Pathfinder: High-Resolution Control-Flow Attacks Exploiting the Conditional Branch Predictor
Hosein Yavarzadeh, Archit Agarwal, Max Christman, Christina Garman, Daniel Genkin, Andrew Kwong, Daniel Moghimi, Deian Stefan, Kazem Taram, Dean M. Tullsen
摘要
This paper introduces novel attack primitives that enable adversaries to leak (read) and manipulate (write) the path history register (PHR) and the prediction history tables (PHTs) of the conditional branch predictor in high-performance CPUs. These primitives enable two new classes of attacks: first, it can recover the entire control flow history of a victim program by exploiting read primitives, as demonstrated by a practical secret-image recovery based on capturing the entire control flow of libjpeg routines. Second, it can launch extremely high-resolution transient attacks by exploiting write primitives. We demonstrate this with a key recovery attack against AES based on extracting intermediate values.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper15
- Indirector: High-Precision Branch Target Injection Attacks Exploiting the Indirect Branch PredictorLuyi Li, Hosein Yavarzadeh, Dean M. TullsenUSENIX Security 2024 · 被引用 18 次
- MDPeek: Breaking Balanced Branches in SGX with Memory Disambiguation Unit Side ChannelsChang Liu, Shuaihu Feng, Yuan Li, Dongsheng Wang 等ASPLOS 2025 · 被引用 7 次
- Enter, Exit, Page Fault, Leak : Testing Isolation Boundaries for Microarchitectural LeaksOleksii Oleksenko, Flavien Solt, Cédric Fournet, Jana Hofmann 等S&P 2026 · 被引用 4 次
- Efficient Memory Side-Channel Protection for Embedding Generation in Machine LearningMuhammad Umar, Akhilesh Parag Marathe, Monami Dutta Gupta, Shubham Jogprakash Ghosh 等HPCA 2025 · 被引用 2 次
- Cassandra: Efficient Enforcement of Sequential Execution for Cryptographic ProgramsAli Hajiabadi, Trevor E. CarlsonISCA 2025 · 被引用 2 次
相关 Paper
- Conjuring: Leaking Control Flow via Speculative Fetch AttacksAli Hajiabadi, Trevor E. CarlsonDAC 2024 · 被引用 5 次
- iEnFlow: Endogenous Control-Flow Attacks via Conditional Branch Prediction on Apple SiliconKaiyuan Rong, Jiajie Chen, Junqi Fang, Peng Qu 等CCS 2026
- SPECRUN: The Danger of Speculative Runahead Execution in ProcessorsChaoqun Shen, Gang Qu, Jiliang ZhangDAC 2024 · 被引用 1 次
- BunnyHop: Exploiting the Instruction PrefetcherZhiyuan Zhang, Mingtian Tao, Sioli O'Connell, Chitchanok Chuengsatiansup 等USENIX Security 2023
- Exploiting Inaccurate Branch History in Side-Channel AttacksYuhui Zhu, Alessandro BiondiUSENIX Security 2025
