The Code That Never Ran: Modeling Attacks on Speculative Evaluation
Craig Disselkoen, Radha Jagadeesan, Alan Jeffrey, James Riely
Abstract
This paper studies information flow caused by speculation mechanisms in hardware and software. The Spectre attack shows that there are practical information flow attacks which use an interaction of dynamic security checks, speculative evaluation and cache timing. Previous formal models of program execution are designed to capture computer architecture, rather than micro-architecture, and so do not capture attacks such as Spectre. In this paper, we propose a model based on pomsets which is designed to model speculative evaluation. The model is abstract with respect to specific micro-architectural features, such as caches and pipelines, yet is powerful enough to express known attacks such as Spectre and Prime+Abort, and verify their countermeasures. The model also allows for the prediction of new information flow attacks. We derive two such attacks, which exploit compiler optimizations, and validate these experimentally against gcc and clang.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers10
- SoK: Practical Foundations for Software Spectre DefensesSunjay Cauligi, Craig Disselkoen, Daniel Moghimi, Gilles Barthe et al.S&P 2022 · 59 citations
- Automatically eliminating speculative leaks from cryptographic code with bladeMarco Vassena, Craig Disselkoen, Klaus von Gleissenthall, Sunjay Cauligi et al.POPL 2021 · 53 citations
- InSpectre: Breaking and Fixing Microarchitectural Vulnerabilities by Formal AnalysisRoberto Guanciale, Musard Balliu, Mads DamCCS 2020 · 51 citations
- High-Assurance Cryptography in the Spectre EraGilles Barthe, Sunjay Cauligi, Benjamin Grégoire, Adrien Koutsos et al.S&P 2021 · 42 citations
- Cats vs. Spectre: An Axiomatic Approach to Modeling Speculative Execution AttacksHernán Ponce de León, Johannes KinderS&P 2022 · 35 citations
Builds on4
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Prime+Abort: A Timer-Free High-Precision L3 Cache Attack using Intel TSXCraig Disselkoen, David Kohlbrenner, Leo Porter, Dean M. TullsenUSENIX Security 2017 · 186 citations
- Trusted Browsers for Uncertain TimesDavid Kohlbrenner, Hovav ShachamUSENIX Security 2016 · 83 citations
- HyperFlow: A Processor Architecture for Nonmalleable, Timing-Safe Information Flow SecurityAndrew Ferraiuolo, Mark Zhao, Andrew C. Myers, G. Edward SuhCCS 2018 · 63 citations
Related papers
- New Models for Understanding and Reasoning about Speculative Execution AttacksZecheng He, Guangyuan Hu, Ruby B. LeeHPCA 2021 · 18 citations
- Speculative interference attacks: breaking invisible speculation schemesMohammad Behnia, Prateek Sahu, Riccardo Paccagnella, Jiyong Yu et al.ASPLOS 2021 · 69 citations
- ProSpeCT: Provably Secure Speculation for the Constant-Time PolicyLesly-Ann Daniel, Marton Bognar, Job Noorman, Sébastien Bardin et al.USENIX Security 2023
- Pensieve: Microarchitectural Modeling for Security EvaluationYuheng Yang, Thomas Bourgeat, Stella Lau, Mengjia YanISCA 2023 · 23 citations
- Exorcising Spectres with Secure CompilersMarco Patrignani, Marco GuarnieriCCS 2021 · 5 citations
