SpecTaint: Speculative Taint Analysis for Discovering Spectre Gadgets
Zhenxiao Qi, Qian Feng, Yueqiang Cheng, Mengjia Yan, Peng Li, Heng Yin, Tao Wei
Abstract
—Software patching is a crucial mitigation approach against Spectre-type attacks. It utilizes serialization instructions to disable speculative execution of potential Spectre gadgets in a program. Unfortunately, there are no effective solutions to detect gadgets for Spectre-type attacks. In this paper, we propose a novel Spectre gadget detection technique by enabling dynamic taint analysis on speculative execution paths. To this end, we simulate and explore speculative execution at system level (within a CPU emulator). We have implemented a prototype called SpecTaint to demonstrate the efficacy of our proposed approach. We evaluated SpecTaint on our Spectre Samples Dataset, and compared SpecTaint with existing state-of-the-art Spectre gadget detection approaches on real-world applications. Our experimental results demonstrate that SpecTaint outperforms existing methods with respect to detection precision and recall by large margins, and it also detects new Spectre gadgets in real-world applications such as Caffe and Brotli. Besides, SpecTaint significantly reduces the performance overhead after patching the detected gadgets, compared with other approaches.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5a0eea1c-48e6-4e8d-bb97-a7dd8653b94eCited by top-tier papers19
- Rage Against the Machine Clear: A Systematic Analysis of Machine Clears and Their Implications for Transient Execution AttacksHany Ragab, Enrico Barberis, Herbert Bos, Cristiano GiuffridaUSENIX Security 2021 · 76 citations
- SoK: Practical Foundations for Software Spectre DefensesSunjay Cauligi, Craig Disselkoen, Daniel Moghimi, Gilles Barthe et al.S&P 2022 · 59 citations
- Cats vs. Spectre: An Axiomatic Approach to Modeling Speculative Execution AttacksHernán Ponce de León, Johannes KinderS&P 2022 · 35 citations
- InSpectre Gadget: Inspecting the Residual Attack Surface of Cross-privilege Spectre v2Sander Wiebing, Alvise de Faveri Tron, Herbert Bos, Cristiano GiuffridaUSENIX Security 2024 · 32 citations
- Phantom: Exploiting Decoder-detectable MispredictionsJohannes Wikner, Daniël Trujillo, Kaveh RazaviMICRO 2023 · 19 citations
Builds on9
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim et al.USENIX Security 2017 · 536 citations
- LAVA: Large-Scale Automated Vulnerability AdditionBrendan Dolan-Gavitt, Patrick Hulin, Engin Kirda, Tim Leek et al.S&P 2016 · 354 citations
Related papers
- Kasper: Scanning for Generalized Transient Execution Gadgets in the Linux KernelBrian Johannesmeyer, Jakob Koschel, Kaveh Razavi, Herbert Bos et al.NDSS 2022
- Exorcist: Enabling Atomic-Level Runtime Detection of Spectre Attacks using Precise Event Based SamplingHao Jia, Haoyu Ma, Changfeng Ding, Jinku LiFSE 2026
- SpecFuzz: Bringing Spectre-type vulnerabilities to the surfaceOleksii Oleksenko, Bohdan Trach, Mark Silberstein, Christof FetzerUSENIX Security 2020
- Hunting the Haunter - Efficient Relational Symbolic Execution for Spectre with Haunted RelSELesly-Ann Daniel, Sébastien Bardin, Tamara RezkNDSS 2021
- Conditional address propagation: an efficient defense mechanism against transient execution attacksPeinan Li, Rui Hou, Lutan Zhao, Yifan Zhu et al.DAC 2022 · 1 citation
