USENIX Security2023Top-tier venue
(M)WAIT for It: Bridging the Gap between Microarchitectural and Architectural Side Channels
Ruiyi Zhang, Taehyun Kim, Daniel Weber, Michael Schwarz
Abstract
In the last years, there has been a rapid increase in microarchitectural attacks, exploiting side effects of various parts of the CPU. Most of them have in common that they rely on timing differences, requiring an architectural high-resolution timer to make microarchitectural states visible to an attacker. In this paper, we present a new primitive that converts microarchitectural states into architectural states without relying on time measurements. We exploit the unprivileged idle-loop optimization instructions umonitor and umwait introduced with the new Intel microarchitectures (Tremont and Alder Lake). Although not documented, these instructions provide architectural feedback about the transient usage of a specified memory region. In three case studies, we show the versatility of our primitive. First, with Spectral, we present a way of enabling transient-execution attacks to leak bits architecturally with up to 200 kbit/s without requiring any architectural timer. Second, we show traditional side-channel attacks without relying on an architectural timer. Finally, we demonstrate that when augmented with a coarse-grained timer, we can also mount interrupt-timing attacks, allowing us to, e.g., detect which website a user opens. Our case studies highlight that the boundary between architecture and microarchitecture becomes more and more blurry, leading to new attack variants and complicating effective countermeasures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c7592fd2-afd3-406e-81cb-87812f3b10c6Cited by top-tier papers23
- ThermalScope: A Practical Interrupt Side Channel Attack Based on Thermal Event InterruptsXin Zhang, Zhi Zhang, Qingni Shen, Wenhao Wang et al.DAC 2024 · 12 citations
- TDXdown: Single-Stepping and Instruction Counting Attacks against Intel TDXLuca Wilke, Florian Sieck, Thomas EisenbarthCCS 2024 · 9 citations
- Uncovering and Exploiting AMD Speculative Memory Access Predictors for Fun and ProfitChang Liu, Dongsheng Wang, Yongqiang Lyu, Pengfei Qiu et al.HPCA 2024 · 9 citations
- ShadowLoad: Injecting State into Hardware PrefetchersLorenz Hetterich, Fabian Thomas, Lukas Gerlach, Ruiyi Zhang et al.ASPLOS 2025 · 9 citations
- Lost and Found in Speculation: Hybrid Speculative Vulnerability DetectionMohamadreza Rostami, Shaza Zeitouni, Rahul Kande, Chen Chen et al.DAC 2024 · 6 citations
Builds on38
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz et al.USENIX Security 2016 · 500 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
Related papers
- Whisper: Timing the Transient Execution to Leak Secrets and Break KASLRYu Jin, Chunlu Wang, Pengfei Qiu, Chang Liu et al.DAC 2024 · 1 citation
- Osiris: Automated Discovery of Microarchitectural Side ChannelsDaniel Weber, Ahmad Ibrahim, Hamed Nemati, Michael Schwarz et al.USENIX Security 2021 · 75 citations
- ÆPIC Leak: Architecturally Leaking Uninitialized Data from the MicroarchitecturePietro Borrello, Andreas Kogler, Martin Schwarzl, Moritz Lipp et al.USENIX Security 2022
- SegScope: Probing Fine-grained Interrupts via Architectural FootprintsXin Zhang, Zhi Zhang, Qingni Shen, Wenhao Wang et al.HPCA 2024 · 15 citations
- Rapid Reversing of Non-Linear CPU Cache Slice Functions: Unlocking Physical Address LeakageMikka Rainer, Lorenz Hetterich, Fabian Thomas, Tristan Hornetz et al.S&P 2025
