DOLMA: Securing Speculation with the Principle of Transient Non-Observability

DOLMA: Securing Speculation with the Principle of Transient Non-Observability
复制标题

DOI:
--
复制
发表时间:
2021
期刊:
--
影响因子:
--
通讯作者:
Kevin Loughlin;Ian Neal;Jiacheng Ma;Elisa Tsai;Ofir Weisse;S. Narayanasamy;Baris Kasikci
Kevin Loughlin;Ian Neal;Jiacheng Ma;Elisa Tsai;Ofir Weisse;S. Narayanasamy;Baris Kasikci
中科院分区:
其他
文献类型:
--
作者:
Kevin Loughlin;Ian Neal;Jiacheng Ma;Elisa Tsai;Ofir Weisse;S. Narayanasamy;Baris Kasikci

文献摘要

被引文献

相似文献

现代处理器允许攻击者通过微架构隐蔽计时通道在瞬态(即错误推测)执行期间泄露数据。虽然最初的防御是特定于通道的,但最近的解决方案采用推测信息流控制,试图自动减轻通过任何通道的攻击。然而,我们证明了当前最先进的防御无法减轻使用推测存储的攻击,在瞬态执行期间仍然允许任意数据泄漏。此外,我们还表明,目前的技术水平无法扩展到保护寄存器中的数据,从而导致30。8 - 63。根据威胁模型,spec2017的开销为4%。然后,我们介绍了dolma,这是第一个自动提供针对所有已知瞬态执行攻击的全面保护的防御。dolma将轻量级推测信息流控制方案与一组安全性能优化相结合。通过实施暂态不可观察性的新原理,dolma确保在现有攻击的背景下,内核上的时间片提供了一个隔离单元。因此,dolma可以允许推测的TLB/L1缓存访问和可变时间算法,而不会损失安全性。在spec2017上,dolma实现了10级内存中数据的全面保护。2-29。7%的开销,为寄存器中的数据增加保护。6-42。2%管理费(8);2 - 21。比目前的水平低2%,但安全性更高)。
Modern processors allow attackers to leak data during transient (i.e., mis-speculated) execution through microarchitectural covert timing channels. While initial defenses were channel-specific, recent solutions employ speculative information flow control in an attempt to automatically mitigate attacks via any channel. However, we demonstrate that the current state-of-the-art defense fails to mitigate attacks using speculative stores, still allowing arbitrary data leakage during transient execution. Furthermore, we show that the state of the art does not scale to protect data in registers, incurring 30 . 8–63 . 4% overhead on SPEC 2017, depending on the threat model. We then present D OLMA , the first defense to automatically provide comprehensive protection against all known transient execution attacks. D OLMA combines a lightweight speculative information flow control scheme with a set of secure performance optimizations. By enforcing a novel principle of transient non-observability , D OLMA ensures that a time slice on a core provides a unit of isolation in the context of existing attacks. Accordingly, D OLMA can allow speculative TLB/L1 cache accesses and variable-time arithmetic without loss of security. On SPEC 2017, D OLMA achieves comprehensive protection of data in memory at 10 . 2–29 . 7% overhead, adding protection for data in registers at 22 . 6–42 . 2% overhead (8 . 2– 21 . 2% less than the state of the art, with greater security).