Exorcist: Enabling Atomic-Level Runtime Detection of Spectre Attacks using Precise Event Based Sampling
Hao Jia, Haoyu Ma, Changfeng Ding, Jinku Li
Abstract
While being key hardware techniques for improving the performance of modern processors, the speculative execution mechanisms also lead to side-channel attacks, which pose significant threats to the security of computer systems. While researchers have proposed various solutions to mitigate the threat posed by speculative attacks, most existing approaches have focused on offline static vulnerability analysis, which suffers from significant limitations of incompleteness and poor scalability. Based on Intel's Precise Event Based Sampling (PEBS) technique, this paper proposes Exorcist, a novel runtime framework for detecting Spectre-PHT attacks at the atomic level. Leveraging the key observation that the atomic execution of a Spectre-PHT gadget triggers both a cache miss and a branch mis-precision in a fixed sequence, Exorcist uses carefully configured PEBS monitoring to efficiently capture all related fine-grained hardware performance events, then launches a kernel- and user-level collaborated taint analysis to effectively pinpoint Spectre-PHT gadgets that have actually exploited vulnerable speculative executions. Our approach significantly reduces the amount of native instructions needed to be processed to confirm actual Spectre exploitation, making it capable of achieving high accuracy and a negligible false positive rate with second-level response time. We have implemented a prototype of Exorcist and performed a comprehensive evaluation on it. Experimental results indicate that Exorcist can efficiently detect Spectre-PHT attacks at runtime with acceptable performance overhead, including JIT-compiled Spectre-PHT payloads written in JavaScript that are beyond the reach of existing offline analysis-based approaches.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 14bab612-fd12-4af4-b999-eff41c45d46eRelated papers
- SpecTaint: Speculative Taint Analysis for Discovering Spectre GadgetsZhenxiao Qi, Qian Feng, Yueqiang Cheng, Mengjia Yan et al.NDSS 2021
- Kasper: Scanning for Generalized Transient Execution Gadgets in the Linux KernelBrian Johannesmeyer, Jakob Koschel, Kaveh Razavi, Herbert Bos et al.NDSS 2022
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- ConTExT: A Generic Approach for Mitigating SpectreMichael Schwarz, Moritz Lipp, Claudio Canella, Robert Schilling et al.NDSS 2020
- Conditional address propagation: an efficient defense mechanism against transient execution attacksPeinan Li, Rui Hou, Lutan Zhao, Yifan Zhu et al.DAC 2022 · 1 citation
