Lune

USENIX Security2023顶会

Downfall: Exploiting Speculative Data Gathering

Daniel Moghimi

出版方
2023年份
26顶会引用

摘要

We introduce Downfall attacks, new transient execution attacks that undermine the security of computers running everywhere across the internet. We exploit the gather instruction on high-performance x86 CPUs to leak data across boundaries of user-kernel, processes, virtual machines, and trusted execution environments. We also develop practical and end-to-end attacks to steal cryptographic keys, program's runtime data, and even data at rest (arbitrary data). Our findings, exploitation techniques, and demonstrated attacks defeat all previous defenses, calling for critical hardware fixes and security updates for widely-used client and server computers. Stealing Cryptographic Keys ( §5) We demonstrate endto-end cross-VM attacks against widely-used modern cryptographic software that uses SIMD instructions for efficient and secure (constant-time) execution. We steal AES-128 and AES-256 keys from the off-the-shelf OpenSSL command line tool for encrypting data. Unlike previous such attacks, our attack is simple and reliable; In less than 10 seconds, we steal AES round keys, 8 bytes at a time, and combine them to break AES without any cryptanalysis, source code analysis, or any data analysis tricks required by previous attacks [52, 60] . Stealing Arbitrary Data ( §6) We discover that GDS can steal data from no-op operations that do not do anything architecturally. Masked memory operations, when the masked bit is unset, and the streaming data copy instructions, when the data copy size is zero, should not execute architecturally. But, we found that Intel CPUs transiently prefetch data into the leaky SIMD register buffers when such no-op operations are

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper26

问问它们各自怎么用它

它引用的顶会 Paper21

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖