Exploiting Hidden Resource Contention in Selective Speculation Defenses
Xiaoyu Cheng, Fei Tong, Zhenyu Lei, Fang Jiang, Zhe Zhou, Guang Cheng, Trevor E. Carlson
摘要
Transient execution attacks continue to evolve beyond cache-centric channels, motivating selective speculation defenses that aim to provide comprehensive protection with low overhead by delaying only transmit instructions. In this work, we show that several state-of-the-art selective-speculation defenses rest on shared assumptions that overlook important microarchitectural behaviors, leaving systematic blind spots that admit secret-dependent reservation-station (RS) contention. Our analysis identifies three limitations in optimized selective-speculation designs. First, existing transmit taxonomies emphasize post-issue execution effects and miss dispatch-phase channels, such as operand-dependent μop expansion in instructions (e.g., REP-prefixed string operations) that create operand-dependent RS occupancy before execution. Second, the delay-until-resolution strategy focuses on redirect-based control leakage, but predicated instructions (e.g., x86 CMOV and RISC-V Zicond) enable secret-dependent selection without branch resolution, allowing secrets to steer operand-dependent μop expansion (e.g., REP iteration counts). Finally, the older-μop-first allocation strategy assumes unsafe contention is prevented by prioritizing non-transient μops, yet undelayed arithmetic and cache-hit memory μops can still lead to secret-dependent RS pressure through latency-amplifying dependency chains. Guided by these findings, we construct Spectre-v1-style gadgets that bypass STT/DOLMA on x86 and RISC-V gem5 models. We further validate RS-contention effects on real CPUs, including a REP MOVSB- and REP STOSB-based proof-of-concept and a real-world RS-contention pattern identified by our LLVM pass, demonstrating realistic gadget structure and measurable signal. Finally, we propose strengthened STT mechanisms that close both existing and newly exposed gaps at moderate performance overhead.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper24
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo 等S&P 2019 · 被引用 408 次
- ret2spec: Speculative Execution Using Return Stack BuffersGiorgi Maisuradze, Christian RossowCCS 2018 · 被引用 282 次
相关 Paper
- Conditional address propagation: an efficient defense mechanism against transient execution attacksPeinan Li, Rui Hou, Lutan Zhao, Yifan Zhu 等DAC 2022 · 被引用 1 次
- Perspective: A Principled Framework for Pliable and Secure Speculation in Operating SystemsTae Hoon Kim, David Rudo, Kaiyang Zhao, Zirui Neil Zhao 等ISCA 2024 · 被引用 6 次
- DOLMA: Securing Speculation with the Principle of Transient Non-ObservabilityKevin Loughlin, Ian Neal, Jiacheng Ma, Elisa Tsai 等USENIX Security 2021 · 被引用 94 次
- SPECRUN: The Danger of Speculative Runahead Execution in ProcessorsChaoqun Shen, Gang Qu, Jiliang ZhangDAC 2024 · 被引用 1 次
- Speculative interference attacks: breaking invisible speculation schemesMohammad Behnia, Prateek Sahu, Riccardo Paccagnella, Jiyong Yu 等ASPLOS 2021 · 被引用 69 次
