Verification of serialising instructions for security against transient execution attacks

Verification of serialising instructions for security against transient execution attacks
复制标题

验证序列化指令以防止瞬时执行攻击

DOI:
10.1049/cdt2.12058
复制
发表时间:
2023
影响因子:
1.2
通讯作者:
Mathure, Nimish
Mathure, Nimish
中科院分区:
计算机科学4区
文献类型:
--
作者:
Ponugoti, Kushal K.;Srinivasan, Sudarshan K.;Mathure, Nimish

文献摘要

参考文献

被引文献

相似文献

Spectre 和 Meltdown 等瞬态执行攻击利用现代微处理器中的推测执行,通过缓存侧通道泄漏信息。防御许多瞬态执行攻击的软件解决方案使用lfence序列化指令,该指令不允许lfence之后的指令相对于lfence之前的指令乱序执行。然而,硬件实施中的错误和特洛伊木马可能会被利用来破坏软件缓解措施。上述安全漏洞之前尚未被识别和解决。作者提供了一种正式的方法解决方案来解决验证犯罪硬件实现的问题。作者还展示了如何设计硬件木马来规避,并证明他们的验证方法也可以标记此类木马。作者使用 RSD 证明了我们方法的有效性,RSD 是一种基于开源 RISC-V 的超标量乱序处理器。
Transient execution attacks such as Spectre and Meltdown exploit speculative execution in modern microprocessors to leak information via cache side‐channels. Software solutions to defend against many transient execution attacks employ thelfenceserialising instruction, which does not allow instructions that come after thelfenceto execute out‐of‐order with respect to instructions that come before thelfence. However, errors and Trojans in the hardware implementation oflfencecan be exploited to compromise the software mitigations that uselfence. The aforementioned security gap has not been identified and addressed previously. The authors provide a formal method solution that addresses the verification oflfencehardware implementation. The authors also show how hardware Trojans can be designed to circumventlfenceand demonstrate that their verification approach will flag such Trojans as well. The authors have demonstrated the efficacy of our approach using RSD, which is an open source RISC‐V based superscalar out‐of‐order processor.
DOI: 10.1145/1014194.800930
发表时间: 1982-10
期刊: --
影响因子: --
作者:
J. Hennessy;N. Jouppi;S. Przybylski;C. Rowen;T. Gross;F. Baskett;John T. Gill
通讯作者: J. Hennessy;N. Jouppi;S. Przybylski;C. Rowen;T. Gross;F. Baskett;John T. Gill
SpecTaint:用于发现 Spectre 小工具的推测性污点分析
DOI: 10.14722/ndss.2021.24466
发表时间: 2021
期刊: Proceedings 2021 Network and Distributed System Security Symposium
影响因子: --
作者:
Zhenxiao Qi;Qian Feng;Yueqiang Cheng;Mengjia Yan;Peng Li;Heng Yin;Tao Wei
通讯作者: Tao Wei
使用硬件性能计数器检测幽灵攻击
DOI: 10.1109/tc.2021.3082471
发表时间: 2022
影响因子: 3.7
作者:
Li, Congmiao;Gaudiot, Jean-Luc
通讯作者: Gaudiot, Jean-Luc