Speculation at Fault: Modeling and Testing Microarchitectural Leakage of CPU Exceptions
Jana Hofmann, Emanuele Vannacci, Cédric Fournet, Boris Köpf, Oleksii Oleksenko
摘要
Microarchitectural leakage models provide effective tools to prevent vulnerabilities such as Spectre and Meltdown via secure co-design: For software, they provide a foundation for secure compilation and verification; for hardware, they provide a target specification to test and verify against. Unfortunately, existing leakage models are severely limited: None of them covers CPU exceptions, which are essential to implement security abstractions such as virtualization and memory protection, and which are the source of critical vulnerabilities such as Meltdown, MDS, and Foreshadow. In this paper, we provide the first leakage models for CPU exceptions, together with new tools for testing black-box CPUs against them. We run extensive experiments and successively refine these models, until we precisely capture the leakage for a representative subset of exceptions on four different x86 microarchitectures. In the process, we contradict, refine, and corroborate a large number of findings from prior work, and we uncover three novel transient leaks affecting stores to non-canonical addresses, stores to read-only memory, and divisions by zero.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- "These results must be false": A usability evaluation of constant-time analysis toolsMarcel Fourné, Daniel De Almeida Braga, Jan Jancar, Mohamed Sabt 等USENIX Security 2024 · 被引用 15 次
- Testing Side-channel Security of Cryptographic Implementations against Future MicroarchitecturesGilles Barthe, Marcel Böhme, Sunjay Cauligi, Chitchanok Chuengsatiansup 等CCS 2024 · 被引用 6 次
- DejaVuzz: Disclosing Transient Execution Bugs with Dynamic Swappable Memory and Differential Information Flow Tracking Assisted Processor FuzzingJinyan Xu, Yangye Zhou, Xingzhi Zhang, Yinshuai Li 等ASPLOS 2025 · 被引用 4 次
- Enter, Exit, Page Fault, Leak : Testing Isolation Boundaries for Microarchitectural LeaksOleksii Oleksenko, Flavien Solt, Cédric Fournet, Jana Hofmann 等S&P 2026 · 被引用 4 次
- AMuLeT: Automated Design-Time Testing of Secure Speculation CountermeasuresBo Fu, Leo Tenenbaum, David Adler, Assaf Klein 等ASPLOS 2025 · 被引用 3 次
它引用的顶会 Paper28
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck 等CCS 2019 · 被引用 464 次
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo 等S&P 2019 · 被引用 408 次
相关 Paper
- Revizor: testing black-box CPUs against speculation contractsOleksii Oleksenko, Christof Fetzer, Boris Köpf, Mark SilbersteinASPLOS 2022 · 被引用 36 次
- Crucible: Retrofitting Commodity CPUs with Vulnerabilities via Transparent Software EmulationTristan Hornetz, Lukas Gerlach, Michael SchwarzS&P 2026
- Structural Operational Semantics for Functional and Security Verification of Pipelined ProcessorsRobert J. Colvin, Roger C. SuCAV 2025 · 被引用 2 次
- Trevex: A Black-Box Detection Framework for Data-Flow Transient Execution VulnerabilitiesDaniel Weber, Fabian Thomas, Leon Trampert, Ruiyi Zhang 等S&P 2026 · 被引用 1 次
- Hide and Seek with Spectres: Efficient discovery of speculative information leaks with random testingOleksii Oleksenko, Marco Guarnieri, Boris Köpf, Mark SilbersteinS&P 2023
