USENIX Security2017Top-tier venue
On the effectiveness of mitigations against floating-point timing channels
David Kohlbrenner, Hovav Shacham
Abstract
The duration of floating-point instructions is a known timing side channel that has been used to break Same-Origin Policy (SOP) privacy on Mozilla Firefox and the Fuzz differentially private database. Several defenses have been proposed to mitigate these attacks.
We present detailed benchmarking of floating point performance for various operations based on operand values. We identify families of values that induce slow and fast paths beyond the classes (normal, subnormal, etc.) considered in previous work, and note that different processors exhibit different timing behavior.
We evaluate the efficacy of the defenses deployed (or not) in Web browsers to floating point side channel attacks on SVG filters. We find that Google Chrome, Mozilla Firefox, and Apple's Safari have insufficiently addressed the floating-point side channel, and we present attacks for each that extract pixel data cross-origin on most platforms.
We evaluate the vector-operation based defensive mechanism proposed at USENIX Security 2016 by Rane, Lin and Tiwari and find that it only reduces, not eliminates, the floating-point side channel signal.
Together, these measurements and attacks cause us to conclude that floating point is simply too variable to use in a timing security sensitive context.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 31336366-6ccf-4b5b-b1d7-460ccce95ec7Cited by top-tier papers22
- Rage Against the Machine Clear: A Systematic Analysis of Machine Clears and Their Implications for Transient Execution AttacksHany Ragab, Enrico Barberis, Herbert Bos, Cristiano GiuffridaUSENIX Security 2021 · 76 citations
- IODINE: Verifying Constant-Time Execution of HardwareKlaus von Gleissenthall, Rami Gökhan Kici, Deian Stefan, Ranjit JhalaUSENIX Security 2019 · 45 citations
- Towards Verified, Constant-time Floating Point OperationsMarc Andrysco, Andres Nötzli, Fraser Brown, Ranjit Jhala et al.CCS 2018 · 33 citations
- Spook.js: Attacking Chrome Strict Site Isolation via Speculative ExecutionAyush Agarwal, Sioli O'Connell, Jason Kim, Shaked Yehezkel et al.S&P 2022 · 32 citations
- Rendered Private: Making GLSL Execution Uniform to Prevent WebGL-based Browser FingerprintingShujiang Wu, Song Li, Yinzhi Cao, Ningfei WangUSENIX Security 2019 · 27 citations
Builds on4
- ASLR on the Line: Practical Cache Attacks on the MMUBen Gras, Kaveh Razavi, Erik Bosman, Herbert Bos et al.NDSS 2017 · 276 citations
- Verifying Constant-Time ImplementationsJosé Bacelar Almeida, Manuel Barbosa, Gilles Barthe, François Dupressoir et al.USENIX Security 2016 · 274 citations
- Trusted Browsers for Uncertain TimesDavid Kohlbrenner, Hovav ShachamUSENIX Security 2016 · 83 citations
- Secure, Precise, and Fast Floating-Point Operations on x86 ProcessorsAshay Rane, Calvin Lin, Mohit TiwariUSENIX Security 2016 · 34 citations
Related papers
- Pixel Thief: Exploiting SVG Filter Leakage in Firefox and ChromeSioli O'Connell, Lishay Aben Sour, Ron Magen, Daniel Genkin et al.USENIX Security 2024 · 5 citations
- Extension Breakdown: Security Analysis of Browsers Extension Resources Control PoliciesIskander Sánchez-Rola, Igor Santos, Davide BalzarottiUSENIX Security 2017 · 67 citations
- Rendering Contention Channel Made Practical in Web BrowsersShujiang Wu, Jianjia Yu, Min Yang, Yinzhi CaoUSENIX Security 2022
- Déjà Vu: Side-Channel Analysis of Mozilla's NSSSohaib ul Hassan, Iaroslav Gridin, Ignacio M. Delgado-Lozano, Cesar Pereida García et al.CCS 2020 · 4 citations
- Pool-Party: Exploiting Browser Resource Pools for Web TrackingPeter Snyder, Soroush Karami, Arthur Edelstein, Benjamin Livshits et al.USENIX Security 2023
