Key Laboratory of Aerospace Information Security and Trusted Computing,Ministry of Education,School of Cyber Science and Engineering,Wuhan University,Wuhan 430072,Hubei,China
Spectre attack and its variants have been released continuously, leaving traces in the cache and then leaking sensitive information through the cache side-channel attacks. However, existing detection methods for Spectre attacks are insufficient for analyzing of the attack code patterns and existing defenses, resulting in false positives and negatives. This paper proposed an improved cache-aware dynamic analysis method to address this issue to identify various Spectre attacks. This paper analyzed and modeled variants of Spectre attacks based on the attack principle and code pattern characteristics, and improved the formal cache model based on the least recently used replacement policy, finally implemented a cache-aware dynamic analysis and detection tool for Spectre vulnerability based on the modeling of Spectre attacks and cache. Through experiments conducted on a set of microbenchmarks and commonly used cryptographic libraries, Spectre gadgets were accurately detected in all microbenchmark samples. Additionally, cache side-channel and Spectre vulnerabilities were identified in several cryptographic algorithms. In the end, the experimental results showed that the method proposed in this paper has a good detection capability.
在推测执行中,分支预测单元(Branch Predic-tion Unit, BPU)存储过去的分支方向和分支跳转目标并利用程序控制流中的局部性对未来的分支进行预测。BPU通过使用模式历史表(Pattern History Table, PHT)来预测是否采取该分支。假设攻击者可以控制输入值并预先通过重复训练以毒化PHT。在受害者执行过程中,分支语句可能难以立刻获得执行结果,此时被攻击者毒化的预测器将指向错误的分支预测方向,使攻击者控制的不合法输入值绕过边界检查并执行瞬态指令,实现跨内存隔离边界的数据的瞬态读取,随后基于侧信道攻击获取指令读取的敏感数据。
OSVIKD A, SHAMIRA, TROMERE. Cache attacks and countermeasures: The Case of AES[M]//Topics in Cryptology — CT-RSA 2006. Berlin: Springer, 2006: 1-20. DOI: 10.1007/11605805_1 .
[2]
PERCIVALC. Cache missing for fun and profit[DB/OL]. [2023-10-12].
[3]
WUZ Y, XUZ, WANGH N. Whispers in the hyper-space: High-speed covert channel attacks in the cloud[DB/OL]. [2023-10-12].DOI: 10.1109/tnet.2014.2304439 .
[4]
BRASSERF, MÜLLERU, DMITRIENKOA, et al. Software grand exposure: SGX cache attacks are practical[DB/OL]. [2023-10-12].
YANGF, ZHANGQ Y, SHIZ P, et al. Survey on software side-channel attacks in trusted execution environment[J]. Journal of Software, 2023, 34(1): 381-403. DOI: 10.13328/j.cnki.jos.006501 (Ch ).
[7]
XIAOY, LIM Y, CHENS C, et al. STACCO: Differentially analyzing side-channel traces for detecting SSL/TLS vulnerabilities in secure enclaves[EB/OL].[2023-10-11].DOI: 10.1145/3133956.3134016 .
[8]
WANGS, WANGP, LIUX, et al. CacheD: Identifying cache-based timing channels in production software[EB/OL].[2023-10-11].
[9]
WICHELMANNJ, MOGHIMIA, EISENBARTHT, et al. MicroWalk: A framework for finding side channels in binaries[EB/OL].[2023-10-11]. DOI: 10.1145/3274694.3274741 .
[10]
NILIZADEHS, NOLLERY, PASAREANUC S. DifFuzz: differential fuzzing for side-channel analysis[C]//2019 IEEE/ACM 41st International Conference on Software Engineering (ICSE). New York: IEEE Press, 2019: 176-187. DOI: 10.1109/ICSE.2019.00034 .
[11]
WANGW B, ZHANGY Q, LINZ Q. Time and order: Towards automatically identifying side-channel vulnerabilities in enclave binaries[EB/OL].[2023-10-11].
[12]
BROTZMANR, LIUS, ZHANGD F, et al. CaSym: cache aware symbolic execution for side channel detection and mitigation[C]//2019 IEEE Symposium on Security and Privacy (SP). New York: IEEE Press, 2019: 505-521. DOI: 10.1109/SP.2019.00022 .
[13]
KOCHERP, HORNJ, FOGHA, et al. Spectre attacks: Exploiting speculative execution[C]//2019 IEEE Symposium on Security and Privacy (SP). New York: IEEE Press, 2019: 1-19. DOI: 10.1109/SP.2019.00002 .
HORNJ. Speculative execution, variant 4 : Speculative store bypass, 2018[EB/OL].[2023-10-11].
[16]
BHATTACHARYYAA, SANDULESCUA, NEUGSCHWANDTNERM, et al. SMoTherSpectre: Exploiting speculative execution through port contention[EB/OL].[2023-10-11].DOI: 10.1145/3319535.3363194 .
[17]
KORUYEHE M, KHASAWNEHK N, SONGC Y, et al. Spectre returns! speculation attacks using the return stack buffer[C]//IEEE Design & Test. New York: IEEE Press, 2024: 47-55. DOI: 10.1109/MDAT.2024.3352537 .
[18]
WANGG H, CHATTOPADHYAYS, GOTOVCHITSI, et al. oo7: Low-overhead defense against spectre attacks via program analysis[J]. IEEE Transactions on Software Engineering, 2021, 47(11): 2504-2519. DOI: 10.1109/TSE.2019.2953709 .
[19]
GUARNIERIM, KÖPFB, MORALESJ F, et al. Spectector: Principled detection of speculative information flows[C]//2020 IEEE Symposium on Security and Privacy (SP). New York: IEEE Press, 2020: 1-19. DOI: 10.1109/SP40000.2020.00011 .
[20]
OLEKSENKOO, TRACHB, SILBERSTEINM, et al. SpecFuzz: Bringing spectre-type vulnerabilities to the surface[EB/OL].[2023-10-11].
[21]
QIZ X, FENGQ, CHENGY Q, et al. SpecTaint: Speculative taint analysis for discovering spectre gadgets[EB/OL]. [2023-10-11]. DOI: 10.14722/ndss.2021.24466 .
LIUC, YANGY, LIH R, et al. A survey of branch prediction attacks on modern processors[J]. Chinese Journal of Computers, 2022, 45(12): 2475-2509. DOI: 10.11897/SP.J.1016.2022.02475(Ch ).
[24]
RAGABH, BARBERISE, BOS H, et al. Rage against the machine clear: A systematic analysis of machine clears and their implications for transient execution attacks[EB/OL].[2023-10-11].
WUX H, HEY P, MAH T, et al. Microarchitectural transient execution attacks and defense methods[J]. Journal of Software, 2020, 31(2): 544-563. DOI: 10.13328/j.cnki.jos.005979 (Ch ).
[27]
RENX D, MOODYL, TARAMM, et al. I see dead µops: Leaking secrets via Intel/AMD micro-op caches[C]//2021 ACM/IEEE 48th Annual International Symposium on Computer Architecture (ISCA). New York: IEEE Press, 2021: 361-374. DOI: 10.1109/ISCA52012.2021.00036 .
[28]
OLEKSENKOO, TRACHB, REIHERT, et al. You shall not bypass: Employing data dependencies to prevent bounds check bypass[EB/OL]. 2018: arXiv: 1805.08506.
[29]
WEISERS, ZANKLA, SPREITZERR, et al. DATA—differential address trace analysis: Finding address-based side-channels in binaries[EB/OL].[2023-10-11].
[30]
MAMBRETTIA, NEUGSCHWANDTNERM, SORNIOTTIA, et al. Speculator: A tool to analyze speculative execution attacks and mitigations[EB/OL].[2023-10-11]. DOI: 10.1145/3359789.3359837 .
[31]
KOCHERP. Spectre mitigations in microsoft’s C/C++ compiler[EB/OL].[2023-10-11].