Exposing cache timing side-channel leaks through out-of-order symbolic execution
Shengjian Guo, Yueqi Chen, Jiyong Yu, Meng Wu, Zhiqiang Zuo, Peng Li, Yueqiang Cheng, Huibo Wang
摘要
As one of the fundamental optimizations in modern processors, the out-of-order execution boosts the pipeline throughput by executing independent instructions in parallel rather than in their program orders. However, due to the side effects introduced by such microarchitectural optimization to the CPU cache, secret-critical applications may suffer from timing side-channel leaks. This paper presents a symbolic execution-based technique, named SymO 3 , for exposing cache timing leaks under the context of out-of-order execution. SymO 3 proposes new components that address the modeling, reduction, and reasoning challenges of accommodating program analysis to the software code out-of-order analysis. We implemented SymO 3 upon KLEE and conducted three evaluations on it. Experimental results show that SymO 3 successfully uncovers a set of cache timing leaks in five real-world programs. Also, SymO 3 finds that, in general, program transformation from compiler optimizations shrink the surface to timing leaks. Furthermore, augmented with a speculative execution modeling, SymO 3 identifies five more leaky programs based on the compound analysis.
• Security and privacy → Software and application security; • Software and its engineering → Software verification and validation.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- DeJITLeak: eliminating JIT-induced timing side-channel leaksQi Qin, JulianAndres JiYang, Fu Song, Taolue Chen 等FSE 2022 · 被引用 18 次
- Eunomia: Enabling User-Specified Fine-Grained Search in Symbolically Executing WebAssembly BinariesNingyu He, Zhehao Zhao, Jikai Wang, Yubin Hu 等ISSTA 2023 · 被引用 10 次
- SymGX: Detecting Cross-boundary Pointer Vulnerabilities of SGX Applications via Static Symbolic ExecutionYuanpeng Wang, Ziqi Zhang, Ningyu He, Zhineng Zhong 等CCS 2023 · 被引用 8 次
它引用的顶会 Paper16
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher 等NDSS 2016 · 被引用 1,021 次
- ASLR on the Line: Practical Cache Attacks on the MMUBen Gras, Kaveh Razavi, Erik Bosman, Herbert Bos 等NDSS 2017 · 被引用 276 次
相关 Paper
- SpecuSym: speculative symbolic execution for cache timing leak detectionShengjian Guo, Yueqi Chen, Peng Li, Yueqiang Cheng 等ICSE 2020 · 被引用 34 次
- CaSym: Cache Aware Symbolic Execution for Side Channel Detection and MitigationRobert Brotzman, Shen Liu, Danfeng Zhang, Gang Tan 等S&P 2019 · 被引用 77 次
- CacheD: Identifying Cache-Based Timing Channels in Production SoftwareShuai Wang, Pei Wang, Xiao Liu, Danfeng Zhang 等USENIX Security 2017 · 被引用 130 次
- Identifying Cache-Based Side Channels through Secret-Augmented Abstract InterpretationShuai Wang, Yuyan Bao, Xiao Liu, Pei Wang 等USENIX Security 2019 · 被引用 57 次
- GhostMinion: A Strictness-Ordered Cache System for Spectre MitigationSam AinsworthMICRO 2021 · 被引用 36 次
