Leaky Frontends: Security Vulnerabilities in Processor Frontends
Shuwen Deng, Bowen Huang, Jakub Szefer
摘要
This paper evaluates new security threats due to the processor frontend in modern Intel processors. The root causes of the security threats are the multiple paths in the processor frontend that the micro-operations can take: through the Micro-Instruction Translation Engine (MITE), through the Decode Stream Buffer (DSB), also called the Micro-operation Cache, or through the Loop Stream Detector (LSD). Each path has its own unique timing and power signatures, which lead to the side- and covert-channel attacks presented in this work. Especially, the switching between the different paths leads to observable timing or power differences which, as this work demonstrates, could be exploited by attackers. Because of the different paths, the switching, and way the components are shared in the frontend between hardware threads, two separate threads are able to be mutually influenced and timing or power can reveal activity on the other thread. The security threats are not limited to multi-threading, and this work further demonstrates new ways for leaking execution information about SGX enclaves or a new in-domain Spectre variant in single-thread setting. Finally, this work demonstrates a new method for fingerprinting the microcode patches of the processor by analyzing the behavior of different paths in the frontend. The findings of this work highlight the security threats associated with the processor frontend and the need for deployment of defenses for the modern processor frontend.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper13
- Uncovering and Exploiting AMD Speculative Memory Access Predictors for Fun and ProfitChang Liu, Dongsheng Wang, Yongqiang Lyu, Pengfei Qiu 等HPCA 2024 · 被引用 9 次
- Doppelganger Loads: A Safe, Complexity-Effective Optimization for Secure Speculation SchemesAmund Bergland Kvalsvik, Pavlos Aimoniotis, Stefanos Kaxiras, Magnus SjälanderISCA 2023 · 被引用 9 次
- Uncore Encore: Covert Channels Exploiting Uncore Frequency ScalingYanan Guo, Dingyuan Cao, Xin Xin, Youtao Zhang 等MICRO 2023 · 被引用 9 次
- Conjuring: Leaking Control Flow via Speculative Fetch AttacksAli Hajiabadi, Trevor E. CarlsonDAC 2024 · 被引用 5 次
- Libra: Architectural Support For Principled, Secure And Efficient Balanced Execution On High-End ProcessorsHans Winderix, Marton Bognar, Lesly-Ann Daniel, Frank PiessensCCS 2024 · 被引用 4 次
它引用的顶会 Paper13
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp 等USENIX Security 2019 · 被引用 442 次
- Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLRDaniel Gruss, Clémentine Maurice, Anders Fogh, Moritz Lipp 等CCS 2016 · 被引用 278 次
- PLATYPUS: Software-based Power Side-Channel Attacks on x86Moritz Lipp, Andreas Kogler, David F. Oswald, Michael Schwarz 等S&P 2021 · 被引用 242 次
相关 Paper
- Frontal Attack: Leaking Control-Flow in SGX via the CPU FrontendIvan Puddu, Moritz Schneider, Miro Haller, Srdjan CapkunUSENIX Security 2021 · 被引用 63 次
- Exploitation of Security Vulnerability on RetirementKe Xu, Ming Tang, Quancheng Wang, Han WangHPCA 2024 · 被引用 3 次
- I See Dead µops: Leaking Secrets via Intel/AMD Micro-Op CachesXida Ren, Logan Moody, Mohammadkazem Taram, Matthew Jordan 等ISCA 2021 · 被引用 59 次
- LVI: Hijacking Transient Execution through Microarchitectural Load Value InjectionJo Van Bulck, Daniel Moghimi, Michael Schwarz, Moritz Lipp 等S&P 2020 · 被引用 275 次
- GADGETSPINNER: A New Transient Execution Primitive Using the Loop Stream DetectorYun Chen, Ali Hajiabadi, Trevor E. CarlsonHPCA 2024 · 被引用 6 次
