End-to-End Automated Exploit Generation for Validating the Security of Processor Designs

End-to-End Automated Exploit Generation for Validating the Security of Processor Designs
复制标题

DOI:
10.1109/micro.2018.00071
复制
发表时间:
2018-10
期刊:
2018 51st Annual IEEE/ACM International Symposium on Microarchitecture (MICRO)
影响因子:
--
通讯作者:
Rui Zhang;Calvin Deutschbein;Peng Huang;C. Sturton
Rui Zhang;Calvin Deutschbein;Peng Huang;C. Sturton
中科院分区:
其他
文献类型:
--
作者:
Rui Zhang;Calvin Deutschbein;Peng Huang;C. Sturton

文献摘要

被引文献

相似文献

本文介绍了Coppelia,这是一种端到端工具,在给定处理器设计和一组关键安全不变的情况下,它会自动生成完整的,可重播的利用程序,以帮助设计师查找,上下文化并评估硬件漏洞的安全威胁。在Coppelia中,我们使用新的周期缝合方法和快速验证技术开发了面向硬件的向后符号执行引擎,以及用于利用生成的几种优化。然后,我们添加程序存根以完成利用。我们在三个不同架构的CPU上评估Coppelia。 Coppelia能够在这些CPU中找到并生成31个已知漏洞中29个的利用,其中包括商业和学术模型检查工具找不到的11个漏洞。所有生成的漏洞利用都可以在FPGA板上成功重播。此外,Coppelia在这些CPU中找到了4个新漏洞以及漏洞。我们还使用Coppelia来验证安全补丁是否确实修复了漏洞,并完善了一组断言。
This paper presents Coppelia, an end-to-end tool that, given a processor design and a set of security-critical invariants, automatically generates complete, replayable exploit programs to help designers find, contextualize, and assess the security threat of hardware vulnerabilities. In Coppelia, we develop a hardware-oriented backward symbolic execution engine with a new cycle stitching method and fast validation technique, along with several optimizations for exploit generation. We then add program stubs to complete the exploit. We evaluate Coppelia on three CPUs of different architectures. Coppelia is able to find and generate exploits for 29 of 31 known vulnerabilities in these CPUs, including 11 vulnerabilities that commercial and academic model checking tools can not find. All of the generated exploits are successfully replayable on an FPGA board. Moreover, Coppelia finds 4 new vulnerabilities along with exploits in these CPUs. We also use Coppelia to verify whether a security patch indeed fixed a vulnerability, and to refine a set of assertions.