A Systematic Evaluation of Transient Execution Attacks and Defenses
Claudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp, Benjamin von Berg, Philipp Ortner, Frank Piessens, Dmitry Evtyushkin, Daniel Gruss
摘要
Research on transient execution attacks including Spectre and Meltdown showed that exception or branch misprediction events might leave secret-dependent traces in the CPU's microarchitectural state. This observation led to a proliferation of new Spectre and Meltdown attack variants and even more ad-hoc defenses (e.g., microcode and software patches). Both the industry and academia are now focusing on finding effective defenses for known issues. However, we only have limited insight on residual attack surface and the completeness of the proposed defenses. In this paper, we present a systematization of transient execution attacks. Our systematization uncovers 6 (new) transient execution attacks that have been overlooked and not been investigated so far: 2 new exploitable Meltdown effects: Meltdown-PK (Protection Key Bypass) on Intel, and Meltdown-BND (Bounds Check Bypass) on Intel and AMD; and 4 new Spectre mistraining strategies. We evaluate the attacks in our classification tree through proof-of-concept implementations on 3 major CPU vendors (Intel, AMD, ARM). Our systematization yields a more complete picture of the attack surface and allows for a more systematic evaluation of defenses. Through this systematic evaluation, we discover that most defenses, including deployed ones, cannot fully mitigate all attack variants.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper113
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck 等CCS 2019 · 被引用 464 次
- LVI: Hijacking Transient Execution through Microarchitectural Load Value InjectionJo Van Bulck, Daniel Moghimi, Michael Schwarz, Moritz Lipp 等S&P 2020 · 被引用 275 次
- RAMBleed: Reading Bits in Memory Without Accessing ThemAndrew Kwong, Daniel Genkin, Daniel Gruss, Yuval YaromS&P 2020 · 被引用 239 次
- Firecracker: Lightweight Virtualization for Serverless ApplicationsAlexandru Agache, Marc Brooker, Alexandra Iordache, Anthony Liguori 等NSDI 2020 · 被引用 197 次
- Spectector: Principled Detection of Speculative Information FlowsMarco Guarnieri, Boris Köpf, José F. Morales, Jan Reineke 等S&P 2020 · 被引用 177 次
它引用的顶会 Paper9
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz 等USENIX Security 2016 · 被引用 500 次
- ret2spec: Speculative Execution Using Return Stack BuffersGiorgi Maisuradze, Christian RossowCCS 2018 · 被引用 282 次
- Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLRDaniel Gruss, Clémentine Maurice, Anders Fogh, Moritz Lipp 等CCS 2016 · 被引用 278 次
- SMoTherSpectre: Exploiting Speculative Execution through Port ContentionAtri Bhattacharyya, Alexandra Sandulescu, Matthias Neugschwandtner, Alessandro Sorniotti 等CCS 2019 · 被引用 267 次
相关 Paper
- Exploring Branch Predictors for Constructing Transient Execution TrojansTao Zhang, Kenneth Koltermann, Dmitry EvtyushkinASPLOS 2020 · 被引用 32 次
- Conditional address propagation: an efficient defense mechanism against transient execution attacksPeinan Li, Rui Hou, Lutan Zhao, Yifan Zhu 等DAC 2022 · 被引用 1 次
- A Formal Approach for Detecting Vulnerabilities to Transient Execution Attacks in Out-of-Order ProcessorsMohammad Rahmani Fadiheh, Johannes Müller, Raik Brinkmann, Subhasish Mitra 等DAC 2020 · 被引用 38 次
- An Exploratory Analysis of Microcode as a Building Block for System DefensesBenjamin Kollenda, Philipp Koppe, Marc Fyrbiak, Christian Kison 等CCS 2018 · 被引用 13 次
- New Models for Understanding and Reasoning about Speculative Execution AttacksZecheng He, Guangyuan Hu, Ruby B. LeeHPCA 2021 · 被引用 18 次
