Speculative Taint Tracking (STT): A Comprehensive Protection for Speculatively Accessed Data

Speculative Taint Tracking (STT): A Comprehensive Protection for Speculatively Accessed Data
复制标题

DOI:
10.1145/3352460.3358274
复制
发表时间:
2019-10
期刊:
影响因子:
3.6
通讯作者:
Jiyong Yu;Mengjia Yan;Artem Khyzha;Adam Morrison;J. Torrellas;Christopher W. Fletcher
Jiyong Yu;Mengjia Yan;Artem Khyzha;Adam Morrison;J. Torrellas;Christopher W. Fletcher
中科院分区:
计算机科学3区
文献类型:
--
作者:
Jiyong Yu;Mengjia Yan;Artem Khyzha;Adam Morrison;J. Torrellas;Christopher W. Fletcher

文献摘要

相似文献

投机性执行攻击构成了巨大的安全威胁,能够在恶意推测下读取任意程序数据,然后通过微体系式秘密渠道删除该数据。本文提出了投机性污染跟踪(STT),这是一种高安全性和高性能硬件机制,以阻止这些攻击。主要的想法是,只要我们能够证明转发的结果未达到潜在的秘密渠道,就可以安全地执行并有选择地转发读取秘密的投机说明的结果。本文的技术核心是一个新的抽象,可帮助识别所有秘密渠道,并且是一个构建结构,可快速识别秘密渠道何时不再是威胁。我们进一步对该计划进行了详细的正式分析,并在同伴文件中证明了安全性。当对Spec06工作负载进行评估时,STT相对于不安全的机器会产生8.5%或14.5%的性能开销。
Speculative execution attacks present an enormous security threat, capable of reading arbitrary program data under malicious speculation, and later exfiltrating that data over microarchitectural covert channels. This article proposes speculative taint tracking (STT), a high-security and high-performance hardware mechanism to block these attacks. The main idea is that it is safe to execute and selectively forward the results of speculative instructions that read secrets, as long as we can prove that the forwarded results do not reach potential covert channels. The technical core of the article is a new abstraction to help identify all covert channels, and an architecture to quickly identify when a covert channel is no longer a threat. We further conduct a detailed formal analysis on the scheme and prove security in a companion document. When evaluated on SPEC06 workloads, STT incurs 8.5% or 14.5% performance overhead relative to an insecure machine.