AfterImage: Leaking Control Flow Data and Tracking Load Operations via the Hardware Prefetcher
Yun Chen, Lingfeng Pei, Trevor E. Carlson
摘要
Research into processor-based side-channels has seen both a large number and a large variety of disclosed vulnerabilities that can leak critical, private data to malicious attackers. While most previous works require speculative execution and the use of cache primitives to transmit data, our new approach, called AfterImage, requires neither, capitalizing on vulnerabilities in Intel’s IP-stride prefetcher to both expose and transmit victim data. By training this prefetcher with attacker-known values, and watching for changes to the prefetcher state when execution returns to the attacker, it is now possible to monitor and leak critical data from a large number of common userspace applications and kernel routines without speculation and additional cache accesses. To demonstrate the novel capabilities of AfterImage, we (1) present proof-of-concept attacks that leak data across different isolation levels, (2) present an end-to-end attack that leaks an entire RSA key from a modern, timing-balanced algorithm, and also (3) show how AfterImage can significantly improve the effectiveness of other attacks, such as power side-channel attacks, by using this technique as a high-precision marker.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper19
- GoFetch: Breaking Constant-Time Cryptographic Implementations Using Data Memory-Dependent PrefetchersBoru Chen, Yingchen Wang, Pradyumna Shome, Christopher W. Fletcher 等USENIX Security 2024 · 被引用 52 次
- All Your PC Are Belong to Us: Exploiting Non-control-Transfer Instruction BTB Updates for Dynamic PC ExtractionJiyong Yu, Trent Jaeger, Christopher Wardlaw FletcherISCA 2023 · 被引用 12 次
- FetchBench: Systematic Identification and Characterization of Proprietary PrefetchersTill Schlüter, Amit Choudhari, Lorenz Hetterich, Leon Trampert 等CCS 2023 · 被引用 11 次
- Uncovering and Exploiting AMD Speculative Memory Access Predictors for Fun and ProfitChang Liu, Dongsheng Wang, Yongqiang Lyu, Pengfei Qiu 等HPCA 2024 · 被引用 9 次
- ShadowLoad: Injecting State into Hardware PrefetchersLorenz Hetterich, Fabian Thomas, Lukas Gerlach, Ruiyi Zhang 等ASPLOS 2025 · 被引用 9 次
相关 Paper
- PREFETCHX: Cross-Core Cache-Agnostic Prefetcher-based Side-Channel AttacksYun Chen, Ali Hajiabadi, Lingfeng Pei, Trevor E. CarlsonHPCA 2024 · 被引用 15 次
- Unveiling Hardware-based Data Prefetcher, a Hidden Source of Information LeakageYoung-joo Shin, Hyung Chan Kim, Dokeun Kwon, Ji-Hoon Jeong 等CCS 2018 · 被引用 73 次
- Peek-a-Walk: Leaking Secrets via Page Walk Side ChannelsAlan Wang, Boru Chen, Yingchen Wang, Christopher W. Fletcher 等S&P 2025
- Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLRDaniel Gruss, Clémentine Maurice, Anders Fogh, Moritz Lipp 等CCS 2016 · 被引用 278 次
- AMD Prefetch Attacks through Power and TimeMoritz Lipp, Daniel Gruss, Michael SchwarzUSENIX Security 2022
