USENIX Security2021Top-tier venue
Frontal Attack: Leaking Control-Flow in SGX via the CPU Frontend
Ivan Puddu, Moritz Schneider, Miro Haller, Srdjan Capkun
Abstract
We introduce a new timing side-channel attack on Intel CPU processors. Our Frontal attack exploits the way that CPU frontend fetches and processes instructions while being interrupted. In particular, we observe that in modern Intel CPUs, some instruction's execution times will depend on which operations precede and succeed them, and on their virtual addresses. Unlike previous attacks that could only profile branches if they contained different code or were based on conditional jumps, the attack allows the adversary to distinguish between instruction-wise identical branches. As the attack requires OS capabilities to set the interrupts, we use it to exploit SGX enclaves. Our attack demonstrates that a realistic SGX attacker can always observe the full enclave instruction trace, and secret-depending branching should not be used even alongside defenses to current controlled-channel attacks. We show that the adversary can use the Frontal attack to extract a secret from an SGX enclave if that secret was used as a branching condition for two instruction-wise identical branches. The attack can be exploited against several crypto libraries and affects all Intel CPUs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ea0e7d72-1741-485f-8dac-70a8eac4b274Cited by top-tier papers31
- CacheWarp: Software-based Fault Injection using Selective State ResetRuiyi Zhang, Lukas Gerlach, Daniel Weber, Lorenz Hetterich et al.USENIX Security 2024 · 36 citations
- Obelix: Mitigating Side-Channels Through Dynamic ObfuscationJan Wichelmann, Anja Rabich, Anna Pätschke, Thomas EisenbarthS&P 2024 · 15 citations
- On (the Lack of) Code Confidentiality in Trusted Execution EnvironmentsIvan Puddu, Moritz Schneider, Daniele Lain, Stefano Boschetto et al.S&P 2024 · 14 citations
- A Systematic Evaluation of Automated Tools for Side-Channel Vulnerabilities Detection in Cryptographic LibrariesAntoine Geimer, Mathéo Vergnolle, Frédéric Recoules, Lesly-Ann Daniel et al.CCS 2023 · 12 citations
- All Your PC Are Belong to Us: Exploiting Non-control-Transfer Instruction BTB Updates for Dynamic PC ExtractionJiyong Yu, Trent Jaeger, Christopher Wardlaw FletcherISCA 2023 · 12 citations
Builds on15
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim et al.USENIX Security 2017 · 536 citations
- T-SGX: Eradicating Controlled-Channel Attacks Against Enclave ProgramsMing-Wei Shih, Sangho Lee, Taesoo Kim, Marcus PeinadoNDSS 2017 · 431 citations
- Leaky Cauldron on the Dark Land: Understanding Memory Side-Channel Hazards in SGXWenhao Wang, Guoxing Chen, Xiaorui Pan, Yinqian Zhang et al.CCS 2017 · 403 citations
Related papers
- Telling Your Secrets without Page Faults: Stealthy Page Table-Based Attacks on Enclaved ExecutionJo Van Bulck, Nico Weichbrodt, Rüdiger Kapitza, Frank Piessens et al.USENIX Security 2017 · 316 citations
- CopyCat: Controlled Instruction-Level Attacks on EnclavesDaniel Moghimi, Jo Van Bulck, Nadia Heninger, Frank Piessens et al.USENIX Security 2020
- Leaky Frontends: Security Vulnerabilities in Processor FrontendsShuwen Deng, Bowen Huang, Jakub SzeferHPCA 2022 · 27 citations
- Nemesis: Studying Microarchitectural Timing Leaks in Rudimentary CPU Interrupt LogicJo Van Bulck, Frank Piessens, Raoul StrackxCCS 2018 · 141 citations
- AEX-Notify: Thwarting Precise Single-Stepping Attacks through Interrupt Awareness for Intel SGX EnclavesScott Constable, Jo Van Bulck, Xiang Cheng, Yuan Xiao et al.USENIX Security 2023
