GADGETSPINNER: A New Transient Execution Primitive Using the Loop Stream Detector
Yun Chen, Ali Hajiabadi, Trevor E. Carlson
摘要
Transient execution attacks constitute a major class of attacks affecting all modern out-of-order CPUs. These attacks exploit transient execution windows (i.e., the instructions that execute but never commit) to leak confidential information from victims. Existing attacks either rely on branch mispredictions, incorrect memory speculation, or deferred exception handling to create transient windows. In this work, we introduce a new transient execution primitive, called GADGETSPINNER. We exploit the Loop Stream Detector (LSD) in Intel processors to perform out-of-loop-bounds execution and perform illegal operations. Our key observation is that the LSD holds on to an old copy of branch predictions from the first iteration of the loop and keeps using this copy until a branch misprediction occurs, i.e., advances beyond the loop bound. We exploit the delay between the speculative iteration of the loop and when the branch misprediction is resolved. In this paper, we analyze the transient execution of the LSD and perform end-to-end attacks to (1) perform illegal reads from protected memory regions, (2) bypass Intel SGX and extract the weights of a trained CNN model in DNNL library, (3) break Kernel ASLR (KASLR), and finally (4) perform cross-core/cross-process attacks. We also show that many defenses for prior transient execution attacks, like secure Branch Prediction Unit (BPU) designs, fail to protect against GADGETSPINNER.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper3
- Conjuring: Leaking Control Flow via Speculative Fetch AttacksAli Hajiabadi, Trevor E. CarlsonDAC 2024 · 被引用 5 次
- Cassandra: Efficient Enforcement of Sequential Execution for Cryptographic ProgramsAli Hajiabadi, Trevor E. CarlsonISCA 2025 · 被引用 2 次
- Levioso: Efficient Compiler-Informed Secure SpeculationAli Hajiabadi, Archit Agarwal, Andreas Diavastos, Trevor E. CarlsonDAC 2024 · 被引用 1 次
相关 Paper
- CacheOut: Leaking Data on Intel CPUs via Cache EvictionsStephan van Schaik, Marina Minkin, Andrew Kwong, Daniel Genkin 等S&P 2021 · 被引用 158 次
- CrossTalk: Speculative Data Leaks Across Cores Are RealHany Ragab, Alyssa Milburn, Kaveh Razavi, Herbert Bos 等S&P 2021 · 被引用 162 次
- Downfall: Exploiting Speculative Data GatheringDaniel MoghimiUSENIX Security 2023
- LVI: Hijacking Transient Execution through Microarchitectural Load Value InjectionJo Van Bulck, Daniel Moghimi, Michael Schwarz, Moritz Lipp 等S&P 2020 · 被引用 275 次
- Inception: Exposing New Attack Surfaces with Training in Transient ExecutionDaniël Trujillo, Johannes Wikner, Kaveh RazaviUSENIX Security 2023
