Spectre Attacks: Exploiting Speculative Execution.

Modern processors use branch prediction and speculative execution to maximize performance. For example, if the destination of a branch depends on a memory value that is in the process of being read, CPUs will try to guess the destination and attempt to execute ahead. When the memory value finally ar...

Descripción completa

Detalles Bibliográficos
Publicado en:Communications of the ACM Vol. 63; no. 7; pp. 93 - 102
Autores principales: Kocher, Paul, Horn, Jann, Fogh, Anders, Genkin, Daniel, Gruss, Daniel, Haas, Werner, Hamburg, Mike, Lipp, Moritz, Mangard, Stefan, Prescher, Thomas, Schwarz, Michael, Yarom, Yuval
Formato: Artículo
Publicado: Association for Computing Machinery Jul2020
Materias:
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=144780582&site=ehost-live
header:
  @attributes:
    shortDbName: hlh
    uiTerm: 144780582
    longDbName: Humanities International Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    jinfo:
      jid:
        00010782
        ACM
      jtl: Communications of the ACM
      issn: 00010782
      maglogo: N
    pubinfo:
      dt: Jul2020
      vid: 63
      iid: 7
      pid: 68
      pub: Association for Computing Machinery
    artinfo:
      ui:
        144780582
        10.1145/3399742
      ppf: 93
      ppct: 9
      formats:
      tig:
        atl: Spectre Attacks: Exploiting Speculative Execution.
      aug:
        au:
          Kocher, Paul
          Horn, Jann
          Fogh, Anders
          Genkin, Daniel
          Gruss, Daniel
          Haas, Werner
          Hamburg, Mike
          Lipp, Moritz
          Mangard, Stefan
          Prescher, Thomas
          Schwarz, Michael
          Yarom, Yuval
        affil:
          Google Project Zero
          G DATA Advanced Analytics
          University of Michigan
          Graz University of Technology
          Cyberus Technology
          Rambus, Cryptography Research Division
          University of Adelaide and Data61
      su:
        Computer hacking
        Central processing units
        Instruction set architecture
        Just-in-time systems
        Microprocessors
      sug:
        subj:
          Computer hacking
          Central processing units
          Instruction set architecture
          Just-in-time systems
          Microprocessors
      ab: Modern processors use branch prediction and speculative execution to maximize performance. For example, if the destination of a branch depends on a memory value that is in the process of being read, CPUs will try to guess the destination and attempt to execute ahead. When the memory value finally arrives, the CPU either discards or commits the speculative computation. Speculative logic is unfaithful in how it executes, can access the victim's memory and registers, and can perform operations with measurable side effects. Spectre attacks involve inducing a victim to speculatively perform operations that would not occur during correct program execution and which leak the victim's confidential information via a side channel to the adversary. This paper describes practical attacks that combine methodology from side-channel attacks, fault attacks, and return-oriented programming that can read arbitrary memory from the victim's process. More broadly, the paper shows that speculative execution implementations violate the security assumptions underpinning numerous software security mechanisms, such as operating system process separation, containerization, just-in-time (JIT) compilation, and countermeasures to cache timing and side-channel attacks. These attacks represent a serious threat to actual systems because vulnerable speculative execution capabilities are found in microprocessors from Intel, AMD, and ARM that are used in billions of devices. Although makeshift processor-specific countermeasures are possible in some cases, sound solutions will require fixes to processor designs as well as updates to instruction set architectures (ISAs) to give hardware architects and software developers a common understanding as to what computation state CPU implementations are (and are not) permitted to leak.
      pubtype: Periodical
      doctype: Article
      src: R
    language: English
    refInfo:
    copyright:
      @attributes:
        flag: Y
      dt:
        @attributes:
          year: 2020
    holdings:
      @attributes:
        islocal: N