One Flew over the Stack Engine's Nest: Practical Microarchitectural Attacks on the Stack Engine
Silvan Niederer, Sandro Rüegge, Ali Hajiabadi, Kaveh Razavi
摘要
Security research on modern CPUs has raised numerous concerns in recent years.These security issues stem from classic microarchitectural optimizations designed decades ago, without consideration for security.Stack pointer tracking, also known as the stack engine in recent CPUs, is one such optimization.To investigate the security implications of the stack engine, we reverse engineer its operational details on a number of recent Intel and AMD CPUs for the first time.Our results show the particular microarchitecturedependent behaviors of the stack engine, such as the conditions under which it needs to synchronize the stack pointer values with the backend.Using these results, we build three primitives called Direct Underflow, Sync+Reload and Prime+Sync+Probe that enable information leakage through the stack engine under different conditions.We use these primitives in the construction of various covert and side-channel attacks, leaking sensitive patient records from a widely-used JSON library as an example.Our mitigation efforts reveal that recent AMD Zen 4 and Zen 5 CPUs include undocumented chicken bits which allow enabling or disabling the stack engine.Using these bits to disable the stack engine, we measure 3.98% and 3.94% slowdown using SPEC CPU2017 on Zen 4 and Zen 5, respectively, prompting the need to consider more secure designs for the stack engine in future CPUs which we also discuss. CCS Concepts• Security and privacy → Side-channel analysis and countermeasures.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper1
问问它们各自怎么用它相关 Paper
- SQUIP: Exploiting the Scheduler Queue Contention Side ChannelStefan Gast, Jonas Juffinger, Martin Schwarzl, Gururaj Saileshwar 等S&P 2023
- Microarchitectural Leakage Templates and Their Application to Cache-Based Side ChannelsAhmad Ibrahim, Hamed Nemati, Till Schlüter, Nils Ole Tippenhauer 等CCS 2022 · 被引用 4 次
- FetchBench: Systematic Identification and Characterization of Proprietary PrefetchersTill Schlüter, Amit Choudhari, Lorenz Hetterich, Leon Trampert 等CCS 2023 · 被引用 11 次
- Don't Mesh Around: Side-Channel Attacks and Mitigations on Mesh InterconnectsMiles Dai, Riccardo Paccagnella, Miguel Gomez-Garcia, John D. McCalpin 等USENIX Security 2022
- ExfilState: Automated Discovery of Timer-Free Cache Side Channels on ARM CPUsFabian Thomas, Michael Torres, Daniel Moghimi, Michael SchwarzCCS 2025
