北京邮电大学可信分布式计算与服务教育部重点实验室,北京,100876
网络首发:2021-07-10,
纸质出版:2021
移动端阅览
王春露, 田瑞冬, 赵旭, 等. ARM处理器分支预测漏洞分析测评及新漏洞发现[J]. 西安交通大学学报, 2021,55(7):71-78.
Evaluation of Branch Prediction Vulnerability and New Vulnerability Discovery on ARM Processors[J]. 2021, 55(7): 71-78.
王春露, 田瑞冬, 赵旭, 等. ARM处理器分支预测漏洞分析测评及新漏洞发现[J]. 西安交通大学学报, 2021,55(7):71-78. DOI: 10.7652/xjtuxb202107008.
Evaluation of Branch Prediction Vulnerability and New Vulnerability Discovery on ARM Processors[J]. 2021, 55(7): 71-78. DOI: 10.7652/xjtuxb202107008.
针对ARM处理器上的分支预测漏洞研究不全面、不深入等问题
提出了一种分支预测漏洞测评方法。通过对分支预测漏洞的攻击过程进行研究
提炼了分支预测漏洞的6步骤攻击模型。根据分支预测漏洞攻击利用的微体系结构和针对的地址空间
将现有的分支预测漏洞分成9种类型。基于攻击模型和分类方法构建了ARM处理器上的分支预测漏洞测评方法。在主流的3种ARMv8架构处理器上对9种分支预测漏洞进行了测评
测评内容包括是否受漏洞影响、防御方法是否有效和新漏洞的发掘。实验结果表明
部分ARM处理器完全不受分支预测漏洞攻击影响
部分处理器只受5到6种分支预测漏洞影响。在防御方法方面
尚未存在一种防御方法能防御所有的分支预测漏洞
但可以通过不同防御方法的组合来构建完善的防御体系。在测评过程中
发现了一种ARM架构独有的预测执行漏洞——顺序预测漏洞
此漏洞能够泄露同一进程空间的任意数据。
Because of the lack of research about branch prediction vulnerability on ARM processor
a branch prediction vulnerability evaluation method is proposed to evaluate ARM processor security. Studying the attack process of branch prediction vulnerability
a six-step attack model of branch prediction vulnerability is extracted. According to the difference of microarchitecture and address space used by branch prediction vulnerabilities
the existing branch prediction vulnerabilities are divided into nine types. Based on the attack model and classification method
a branch prediction vulnerability evaluation method is designed. Nine kinds of branch prediction vulnerabilities are evaluated on three mainstream ARMv8 architecture processors. The evaluation content includes the influence of vulnerabilities
the effectiveness of defense methods
and the discovery of new vulnerabilities. The results show that some ARM processors are not affected by branch prediction vulnerabilities at all
while the others are only affected by 5 or 6 branch prediction vulnerabilities. In terms of defense methods
there is not a single defense method that can prevent all branch prediction vulnerabilities
but a perfect defense system can be constructed via combination of different defense methods. During the evaluation process
a prediction execution vulnerability unique on ARM architecture
the sequential prediction vulnerability
is also found
which can expose arbitrary data in the same process space.
张晨曦. 计算机体系结构 [M]. 2版. 北京: 高等教育出版社, 2005: 152-157.
KOCHER P, HORN J, FOGH A, et al. Spectre attacks: exploiting speculative execution [C]∥Proceedings of the 2019 IEEE Symposium on Security and Privacy(SP). Piscataway, NJ, USA: IEEE, 2019: 1-19.
KORUYEH E M, KHASAWNEH K N, SONG C Y, et al. Spectre returns!: speculation attacks using the return stack buffer [C/OL]∥Proceedings of the 12th USENIX Workshop on Offensive Technologies. [S.l.]: USENIX, 2018.[2021-01-01].http: ∥www. cs.ucr.edu/~nael/pubs/woot18.pdf.
MAISURADZE G, ROSSOW C. Ret2spec: speculative execution using return stack buffers [C]∥Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security. New York, USA: ACM, 2018: 2109-2122.
吴晓慧, 贺也平, 马恒太, 等. 微架构瞬态执行攻击与防御方法 [J]. 软件学报, 2020, 31(2): 544-563.
WU Xiaohui, HE Yeping, MA Hengtai, et al. Microarchitectural transient execution attacks and defense methods [J]. Journal of Software, 2020, 31(2): 544-563.
EVTYUSHKIN D, RILEY R, ABU-GHAZALEH N C A E, et al. BranchScope [J]. ACM SIGPLAN Notices, 2018, 53(2): 693-707.
SCHWARZ M, SCHWARZL M, LIPP M, et al. NetSpectre: read arbitrary memory over network [C]∥Proceedings of the 24th European Symposium on Research in Computer Security. Cham, Germany: Springer, 2019: 279-299.
HUO Tianlin, MENG Xiaoni, WANG Wenhao, et al. Bluethunder: a 2-level directional predictor based side-channel attack against SGX [J]. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2020(1): 321-347.
CHEN Guoxing, CHEN Sanchuan, XIAO Yuan, et al. SgxPECTRE: stealing intel secrets from SGX enclaves via speculative execution [C]∥Proceedings of the 2019 IEEE European Symposium on Security and Privacy(EuroSP). Piscataway, NJ, USA: IEEE, 2019: 142-157.
EVERS M, CHANG P Y, PATT Y N. Using hybrid branch predictors to improve branch prediction accuracy in the presence of context switches [J]. ACM SIGARCH Computer Architecture News, 1996, 24(2): 3-11.
YEH T Y, PATT Y N. Two-level adaptive training branch prediction [C]∥Proceedings of the 24th Annual International Symposium on Microarchitecture. New York, USA: ACM, 1991: 51-61.
ACIIÇMEZ O, KOÇ Ç K, SEIFERT J P. On the power of simple branch prediction analysis [C]∥Proceedings of the 2nd ACM Symposium on Information, Computer and Communications Security. New York, USA: ACM, 2007: 312-320.
唐朔飞. 计算机组成原理 [M]. 2版. 北京: 高等教育出版社, 2008: 109-117.
OSVIK D A, SHAMIR A, TROMER E. Cache attacks and countermeasures: the case of AES [C]∥Proceedings of the 2006 Cryptographers Track at the RSA Conference. Cham, Germany: Springer, 2006: 1-20.
KOCHER P C. Timing attacks on implementations of Diffie-Hellman, RSA, DSS, and other systems [C]∥Proceedings of the 16th Annual International Cryptology Conference on Advances in Cryptology. Cham, Germany: Springer, 1996: 104-113.
YAROM Y, FALKNER K. FLUSH+RELOAD: a high resolution, low noise, L3 cache side-channel attack [C]∥Proceedings of the 23rd USENIX Security Symposium. [S.l.]: USENIX, 2014: 719-732.
GRUSS D, SPREITZER R, MANGARD S. Cache template attacks: automating attacks on inclusive last-level caches [C]∥Proceedings of the 2015 USENIX Security Symposium. [S.l.]: USENIX, 2015: 897-912.
LIU Fangfei, YAROM Y, GE Qian, et al. Last-level cache side-channel attacks are practical [C]∥Proceedings of the 2015 IEEE Symposium on Security and Privacy. Piscataway, NJ, USA: IEEE, 2015: 605-622.
CANELLA C, BULCK J V, SCHWARZ M, et al. A systematic evaluation of transient execution attacks and defenses [C]∥Proceedings of the 28th USENIX Security Symposium. [S.l.]: USENIX, 2018: 249-266.
GRISENTHWAITE R. Cache speculation side-channels [EB/OL]. [2020-10-01]. https: ∥developer.arm.com/-/media/Files/pdf/Cache_Speculation_Si de-channels.pdf.
GRUSS D, LIPP M, SCHWARZ M, et al. KASLR is dead: long live KASLR [C]∥Proceedings of the 9th International Symposium on Engineering Secure Software and Systems. Cham, Germany: Springer, 2017: 161-176.
高榕,张良,梅魁志.基于Caffe的嵌入式多核处理器深度学习框架并行实现.2018,52(6):36-41+113.[doi:10.7652/xjtuxb201806007]
李杨,王劲林,叶晓舟,曾学文.面向嵌入式处理器的优化Montgomery模乘算法.2017,51(2):47-52+127.[doi:10.7652/xjtuxb201702008]
王强,董小社,王恩东,朱正东.基于I/O受限进程识别的虚拟处理器调度机制.2015,49(4):53-60.[doi:10.7652/xjtuxb201504009]
崔继岳,梅魁志,刘冬冬,李博良.面向OpenCL的Mali GPU仿真器构建研究.2015,49(2):20-24+68.[doi:10.7652/xjtuxb201502004]
丑文龙,梅魁志,高增辉,李博良.ARM GPU的多任务调度设计与实现.2014,48(12):87-92.[doi:10.7652/xjtuxb2014 12014]
0
浏览量
4
下载量
0
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621