Hunting the Haunter - Efficient Relational Symbolic Execution for Spectre with Haunted RelSE
Lesly-Ann Daniel, Sébastien Bardin, Tamara Rezk
Abstract
Spectre are microarchitectural attacks which were made public in January 2018. They allow an attacker to recover secrets by exploiting speculations. Detection of Spectre is particularly important for cryptographic libraries and defenses at the software level have been proposed. Yet, defenses correctness and Spectre detection pose challenges due on one hand to the explosion of the exploration space induced by speculative paths, and on the other hand to the introduction of new Spectre vulnerabilities at different compilation stages. We propose an optimization, coined Haunted RelSE, that allows scalable detection of Spectre vulnerabilities at binary level. We prove the optimization semantically correct w.r.t. the more naive explicit speculative exploration approach used in state-of-the-art tools. We implement Haunted RelSE in a symbolic analysis tool, and extensively test it on a wellknown litmus testset for Spectre-PHT, and on a new litmus testset for Spectre-STL, which we propose. Our technique finds more violations and scales better than state-of-the-art techniques and tools, analyzing real-world cryptographic libraries and finding new violations. Thanks to our tool, we discover that indexmasking—a standard defense for Spectre-PHT—and well-known gcc options to compile position independent executables introduce Spectre-STL violations. We propose and verify a correction to index-masking to avoid the problem.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6d85dc70-03bb-45f1-9ebb-b4b6394f724fCited by top-tier papers27
- SoK: Practical Foundations for Software Spectre DefensesSunjay Cauligi, Craig Disselkoen, Daniel Moghimi, Gilles Barthe et al.S&P 2022 · 59 citations
- Cats vs. Spectre: An Axiomatic Approach to Modeling Speculative Execution AttacksHernán Ponce de León, Johannes KinderS&P 2022 · 35 citations
- InSpectre Gadget: Inspecting the Residual Attack Surface of Cross-privilege Spectre v2Sander Wiebing, Alvise de Faveri Tron, Herbert Bos, Cristiano GiuffridaUSENIX Security 2024 · 32 citations
- Axiomatic hardware-software contracts for securityNicholas Mosier, Hanna Lachnitt, Hamed Nemati, Caroline TrippelISCA 2022 · 26 citations
- Automatic Detection of Speculative Execution CombinationsXaver Fabian, Marco Guarnieri, Marco PatrignaniCCS 2022 · 19 citations
Builds on12
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp et al.USENIX Security 2019 · 442 citations
- ret2spec: Speculative Execution Using Return Stack BuffersGiorgi Maisuradze, Christian RossowCCS 2018 · 282 citations
- Spectector: Principled Detection of Speculative Information FlowsMarco Guarnieri, Boris Köpf, José F. Morales, Jan Reineke et al.S&P 2020 · 177 citations
Related papers
- An Analysis of Speculative Type Confusion Vulnerabilities in the WildOfek Kirzner, Adam MorrisonUSENIX Security 2021 · 40 citations
- SpecTaint: Speculative Taint Analysis for Discovering Spectre GadgetsZhenxiao Qi, Qian Feng, Yueqiang Cheng, Mengjia Yan et al.NDSS 2021
- SpecSafe: detecting cache side channels in a speculative worldRobert Brotzman, Danfeng Zhang, Mahmut Taylan Kandemir, Gang TanOOPSLA 2021 · 3 citations
- Place Protections at the Right Place: Targeted Hardening for Cryptographic Code against Spectre v1Yiming Zhu, Wenchao Huang, Yan XiongUSENIX Security 2025
- SpecCFI: Mitigating Spectre Attacks using CFI Informed SpeculationEsmaeil Mohammadian Koruyeh, Shirin Haji Amin Shirazi, Khaled N. Khasawneh, Chengyu Song et al.S&P 2020 · 74 citations
