing data dependencies to prevent Bounds Check Bypass
You Shall Not Bypass: Employing data dependencies to prevent Bounds Check Bypass
复制标题
您不应绕过:利用数据依赖关系来防止边界检查绕过
DOI:
--
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
C. Fetzer
中科院分区:
文献类型:
--
作者:
O. Oleksenko;Bohdan Trach;T. Reiher;M. Silberstein;C. Fetzer
A recent discovery of a new class of microarchitectural attacks called Spectre picked up the attention of the security community as these attacks can overcome many traditional mechanisms of defense, such as bounds checking. One of the attacks - Bounds Check Bypass - can neither be efficiently solved on system nor architectural levels, and requires changes in the application itself. So far, the proposed mitigations involved serialization, which reduces the usage of CPU resources and causes high overheads. In this work, we propose a method of only delaying the vulnerable instructions, without the necessity to completely serialize execution. Our prototype implemented as an LLVM pass causes 60% overhead across Phoenix benchmark suite, which compares favorably to the full serialization causing 440% slowdown.