Exploring Branch Predictors for Constructing Transient Execution Trojans
Tao Zhang, Kenneth Koltermann, Dmitry Evtyushkin
摘要
Transient execution is one of the most critical features used in CPUs to achieve high performance. Recent Spectre attacks demonstrated how this feature can be manipulated to force applications to reveal sensitive data. The industry quickly responded with a series of software and hardware mitigations among which microcode patches are the most prevalent and trusted. In this paper, we argue that currently deployed protections still leave room for constructing attacks. We do so by presenting transient trojans, software modules that conceal their malicious activity within transient execution mode. They appear completely benign, pass static and dynamic analysis checks, but reveal sensitive data when triggered. To construct these trojans, we perform a detailed analysis of the attack surface currently present in today's systems with respect to the recommended mitigation techniques. We reverse engineer branch predictors in several recent x86_64 processors which allows us to uncover previously unknown exploitation techniques. Using these techniques, we construct three types of transient trojans and demonstrate their stealthiness and practicality.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper19
- Swivel: Hardening WebAssembly against SpectreShravan Narayan, Craig Disselkoen, Daniel Moghimi, Sunjay Cauligi 等USENIX Security 2021 · 被引用 74 次
- SoK: Practical Foundations for Software Spectre DefensesSunjay Cauligi, Craig Disselkoen, Daniel Moghimi, Gilles Barthe 等S&P 2022 · 被引用 59 次
- An Analysis of Speculative Type Confusion Vulnerabilities in the WildOfek Kirzner, Adam MorrisonUSENIX Security 2021 · 被引用 40 次
- Automatic Detection of Speculative Execution CombinationsXaver Fabian, Marco Guarnieri, Marco PatrignaniCCS 2022 · 被引用 19 次
- All Your PC Are Belong to Us: Exploiting Non-control-Transfer Instruction BTB Updates for Dynamic PC ExtractionJiyong Yu, Trent Jaeger, Christopher Wardlaw FletcherISCA 2023 · 被引用 12 次
它引用的顶会 Paper9
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp 等USENIX Security 2019 · 被引用 442 次
- ret2spec: Speculative Execution Using Return Stack BuffersGiorgi Maisuradze, Christian RossowCCS 2018 · 被引用 282 次
- Spectector: Principled Detection of Speculative Information FlowsMarco Guarnieri, Boris Köpf, José F. Morales, Jan Reineke 等S&P 2020 · 被引用 177 次
相关 Paper
- ConTExT: A Generic Approach for Mitigating SpectreMichael Schwarz, Moritz Lipp, Claudio Canella, Robert Schilling 等NDSS 2020
- Phantom: Exploiting Decoder-detectable MispredictionsJohannes Wikner, Daniël Trujillo, Kaveh RazaviMICRO 2023 · 被引用 19 次
- An Exploratory Analysis of Microcode as a Building Block for System DefensesBenjamin Kollenda, Philipp Koppe, Marc Fyrbiak, Christian Kison 等CCS 2018 · 被引用 13 次
- I See Dead µops: Leaking Secrets via Intel/AMD Micro-Op CachesXida Ren, Logan Moody, Mohammadkazem Taram, Matthew Jordan 等ISCA 2021 · 被引用 59 次
- Rain: Transiently Leaking Data from Public Clouds Using Old VulnerabilitiesMathé Hertogh, Dave Quakkelaar, Thijs Raymakers, Mahesh Hari Sarma 等S&P 2026 · 被引用 5 次
