Lune

USENIX Security2017Top-tier venue

Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch Shadowing

Sangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim, Hyesoon Kim, Marcus Peinado

2017Year
536Citations
144Top-tier citations

Abstract

Intel Software Guard Extension (SGX) is a hardware-based trusted execution environment (TEE) that enables secure computation without trusting any underlying software, such as operating system or even hardware firmware. It provides strong security guarantees, namely, confidentiality and integrity, to an enclave (i.e., a program running on Intel SGX) through solid hardware-based isolation. However, a new controlled-channel attack (Xu et al., Oakland 2015), although it is an out-of-scope attack according to Intel SGX's threat model, demonstrated that a malicious OS can infer coarse-grained control flows of an enclave via a series of page faults, and such a side-channel can be severe for security-sensitive applications. In this paper, we explore a new, yet critical, side-channel attack against Intel SGX, called a branch shadowing attack, which can reveal fine-grained control flows (i.e., each branch) of an enclave program running on real SGX hardware. The root cause of this attack is that Intel SGX does not clear the branch history when switching from enclave mode to non-enclave mode, leaving the fine-grained traces to the outside world through a branch-prediction side channel. However, exploiting the channel is not so straightforward in practice because 1) measuring branch prediction/misprediction penalties based on timing is too inaccurate to distinguish fine-grained control-flow changes and 2) it requires sophisticated control over the enclave execution to force its execution to the interesting code blocks. To overcome these challenges, we developed two novel exploitation techniques: 1) Intel PT-and LBR-based history-inferring techniques and 2) APIC-based technique to control the execution of enclave programs in a fine-grained manner. As a result, we could demonstrate our attack by breaking recent security constructs, including ORAM schemes, Sanctum, SGX-Shield, and T-SGX. Not limiting our work to the attack itself, we thoroughly studied the feasibility of hardware-based solutions (e.g., branch history clearing) and also proposed a software-based countermeasure, called Zigzagger, to mitigate the branch shadowing attack in practice.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 18330ffa-aa88-457c-bcb0-0038838c3ab5

Cited by top-tier papers144

Ask how each one uses it

Builds on9

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines