Augury: Using Data Memory-Dependent Prefetchers to Leak Data at Rest
Jose Rodrigo Sanchez Vicarte, Michael Flanders, Riccardo Paccagnella, Grant Garrett-Grossman, Adam Morrison, Christopher W. Fletcher, David Kohlbrenner
摘要
Microarchitectural side-channel attacks are enjoying a time of explosive growth, mostly fueled by novel transient execution vulnerabilities. These attacks are capable of leaking arbitrary data, as long as it is possible for the adversary to read that data into the processor core using transient instructions. In this paper, we present the first microarchitectural attack that leaks data at rest in the memory system, i.e., never directly read into the core speculatively or non-speculatively. This technique is enabled by a previously unreported class of prefetcher: a data memory-dependent prefetcher (DMP). These prefetchers are designed to allow prefetching of irregular address patterns such as pointer chases. As such, DMPs examine and use the contents of memory directly to determine which addresses to prefetch. Our experiments demonstrate the existence of a pointer-chasing DMP on recent Apple processors, including the A14 and M1. We then reverse engineer the details of this DMP to determine the opportunities for and restrictions it places on attackers using it. Finally, we demonstrate several basic attack primitives capable of leaking pointer values using the DMP.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper36
- GoFetch: Breaking Constant-Time Cryptographic Implementations Using Data Memory-Dependent PrefetchersBoru Chen, Yingchen Wang, Pradyumna Shome, Christopher W. Fletcher 等USENIX Security 2024 · 被引用 52 次
- Page Size Aware Cache PrefetchingGeorgios Vavouliotis, Gino Chacon, Lluc Alvarez, Paul V. Gratz 等MICRO 2022 · 被引用 24 次
- iLeakage: Browser-based Timerless Speculative Execution Attacks on Apple DevicesJason Kim, Stephan van Schaik, Daniel Genkin, Yuval YaromCCS 2023 · 被引用 16 次
- BUSted!!! Microarchitectural Side-Channel Attacks on the MCU Bus InterconnectCristiano Rodrigues, Daniel Oliveira, Sandro PintoS&P 2024 · 被引用 15 次
- "These results must be false": A usability evaluation of constant-time analysis toolsMarcel Fourné, Daniel De Almeida Braga, Jan Jancar, Mohamed Sabt 等USENIX Security 2024 · 被引用 15 次
它引用的顶会 Paper12
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim 等USENIX Security 2017 · 被引用 536 次
- Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB AttacksBen Gras, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaUSENIX Security 2018 · 被引用 357 次
- Theory and Practice of Finding Eviction SetsPepe Vila, Boris Köpf, José F. MoralesS&P 2019 · 被引用 145 次
相关 Paper
- SLAP: Data Speculation Attacks via Load Address Prediction on Apple SiliconJason Kim, Daniel Genkin, Yuval YaromS&P 2025
- Peek-a-Walk: Leaking Secrets via Page Walk Side ChannelsAlan Wang, Boru Chen, Yingchen Wang, Christopher W. Fletcher 等S&P 2025
- Unveiling Hardware-based Data Prefetcher, a Hidden Source of Information LeakageYoung-joo Shin, Hyung Chan Kim, Dokeun Kwon, Ji-Hoon Jeong 等CCS 2018 · 被引用 73 次
- FLOP: Breaking the Apple M3 CPU via False Load Output PredictionsJason Kim, Jalen Chuang, Daniel Genkin, Yuval YaromUSENIX Security 2025
- PACMAN: attacking ARM pointer authentication with speculative executionJoseph Ravichandran, Weon Taek Na, Jay Lang, Mengjia YanISCA 2022 · 被引用 68 次
