A Formal Approach for Detecting Vulnerabilities to Transient Execution Attacks in Out-of-Order Processors
Mohammad Rahmani Fadiheh, Johannes Müller, Raik Brinkmann, Subhasish Mitra, Dominik Stoffel, Wolfgang Kunz
摘要
Transient execution attacks, such as Spectre and Meltdown, create a new and serious attack surface in modern processors. In spite of all countermeasures taken during recent years, the cycles of alarm and patch are ongoing and call for a better formal understanding of the threat and possible preventions.This paper introduces a formal definition of security with respect to transient execution attacks, formulated as a HW property. We present a formal method for security verification by HW property checking based on extending Unique Program Execution Checking (UPEC) to out-of-order processors. UPEC can be used to systematically detect all vulnerabilities to transient execution attacks, including vulnerabilities unknown so far. The feasibility of our approach is demonstrated at the example of the BOOM processor, which is a design with more than 650,000 state bits. In BOOM our approach detects a new, so far unknown vulnerability, called Spectre-STC, indicating that also single-threaded processors can be vulnerable to contention-based Spectre attacks.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper15
- SoK: Practical Foundations for Software Spectre DefensesSunjay Cauligi, Craig Disselkoen, Daniel Moghimi, Gilles Barthe 等S&P 2022 · 被引用 59 次
- Cascade: CPU Fuzzing via Intricate Program GenerationFlavien Solt, Katharina Ceesay-Seitz, Kaveh RazaviUSENIX Security 2024 · 被引用 46 次
- WhisperFuzz: White-Box Fuzzing for Detecting and Locating Timing Vulnerabilities in ProcessorsPallavi Borkar, Chen Chen, Mohamadreza Rostami, Nikhilesh Singh 等USENIX Security 2024 · 被引用 31 次
- Pensieve: Microarchitectural Modeling for Security EvaluationYuheng Yang, Thomas Bourgeat, Stella Lau, Mengjia YanISCA 2023 · 被引用 23 次
- SpecDoctor: Differential Fuzz Testing to Find Transient Execution VulnerabilitiesJaewon Hur, Suhwan Song, Sunwoo Kim, Byoungyoung LeeCCS 2022 · 被引用 19 次
相关 Paper
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp 等USENIX Security 2019 · 被引用 442 次
- Phantom Trails: Practical Pre-Silicon Discovery of Transient Data LeaksAlvise de Faveri Tron, Raphael Isemann, Hany Ragab, Cristiano Giuffrida 等USENIX Security 2025
- A Formal Approach to Confidentiality Verification in SoCs at the Register Transfer LevelJohannes Müller, Mohammad Rahmani Fadiheh, Anna Lena Duque Antón, Thomas Eisenbarth 等DAC 2021 · 被引用 11 次
- New Models for Understanding and Reasoning about Speculative Execution AttacksZecheng He, Guangyuan Hu, Ruby B. LeeHPCA 2021 · 被引用 18 次
- Conditional address propagation: an efficient defense mechanism against transient execution attacksPeinan Li, Rui Hou, Lutan Zhao, Yifan Zhu 等DAC 2022 · 被引用 1 次
