You Shall Not Bypass: Employing data dependencies to prevent Bounds Check Bypass

You Shall Not Bypass: Employing data dependencies to prevent Bounds Check Bypass
复制标题

您不应绕过:利用数据依赖关系来防止边界检查绕过

DOI:
--
复制
发表时间:
2018
期刊:
arXiv.org
影响因子:
--
通讯作者:
C. Fetzer
C. Fetzer
中科院分区:
--
文献类型:
--
作者:
O. Oleksenko;Bohdan Trach;T. Reiher;M. Silberstein;C. Fetzer

文献摘要

被引文献

相似文献

最近发现的一类新的微体系攻击称为Specter,引起了安全界的注意,因为这些攻击可以克服许多传统的防御机制,例如界限检查。攻击之一 - 范围检查旁路 - 既不能在系统或架构级别上有效地解决,也无法在应用程序本身中进行更改。到目前为止,提议的缓解措施涉及序列化,从而减少了CPU资源的使用并引起高间接费用。在这项工作中,我们提出了一种仅延迟脆弱指令的方法,而无需完全序列化执行。我们作为LLVM通行证实施的原型导致凤凰基准套件的60%开销,这与完整的序列化相比,导致440%的放缓。
A recent discovery of a new class of microarchitectural attacks called Spectre picked up the attention of the security community as these attacks can overcome many traditional mechanisms of defense, such as bounds checking. One of the attacks - Bounds Check Bypass - can neither be efficiently solved on system nor architectural levels, and requires changes in the application itself. So far, the proposed mitigations involved serialization, which reduces the usage of CPU resources and causes high overheads. In this work, we propose a method of only delaying the vulnerable instructions, without the necessity to completely serialize execution. Our prototype implemented as an LLVM pass causes 60% overhead across Phoenix benchmark suite, which compares favorably to the full serialization causing 440% slowdown.