ExSpectre: Hiding Malware in Speculative Execution
Jack Wampler, Ian Martiny, Eric Wustrow
Abstract
Recently, the Spectre and Meltdown attacks revealed serious vulnerabilities in modern CPU designs, allowing an attacker to exfiltrate data from sensitive programs. These vulnerabilities take advantage of speculative execution to coerce a processor to perform computation that would otherwise not occur, leaking the resulting information via side channels to an attacker. In this paper, we extend these ideas in a different direction, and leverage speculative execution in order to hide malware from both static and dynamic analysis. Using this technique, critical portions of a malicious program's computation can be shielded from view, such that even a debugger following an instructionlevel trace of the program cannot tell how its results were computed. We introduce ExSpectre, which compiles arbitrary malicious code into a seemingly-benign payload binary. When a separate trigger program runs on the same machine, it mistrains the CPU's branch predictor, causing the payload program to speculatively execute its malicious payload, which communicates speculative results back to the rest of the payload program to change its real-world behavior. We study the extent and types of execution that can be performed speculatively, and demonstrate several computations that can be performed covertly. In particular, within speculative execution we are able to decrypt memory using AES-NI instructions at over 11 kbps. Building on this, we decrypt and interpret a custom virtual machine language to perform arbitrary computation and system calls in the real world. We demonstrate this with a proof-of-concept dial back shell, which takes only a few milliseconds to execute after the trigger is issued. We also show how our corresponding trigger program can be a preexisting benign application already running on the system, and demonstrate this concept with OpenSSL driven remotely by the attacker as a trigger program. ExSpectre demonstrates a new kind of malware that evades existing reverse engineering and binary analysis techniques. Because its true functionality is contained in seemingly unreachable dead code, and its control flow driven externally by potentially any other program running at the same time, ExSpectre poses a novel threat to state-of-the-art malware analysis techniques.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 60b08478-0b35-49ee-a146-4b84fab8fb39Cited by top-tier papers8
- LVI: Hijacking Transient Execution through Microarchitectural Load Value InjectionJo Van Bulck, Daniel Moghimi, Michael Schwarz, Moritz Lipp et al.S&P 2020 · 275 citations
- Speculative interference attacks: breaking invisible speculation schemesMohammad Behnia, Prateek Sahu, Riccardo Paccagnella, Jiyong Yu et al.ASPLOS 2021 · 69 citations
- Streamline: a fast, flushless cache covert-channel attack by enabling asynchronous collusionGururaj Saileshwar, Christopher W. Fletcher, Moinuddin K. QureshiASPLOS 2021 · 36 citations
- Exploring Branch Predictors for Constructing Transient Execution TrojansTao Zhang, Kenneth Koltermann, Dmitry EvtyushkinASPLOS 2020 · 32 citations
- PerSpectron: Detecting Invariant Footprints of Microarchitectural Attacks with PerceptronSamira Mirbagher Ajorpaz, Gilles Pokam, Esmaeil Mohammadian Koruyeh, Elba Garza et al.MICRO 2020 · 23 citations
Builds on5
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher et al.NDSS 2016 · 1,021 citations
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim et al.USENIX Security 2017 · 536 citations
Related papers
- Computing with time: microarchitectural weird machinesDmitry Evtyushkin, Thomas Benjamin, Jesse Elwell, Jeffrey A. Eitel et al.ASPLOS 2021 · 14 citations
- SpecSafe: detecting cache side channels in a speculative worldRobert Brotzman, Danfeng Zhang, Mahmut Taylan Kandemir, Gang TanOOPSLA 2021 · 3 citations
- ret2spec: Speculative Execution Using Return Stack BuffersGiorgi Maisuradze, Christian RossowCCS 2018 · 282 citations
- Speculative Probing: Hacking Blind in the Spectre EraEnes Göktas, Kaveh Razavi, Georgios Portokalidis, Herbert Bos et al.CCS 2020 · 36 citations
- Revizor: testing black-box CPUs against speculation contractsOleksii Oleksenko, Christof Fetzer, Boris Köpf, Mark SilbersteinASPLOS 2022 · 36 citations
