Revizor: testing black-box CPUs against speculation contracts
Oleksii Oleksenko, Christof Fetzer, Boris Köpf, Mark Silberstein
摘要
Speculative vulnerabilities such as Spectre and Meltdown expose speculative execution state that can be exploited to leak information across security domains via side-channels. Such vulnerabilities often stay undetected for a long time as we lack the tools for systematic testing of CPUs to find them.
In this paper, we propose an approach to automatically detect microarchitectural information leakage in commercial black-box CPUs. We build on speculation contracts, which we employ to specify the permitted side effects of program execution on the CPU's microarchitectural state. We propose a Model-based Relational Testing (MRT) technique to empirically assess the CPU compliance with these specifications.
We implement MRT in a testing framework called Revizor, and showcase its effectiveness on real Intel x86 CPUs. Revizor automatically detects violations of a rich set of contracts, or indicates their absence. A highlight of our findings is that Revizor managed to automatically surface Spectre, MDS, and LVI, as well as several previously unknown variants.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper29
- WhisperFuzz: White-Box Fuzzing for Detecting and Locating Timing Vulnerabilities in ProcessorsPallavi Borkar, Chen Chen, Mohamadreza Rostami, Nikhilesh Singh 等USENIX Security 2024 · 被引用 31 次
- Pensieve: Microarchitectural Modeling for Security EvaluationYuheng Yang, Thomas Bourgeat, Stella Lau, Mengjia YanISCA 2023 · 被引用 23 次
- Specification and Verification of Side-channel Security for Open-source Processors via Leakage ContractsZilong Wang, Gideon Mohr, Klaus von Gleissenthall, Jan Reineke 等CCS 2023 · 被引用 20 次
- Serberus: Protecting Cryptographic Code from Spectres at Compile-TimeNicholas Mosier, Hamed Nemati, John C. Mitchell, Caroline TrippelS&P 2024 · 被引用 16 次
- RTL Verification for Secure Speculation Using Contract Shadow LogicQinhan Tan, Yuheng Yang, Thomas Bourgeat, Sharad Malik 等ASPLOS 2025 · 被引用 12 次
它引用的顶会 Paper20
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck 等CCS 2019 · 被引用 464 次
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo 等S&P 2019 · 被引用 408 次
- Fallout: Leaking Data on Meltdown-resistant CPUsClaudio Canella, Daniel Genkin, Lukas Giner, Daniel Gruss 等CCS 2019 · 被引用 289 次
相关 Paper
- Speculation at Fault: Modeling and Testing Microarchitectural Leakage of CPU ExceptionsJana Hofmann, Emanuele Vannacci, Cédric Fournet, Boris Köpf 等USENIX Security 2023
- Enter, Exit, Page Fault, Leak : Testing Isolation Boundaries for Microarchitectural LeaksOleksii Oleksenko, Flavien Solt, Cédric Fournet, Jana Hofmann 等S&P 2026 · 被引用 4 次
- Hide and Seek with Spectres: Efficient discovery of speculative information leaks with random testingOleksii Oleksenko, Marco Guarnieri, Boris Köpf, Mark SilbersteinS&P 2023
- Phantom Trails: Practical Pre-Silicon Discovery of Transient Data LeaksAlvise de Faveri Tron, Raphael Isemann, Hany Ragab, Cristiano Giuffrida 等USENIX Security 2025
- Trevex: A Black-Box Detection Framework for Data-Flow Transient Execution VulnerabilitiesDaniel Weber, Fabian Thomas, Leon Trampert, Ruiyi Zhang 等S&P 2026 · 被引用 1 次
