DOLMA: Securing Speculation with the Principle of Transient Non-Observability
DOLMA: Securing Speculation with the Principle of Transient Non-Observability
复制标题
DOI:
--
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
Kevin Loughlin;Ian Neal;Jiacheng Ma;Elisa Tsai;Ofir Weisse;S. Narayanasamy;Baris Kasikci
中科院分区:
文献类型:
--
作者:
Kevin Loughlin;Ian Neal;Jiacheng Ma;Elisa Tsai;Ofir Weisse;S. Narayanasamy;Baris Kasikci
Modern processors allow attackers to leak data during transient (i.e., mis-speculated) execution through microarchitectural covert timing channels. While initial defenses were channel-specific, recent solutions employ speculative information flow control in an attempt to automatically mitigate attacks via any channel. However, we demonstrate that the current state-of-the-art defense fails to mitigate attacks using speculative stores, still allowing arbitrary data leakage during transient execution. Furthermore, we show that the state of the art does not scale to protect data in registers, incurring 30 . 8–63 . 4% overhead on SPEC 2017, depending on the threat model. We then present D OLMA , the first defense to automatically provide comprehensive protection against all known transient execution attacks. D OLMA combines a lightweight speculative information flow control scheme with a set of secure performance optimizations. By enforcing a novel principle of transient non-observability , D OLMA ensures that a time slice on a core provides a unit of isolation in the context of existing attacks. Accordingly, D OLMA can allow speculative TLB/L1 cache accesses and variable-time arithmetic without loss of security. On SPEC 2017, D OLMA achieves comprehensive protection of data in memory at 10 . 2–29 . 7% overhead, adding protection for data in registers at 22 . 6–42 . 2% overhead (8 . 2– 21 . 2% less than the state of the art, with greater security).