OCCUPY+PROBE: Cross-Privilege Branch Target Buffer Side-Channel Attacks at Instruction Granularity
Kaiyuan Rong, Junqi Fang, Haixia Wang, Dapeng Ju, Dongsheng Wang
摘要
In recent years, the Branch Target Buffer (BTB) has raised significant concerns in system security research. As this component is logically or physically shared in certain attack scenarios, it is abused by adversaries to construct side-channels that leak sensitive branch information of victim processes. However, existing BTB side-channel attacks either fail to leak kernel control-flow information from user mode due to the cross-privilege isolation mechanism, or suffer from limited spatial resolution in branch monitoring. In this paper, we propose Occupy+Probe, a novel eviction-based BTB side-channel attack that bridges these gaps by successfully exposing kernel control-flow behaviors directly from user mode. Our approach begins with an in-depth reverse engineering of the offset-related BTB update mechanism on Intel processors, and reveals that textitBTB entries created in user mode can be directly replaced by kernel-mode entries, irrespective of the underlying replacement policy and the hardware isolation, which forms the foundation of Occupy+Probe. In contrast to existing BTB side-channel attacks, Occupy+Probe eliminates the need for entry sharing between the attacker and the victim. Moreover, it achieves instruction-level granularity in branch monitoring, surpassing the spatial resolution of existing eviction-based BTB side-channels. We experimentally demonstrate that Occupy+Probe can leak control-flow information across privilege boundaries with high spatial resolution on various Intel processors. Furthermore, we validate the practical effectiveness of Occupy+Probe through a detailed case study targeting the Linux Kernel Crypto API, showcasing its potential to compromise critical kernel operations. Additionally, compared to prior eviction-based BTB side-channels, Occupy+Probe demonstrates a unique capability to extract tag values of kernel branches, which can be exploited to break KASLR.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper17
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim 等USENIX Security 2017 · 被引用 536 次
- Data Oblivious ISA Extensions for Side Channel-Resistant and High Performance ComputingJiyong Yu, Lucas Hsiung, Mohamad El Hajj, Christopher W. FletcherNDSS 2019 · 被引用 106 次
- Frontal Attack: Leaking Control-Flow in SGX via the CPU FrontendIvan Puddu, Moritz Schneider, Miro Haller, Srdjan CapkunUSENIX Security 2021 · 被引用 63 次
- Exploring Branch Predictors for Constructing Transient Execution TrojansTao Zhang, Kenneth Koltermann, Dmitry EvtyushkinASPLOS 2020 · 被引用 32 次
相关 Paper
- Indirector: High-Precision Branch Target Injection Attacks Exploiting the Indirect Branch PredictorLuyi Li, Hosein Yavarzadeh, Dean M. TullsenUSENIX Security 2024 · 被引用 18 次
- All Your PC Are Belong to Us: Exploiting Non-control-Transfer Instruction BTB Updates for Dynamic PC ExtractionJiyong Yu, Trent Jaeger, Christopher Wardlaw FletcherISCA 2023 · 被引用 12 次
- CryptoBTB: A Secure Hierarchical BTB for Diverse Instruction Footprint WorkloadsDebpratim Adak, Eric Rotenberg, Amro Awad, Huiyang ZhouMICRO 2025 · 被引用 1 次
- SegScope: Probing Fine-grained Interrupts via Architectural FootprintsXin Zhang, Zhi Zhang, Qingni Shen, Wenhao Wang 等HPCA 2024 · 被引用 15 次
- TLB;DR: Enhancing TLB-based Attacks with TLB Desynchronized Reverse EngineeringAndrei Tatar, Daniël Trujillo, Cristiano Giuffrida, Herbert BosUSENIX Security 2022
