Exploration for Software Mitigation to Spectre Attacks of Poisoning Indirect Branches

Exploration for Software Mitigation to Spectre Attacks of Poisoning Indirect Branches
复制标题

DOI:
10.1080/02564602.2018.1531072
复制
发表时间:
2018-10
影响因子:
2.4
通讯作者:
Baozi Chen;Q. Wu;Yusong Tan;Liu Yang;Peng Zou
Baozi Chen;Q. Wu;Yusong Tan;Liu Yang;Peng Zou
中科院分区:
计算机科学4区
文献类型:
--
作者:
Baozi Chen;Q. Wu;Yusong Tan;Liu Yang;Peng Zou

文献摘要

相似文献

摘要推测执行和分支预测是现代超标量处理器中广泛使用的开发并行级的技术。最近,研究人员发现了一种名为Spectre的新型攻击,它利用带有侧通道的推测机制。由于推测在现代超标量处理器中被广泛使用,这些漏洞在许多流行的处理器中被发现。利用这些安全漏洞,攻击者可以从KVM客户机内部泄漏主机内存。虽然硬件提供商正试图在下一代产品中解决微架构设计中的问题,但软件缓解总是可取的。Retpoline是由Google开发的纯软件修复程序,据称对性能的影响可以忽略不计。在本文中,我们研究Retpoline的细节,并评估它与各种工作负载。我们发现Retpoline确实对现有软件的性能有影响,但取决于应用程序与内核的交互方式。根据我们的实验,它显示了更多的回归网络I/O比存储。一个程序越依赖于内核,它显示的回归就越大。为了减轻这种影响,我们提出了一种使用用户空间网络堆栈的方法。我们使用Netmap用户空间包I/O框架验证了该建议。此外,我们观察到在一些用户空间应用程序中应用Retpoline的性能下降,例如Perl解释器,这些应用程序被认为是新型攻击的目标。最后,我们回顾了实验结果,并讨论了未来的潜在缓解Spectre。
ABSTRACT Speculative execution and branch prediction are techniques that are widely used in modern superscalar processors to exploit instruction-level parallelism. Recently, researchers have discovered a new kind of attacks named Spectre which exploits speculation mechanisms with a side channel. Since speculation is widely used in modern superscalar processors, these vulnerabilities are found in many popular processors. Exploiting the security vulnerabilities, the attacker can leak the host memory from inside a KVM guest. While the hardware providers are trying to fix the issues from the microarchitecture designs in the next generation of their products, software mitigation are always desirable. Retpoline is a pure software fix developed by Google and is claimed to have a negligible impact on performance. In this paper, we look into the details of Retpoline and evaluate it with various workloads. We found that Retpoline does have impact on performance to the existing software but varies depending on how applications interact with the kernel. According to our experiment, it shows more regression on the network I/O than the storage. The more a program relies on the kernel, the greater regression it shows. To alleviate the impact, we propose a method that uses userspace network stack. We verify the proposal using Netmap userspace packet I/O framework. Besides, we observe great performance regression of applying Retpoline in some of userspace applications such as Perl interpreter which is thought to be the targets exploited by the new type of attacks. In the end, we review the experiment results and discuss the potential mitigation of Spectre in future.