CryptoBTB: A Secure Hierarchical BTB for Diverse Instruction Footprint Workloads
Debpratim Adak, Eric Rotenberg, Amro Awad, Huiyang Zhou
摘要
Timing attacks leveraging shared resources on a CPU are a growing concern. Branch Target Buffer (BTB), a crucial component of highperformance processors, is shared among threads and privileged spaces. Recently, researchers discovered numerous vulnerabilities in the BTB, allowing an adversary to maliciously infer a victim's BTB update and mistrain the BTB. Such attacks can successfully bypass privilege-level and secure enclave protection, as well as address space isolation. Randomizing BTB through encrypted addressing to prevent these attacks suffers from high performance overhead due to exposed encryption latency in the pipeline. Prior works address this by using encryption schemes that are either not fully secure or require frequent flush. The most recent proposal, HyBP [79], uses stronger encryption schemes. However, it suffers from high overhead since it underutilizes the BTB and suffers from higher collisions within the same thread.
In this work, we propose CryptoBTB, a secure BTB, specifically designed for an exclusive BTB hierarchy. Our proposal decouples the index encryption from the index itself, enabling low-latency index encryption to obscure BTB set mapping. Additionally, unlike earlier secure BTB proposals, this scheme is well-suited for applications with a higher instruction footprint where performance is sensitive to the BTB capacity. We evaluated CryptoBTB on various classes of workloads that stress the BTB differently. Our results show that CryptoBTB incurs 4.27% performance overhead for these workloads, while HyBP experiences 31.89% overhead. Moreover, CryptoBTB requires 22.57% lower hardware overhead than HyBP.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper23
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck 等CCS 2019 · 被引用 464 次
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp 等USENIX Security 2019 · 被引用 442 次
- ScatterCache: Thwarting Cache Attacks via Cache Set RandomizationMario Werner, Thomas Unterluggauer, Lukas Giner, Michael Schwarz 等USENIX Security 2019 · 被引用 221 次
相关 Paper
- Indirector: High-Precision Branch Target Injection Attacks Exploiting the Indirect Branch PredictorLuyi Li, Hosein Yavarzadeh, Dean M. TullsenUSENIX Security 2024 · 被引用 18 次
- HyBP: Hybrid Isolation-Randomization Secure Branch PredictorLutan Zhao, Peinan Li, Rui Hou, Michael C. Huang 等HPCA 2022 · 被引用 10 次
- OCCUPY+PROBE: Cross-Privilege Branch Target Buffer Side-Channel Attacks at Instruction GranularityKaiyuan Rong, Junqi Fang, Haixia Wang, Dapeng Ju 等NDSS 2026
- HybCache: Hybrid Side-Channel-Resilient Caches for Trusted Execution EnvironmentsGhada Dessouky, Tommaso Frassetto, Ahmad-Reza SadeghiUSENIX Security 2020
- A Lightweight Isolation Mechanism for Secure Branch PredictorsLutan Zhao, Peinan Li, Rui Hou, Michael C. Huang 等DAC 2021 · 被引用 29 次
