Context-Sensitive Fencing: Securing Speculative Execution via Microcode Customization

Context-Sensitive Fencing: Securing Speculative Execution via Microcode Customization
复制标题

DOI:
10.1145/3297858.3304060
复制
发表时间:
2019-04
期刊:
Proceedings of the Twenty-Fourth International Conference on Architectural Support for Programming Languages and Operating Systems
影响因子:
--
通讯作者:
Mohammadkazem Taram;A. Venkat;D. Tullsen
Mohammadkazem Taram;A. Venkat;D. Tullsen
中科院分区:
其他
文献类型:
--
作者:
Mohammadkazem Taram;A. Venkat;D. Tullsen

文献摘要

相似文献

本文介绍了上下文敏感的围栏(CSF),一个针对多个变种的Spectre的微码级防御。CSF利用动态改变指令流的解码的能力,以仅在动态条件指示需要时无缝地注入新的微操作(包括围栏)。这使处理器能够抵御攻击,但对关键性能特性(如推测执行)的影响最小。本研究还探讨了几种替代围栏实现,并介绍了三种新类型的围栏,允许最动态的重新排序的加载和存储,但在某种程度上,防止投机性访问改变可见的缓存状态。与最先进的基于软件的屏蔽机制相比,这些优化将防御机制的性能开销降低了六倍。
This paper describes context-sensitive fencing (CSF), a microcode-level defense against multiple variants of Spectre. CSF leverages the ability to dynamically alter the decoding of the instruction stream, to seamlessly inject new micro-ops, including fences, only when dynamic conditions indicate they are needed. This enables the processor to protect against the attack, but with minimal impact on the efficacy of key performance features such as speculative execution. This research also examines several alternative fence implementations, and introduces three new types of fences which allow most dynamic reorderings of loads and stores, but in a way that prevents speculative accesses from changing visible cache state. These optimizations reduce the performance overhead of the defense mechanism, compared to state-of-the-art software-based fencing mechanisms by a factor of six.