Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch Shadowing

Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch Shadowing
复制标题

DOI:
--
复制
发表时间:
2016-11
期刊:
ArXiv
影响因子:
--
通讯作者:
Sangho Lee;Ming-Wei Shih;Prasun Gera;Taesoo Kim;Hyesoon Kim;Marcus Peinado
Sangho Lee;Ming-Wei Shih;Prasun Gera;Taesoo Kim;Hyesoon Kim;Marcus Peinado
中科院分区:
其他
文献类型:
--
作者:
Sangho Lee;Ming-Wei Shih;Prasun Gera;Taesoo Kim;Hyesoon Kim;Marcus Peinado

文献摘要

被引文献

相似文献

英特尔推出了一种基于硬件的可信执行环境,即英特尔软件保护扩展(SGX),它为用户程序提供了一个安全的、隔离的执行环境或enclave,而无需信任任何底层软件(例如,操作系统)或固件。研究人员已经证明,SGX很容易受到基于页面错误的攻击。然而,这种攻击只会揭示一个飞地内的页级内存访问。在本文中,我们探索了一种新的,但关键的,侧信道攻击,分支遮蔽,它揭示了一个飞地中的细粒度控制流(分支粒度)。这种攻击的根本原因是SGX在从enclave模式切换到非enclave模式时没有清除分支历史,留下了细粒度的痕迹供外界观察,从而产生了分支预测侧通道。然而,在实践中利用这个通道是具有挑战性的,因为1)测量分支执行时间对于区分细粒度的控制流更改来说太嘈杂了,2)在执行了我们目标的代码块之后立即暂停一个enclave需要复杂的控制。为了克服这些挑战,我们开发了两种新的开发技术:1)基于最后分支记录(LBR)的历史推断技术和2)基于高级可编程中断控制器(APIC)的技术,以细粒度的方式控制飞地的执行。对RSA的评估表明,我们的攻击推断每个私钥位的准确率为99.8%。最后,我们深入研究了基于硬件的解决方案(即分支历史刷新)的可行性,并提出了一种基于软件的方法来减轻攻击。
Intel has introduced a hardware-based trusted execution environment, Intel Software Guard Extensions (SGX), that provides a secure, isolated execution environment, or enclave, for a user program without trusting any underlying software (e.g., an operating system) or firmware. Researchers have demonstrated that SGX is vulnerable to a page-fault-based attack. However, the attack only reveals page-level memory accesses within an enclave. In this paper, we explore a new, yet critical, side-channel attack, branch shadowing, that reveals fine-grained control flows (branch granularity) in an enclave. The root cause of this attack is that SGX does not clear branch history when switching from enclave to nonenclave mode, leaving fine-grained traces for the outside world to observe, which gives rise to a branch-prediction side channel. However, exploiting this channel in practice is challenging because 1) measuring branch execution time is too noisy for distinguishing fine-grained controlflow changes and 2) pausing an enclave right after it has executed the code block we target requires sophisticated control. To overcome these challenges, we develop two novel exploitation techniques: 1) a last branch record (LBR)-based history-inferring technique and 2) an advanced programmable interrupt controller (APIC)-based technique to control the execution of an enclave in a finegrained manner. An evaluation against RSA shows that our attack infers each private key bit with 99.8% accuracy. Finally, we thoroughly study the feasibility of hardware-based solutions (i.e., branch history flushing) and propose a software-based approach that mitigates the attack.