Pensieve: Microarchitectural Modeling for Security Evaluation
Yuheng Yang, Thomas Bourgeat, Stella Lau, Mengjia Yan
摘要
Traditional modeling approaches in computer architecture aim to obtain an accurate estimation of performance, area, and energy of a processor design. With the advent of speculative execution attacks and their security concerns, these traditional modeling techniques fall short when used for security evaluation of defenses against these attacks.
This paper presents Pensieve, a security evaluation framework targeting early-stage microarchitectural defenses against speculative execution attacks. At the core, it introduces a modeling discipline for systematically studying early-stage defenses. This discipline allows us to cover a space of designs that are functionally equivalent while precisely capturing timing variations due to resource contention and microarchitectural optimizations. We implement a model checking framework to automatically find vulnerabilities in designs. We use Pensieve to evaluate a series of state-of-the-art invisible speculation defense schemes, including Delay-on-Miss, InvisiSpec, and GhostMinion, against a formally defined security property, speculative non-interference. Pensieve finds Spectre-like attacks in all those defenses, including a new speculative interference attack variant that breaks GhostMinion, one of the latest defenses.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- RTL Verification for Secure Speculation Using Contract Shadow LogicQinhan Tan, Yuheng Yang, Thomas Bourgeat, Sharad Malik 等ASPLOS 2025 · 被引用 12 次
- Testing Side-channel Security of Cryptographic Implementations against Future MicroarchitecturesGilles Barthe, Marcel Böhme, Sunjay Cauligi, Chitchanok Chuengsatiansup 等CCS 2024 · 被引用 6 次
- Secure Prefetching for Secure Cache SystemsSumon Nath, Agustín Navarro-Torres, Alberto Ros, Biswabandan PandaMICRO 2024 · 被引用 5 次
- DejaVuzz: Disclosing Transient Execution Bugs with Dynamic Swappable Memory and Differential Information Flow Tracking Assisted Processor FuzzingJinyan Xu, Yangye Zhou, Xingzhi Zhang, Yinshuai Li 等ASPLOS 2025 · 被引用 4 次
- AMuLeT: Automated Design-Time Testing of Secure Speculation CountermeasuresBo Fu, Leo Tenenbaum, David Adler, Assaf Klein 等ASPLOS 2025 · 被引用 3 次
它引用的顶会 Paper23
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB AttacksBen Gras, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaUSENIX Security 2018 · 被引用 357 次
- ret2spec: Speculative Execution Using Return Stack BuffersGiorgi Maisuradze, Christian RossowCCS 2018 · 被引用 282 次
- SMoTherSpectre: Exploiting Speculative Execution through Port ContentionAtri Bhattacharyya, Alexandra Sandulescu, Matthias Neugschwandtner, Alessandro Sorniotti 等CCS 2019 · 被引用 267 次
相关 Paper
- Speculative interference attacks: breaking invisible speculation schemesMohammad Behnia, Prateek Sahu, Riccardo Paccagnella, Jiyong Yu 等ASPLOS 2021 · 被引用 69 次
- Perspective: A Principled Framework for Pliable and Secure Speculation in Operating SystemsTae Hoon Kim, David Rudo, Kaiyang Zhao, Zirui Neil Zhao 等ISCA 2024 · 被引用 6 次
- Speculation Invariance (InvarSpec): Faster Safe Execution Through Program AnalysisZirui Neil Zhao, Houxiang Ji, Mengjia Yan, Jiyong Yu 等MICRO 2020 · 被引用 25 次
- EVAX: Towards a Practical, Pro-active & Adaptive Architecture for High Performance & SecuritySamira Mirbagher Ajorpaz, Daniel Moghimi, Jeffrey Neal Collins, Gilles Pokam 等MICRO 2022 · 被引用 23 次
- The Code That Never Ran: Modeling Attacks on Speculative EvaluationCraig Disselkoen, Radha Jagadeesan, Alan Jeffrey, James RielyS&P 2019 · 被引用 24 次
