Speculative Taint Tracking (STT): A Comprehensive Protection for Speculatively Accessed Data.
Speculative execution attacks present an enormous security threat, capable of reading arbitrary program data under malicious speculation, and later exfiltrating that data over microarchitectural covert channels. This paper proposes speculative taint tracking (STT), a high security and high performan...
| Publicado en: | Communications of the ACM Vol. 64; no. 12; pp. 105 - 113 |
|---|---|
| Autores principales: | , , , , , |
| Formato: | Artículo |
| Publicado: |
Association for Computing Machinery
Dec2021
|
| Materias: | |
| Acceso en línea: | Ver este registro en EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=153715924&site=ehost-live header: @attributes: shortDbName: hlh uiTerm: 153715924 longDbName: Humanities International Complete uiTag: AN controlInfo: bkinfo: jinfo: jid: 00010782 ACM jtl: Communications of the ACM issn: 00010782 maglogo: N pubinfo: dt: Dec2021 vid: 64 iid: 12 pid: 68 pub: Association for Computing Machinery artinfo: ui: 153715924 10.1145/3491201 ppf: 105 ppct: 8 formats: tig: atl: Speculative Taint Tracking (STT): A Comprehensive Protection for Speculatively Accessed Data. aug: au: Jiyong Yu Mengjia Yan Khyzha, Artem Morrison, Adam Torrellas, Josep Fletcher, Christopher W. affil: University of Illinois at Urbana-Champaign, IL, USA. Massachusetts Institute of Technology, Cambridge, MA, USA. Aviv University, Israel. su: Computer security Data protection Malware prevention Computer architecture Computer performance sug: subj: Computer security Data protection Malware prevention Computer architecture Computer performance ab: Speculative execution attacks present an enormous security threat, capable of reading arbitrary program data under malicious speculation, and later exfiltrating that data over microarchitectural covert channels. This paper proposes speculative taint tracking (STT), a high security and high performance hardware mechanism to block these attacks. The main idea is that it is safe to execute and selectively forward the results of speculative instructions that read secrets, as long as we can prove that the forwarded results do not reach potential covert channels. The technical core of the paper is a new abstraction to help identify all microarchitectural covert channels, and an architecture to quickly identify when a covert channel is no longer a threat. We further conduct a detailed formal analysis on the scheme in a companion document. When evaluated on SPEC06 workloads, STT incurs 8.5% or 14.5% performance overhead relative to an insecure machine. pubtype: Periodical doctype: Article src: R language: English refInfo: copyright: @attributes: flag: Y dt: @attributes: year: 2021 holdings: @attributes: islocal: N |
|---|