USENIX Security2023Top-tier venue
Downfall: Exploiting Speculative Data Gathering
Daniel Moghimi
Abstract
We introduce Downfall attacks, new transient execution attacks that undermine the security of computers running everywhere across the internet. We exploit the gather instruction on high-performance x86 CPUs to leak data across boundaries of user-kernel, processes, virtual machines, and trusted execution environments. We also develop practical and end-to-end attacks to steal cryptographic keys, program's runtime data, and even data at rest (arbitrary data). Our findings, exploitation techniques, and demonstrated attacks defeat all previous defenses, calling for critical hardware fixes and security updates for widely-used client and server computers. Stealing Cryptographic Keys ( §5) We demonstrate endto-end cross-VM attacks against widely-used modern cryptographic software that uses SIMD instructions for efficient and secure (constant-time) execution. We steal AES-128 and AES-256 keys from the off-the-shelf OpenSSL command line tool for encrypting data. Unlike previous such attacks, our attack is simple and reliable; In less than 10 seconds, we steal AES round keys, 8 bytes at a time, and combine them to break AES without any cryptanalysis, source code analysis, or any data analysis tricks required by previous attacks [52, 60] . Stealing Arbitrary Data ( §6) We discover that GDS can steal data from no-op operations that do not do anything architecturally. Masked memory operations, when the masked bit is unset, and the streaming data copy instructions, when the data copy size is zero, should not execute architecturally. But, we found that Intel CPUs transiently prefetch data into the leaky SIMD register buffers when such no-op operations are
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers26
- "These results must be false": A usability evaluation of constant-time analysis toolsMarcel Fourné, Daniel De Almeida Braga, Jan Jancar, Mohamed Sabt et al.USENIX Security 2024 · 15 citations
- SNPeek: Side-Channel Analysis for Privacy Applications on Confidential VMsRuiyi Zhang, Albert Cheu, Adrià Gascón, Daniel Moghimi et al.NDSS 2026 · 7 citations
- Lost and Found in Speculation: Hybrid Speculative Vulnerability DetectionMohamadreza Rostami, Shaza Zeitouni, Rahul Kande, Chen Chen et al.DAC 2024 · 6 citations
- Cross-Core Interrupt Detection: Exploiting User and Virtualized IPIsFabian Rauscher, Daniel GrussCCS 2024 · 4 citations
- Lifting Micro-Update Models from RTL for Formal Security AnalysisAdwait Godbole, Kevin Cheang, Yatin A. Manerkar, Sanjit A. SeshiaASPLOS 2024 · 3 citations
Builds on21
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo et al.S&P 2019 · 408 citations
Related papers
- CrossTalk: Speculative Data Leaks Across Cores Are RealHany Ragab, Alyssa Milburn, Kaveh Razavi, Herbert Bos et al.S&P 2021 · 162 citations
- GADGETSPINNER: A New Transient Execution Primitive Using the Loop Stream DetectorYun Chen, Ali Hajiabadi, Trevor E. CarlsonHPCA 2024 · 6 citations
- CacheOut: Leaking Data on Intel CPUs via Cache EvictionsStephan van Schaik, Marina Minkin, Andrew Kwong, Daniel Genkin et al.S&P 2021 · 158 citations
- Adversarial Prefetch: New Cross-Core Cache Side Channel AttacksYanan Guo, Andrew Zigerelli, Youtao Zhang, Jun YangS&P 2022 · 43 citations
- ÆPIC Leak: Architecturally Leaking Uninitialized Data from the MicroarchitecturePietro Borrello, Andreas Kogler, Martin Schwarzl, Moritz Lipp et al.USENIX Security 2022
