Crucible: Retrofitting Commodity CPUs with Vulnerabilities via Transparent Software Emulation
Tristan Hornetz, Lukas Gerlach, Michael Schwarz
摘要
Transient-execution attacks such as Meltdown, Foreshadow, and MDS expose fundamental flaws in modern CPUs, yet reproducing and comparing them today is increasingly complex: vulnerable CPUs are scarce, lab setups cannot be shared easily, and results are hard to compare. These challenges make it difficult to evaluate detection tools, study exploits, or integrate attacks into teaching environments. As vulnerable CPUs become rarer, hands-on experimentation and consistent benchmarking gradually become infeasible, complicating both research and education in microarchitectural security.
In this paper, we introduce Crucible, a software-only framework that transparently simulates Meltdown-type transient execution vulnerabilities on any x86 CPU. Crucible simulates transient execution after a fault by shadowing the instruction stream in a different process to emulate key microarchitectural effects, such as cache leakage, transient windows, and fence behavior. Crucible runs unmodified public proofs-ofconcept and even complete exploits with leakage patterns that match real hardware. We reproduce 3 full end-to-end exploits for well-known vulnerabilities, such as key extraction from VeraCrypt with Meltdown, on unaffected hardware. Crucible supports testing of binary-only applications and integrates with state-of-the-art fuzzers, which detect simulated vulnerabilities with results comparable to real CPUs. We further simulate two artificial vulnerabilities to evaluate generalization in fuzzer behavior. Our work enables systematic, repeatable experiments, preserves legacy vulnerabilities for future use, allows comparison of vulnerability detection approaches, and provides an accessible platform for teaching and training in CPU security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper32
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck 等CCS 2019 · 被引用 464 次
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp 等USENIX Security 2019 · 被引用 442 次
相关 Paper
- Speculation at Fault: Modeling and Testing Microarchitectural Leakage of CPU ExceptionsJana Hofmann, Emanuele Vannacci, Cédric Fournet, Boris Köpf 等USENIX Security 2023
- Trevex: A Black-Box Detection Framework for Data-Flow Transient Execution VulnerabilitiesDaniel Weber, Fabian Thomas, Leon Trampert, Ruiyi Zhang 等S&P 2026 · 被引用 1 次
- SpecDoctor: Differential Fuzz Testing to Find Transient Execution VulnerabilitiesJaewon Hur, Suhwan Song, Sunwoo Kim, Byoungyoung LeeCCS 2022 · 被引用 19 次
- Shesha : Multi-head Microarchitectural Leakage Discovery in new-generation Intel ProcessorsAnirban Chakraborty, Nimish Mishra, Debdeep MukhopadhyayUSENIX Security 2024 · 被引用 3 次
- Medusa: Microarchitectural Data Leakage via Automated Attack SynthesisDaniel Moghimi, Moritz Lipp, Berk Sunar, Michael SchwarzUSENIX Security 2020
