On the effectiveness of mitigations against floating-point timing channels
David Kohlbrenner, Hovav Shacham
摘要
The duration of floating-point instructions is a known timing side channel that has been used to break Same-Origin Policy (SOP) privacy on Mozilla Firefox and the Fuzz differentially private database. Several defenses have been proposed to mitigate these attacks.
We present detailed benchmarking of floating point performance for various operations based on operand values. We identify families of values that induce slow and fast paths beyond the classes (normal, subnormal, etc.) considered in previous work, and note that different processors exhibit different timing behavior.
We evaluate the efficacy of the defenses deployed (or not) in Web browsers to floating point side channel attacks on SVG filters. We find that Google Chrome, Mozilla Firefox, and Apple's Safari have insufficiently addressed the floating-point side channel, and we present attacks for each that extract pixel data cross-origin on most platforms.
We evaluate the vector-operation based defensive mechanism proposed at USENIX Security 2016 by Rane, Lin and Tiwari and find that it only reduces, not eliminates, the floating-point side channel signal.
Together, these measurements and attacks cause us to conclude that floating point is simply too variable to use in a timing security sensitive context.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper22
- Rage Against the Machine Clear: A Systematic Analysis of Machine Clears and Their Implications for Transient Execution AttacksHany Ragab, Enrico Barberis, Herbert Bos, Cristiano GiuffridaUSENIX Security 2021 · 被引用 76 次
- IODINE: Verifying Constant-Time Execution of HardwareKlaus von Gleissenthall, Rami Gökhan Kici, Deian Stefan, Ranjit JhalaUSENIX Security 2019 · 被引用 45 次
- Towards Verified, Constant-time Floating Point OperationsMarc Andrysco, Andres Nötzli, Fraser Brown, Ranjit Jhala 等CCS 2018 · 被引用 33 次
- Spook.js: Attacking Chrome Strict Site Isolation via Speculative ExecutionAyush Agarwal, Sioli O'Connell, Jason Kim, Shaked Yehezkel 等S&P 2022 · 被引用 32 次
- Rendered Private: Making GLSL Execution Uniform to Prevent WebGL-based Browser FingerprintingShujiang Wu, Song Li, Yinzhi Cao, Ningfei WangUSENIX Security 2019 · 被引用 27 次
它引用的顶会 Paper4
- ASLR on the Line: Practical Cache Attacks on the MMUBen Gras, Kaveh Razavi, Erik Bosman, Herbert Bos 等NDSS 2017 · 被引用 276 次
- Verifying Constant-Time ImplementationsJosé Bacelar Almeida, Manuel Barbosa, Gilles Barthe, François Dupressoir 等USENIX Security 2016 · 被引用 274 次
- Trusted Browsers for Uncertain TimesDavid Kohlbrenner, Hovav ShachamUSENIX Security 2016 · 被引用 83 次
- Secure, Precise, and Fast Floating-Point Operations on x86 ProcessorsAshay Rane, Calvin Lin, Mohit TiwariUSENIX Security 2016 · 被引用 34 次
相关 Paper
- Pixel Thief: Exploiting SVG Filter Leakage in Firefox and ChromeSioli O'Connell, Lishay Aben Sour, Ron Magen, Daniel Genkin 等USENIX Security 2024 · 被引用 5 次
- Extension Breakdown: Security Analysis of Browsers Extension Resources Control PoliciesIskander Sánchez-Rola, Igor Santos, Davide BalzarottiUSENIX Security 2017 · 被引用 67 次
- Rendering Contention Channel Made Practical in Web BrowsersShujiang Wu, Jianjia Yu, Min Yang, Yinzhi CaoUSENIX Security 2022
- Déjà Vu: Side-Channel Analysis of Mozilla's NSSSohaib ul Hassan, Iaroslav Gridin, Ignacio M. Delgado-Lozano, Cesar Pereida García 等CCS 2020 · 被引用 4 次
- Pool-Party: Exploiting Browser Resource Pools for Web TrackingPeter Snyder, Soroush Karami, Arthur Edelstein, Benjamin Livshits 等USENIX Security 2023
