µVM A microarchitectural Intermediate Language for Speculative Execution Testing
Resumo
Spectre Branch Target Injection (BTI) is a microarchitectural attack that exploits branch predictors to leak secrets across security domains. While implementation remains tightly coupled to the OS and processor, these vulnerabilities affect x86, ARM, and RISC-V architectures, despite a research bias toward x86 Linux. To cover the largest number of testing scenarios for this type of vulnerability, we present µVM, a microarchitectural intermediate language for speculative execution testing, which we use to test Linux, Windows, x86, and ARM. The framework was also capable of finding 2 bugs in the Linux kernel and undocumented behaviours in Intel CPUs.
Referências
ARM. Arm cpu security bulletin: Spectre/meltdown. [link].
ARM. Spectre-bhb: Speculative target reuse attacks. [link].
Barberis, E., Frigo, P., Muench, M., Bos, H., and Giuffrida, C. (2022). Branch History Injection: On the Effectiveness of Hardware Mitigations Against Cross-Privilege Spectre-v2 Attacks. In USENIX Security. Intel Bounty Reward.
Bitdefender. Security implications of speculatively executing segmentation related instructions on intel cpus. [link].
Canella, C., Genkin, D., Giner, L., Gruss, D., Lipp, M., Minkin, M., Moghimi, D., Piessens, F., Schwarz, M., Sunar, B., Van Bulck, J., and Yarom, Y. (2019). Fallout: Leaking data on meltdown-resistant cpus. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS). ACM.
Evtyushkin, D., Ponomarev, D., and Abu-Ghazaleh, N. (2016). Jump over aslr: Attacking branch predictors to bypass aslr. In 2016 49th Annual IEEE/ACM International Symposium on Microarchitecture (MICRO), pages 1–13.
Horn, J. Reading privileged memory with a side-channel. [link]. Accessado em: 03/01/2022.
Intel. Intel software security guidance. [link].
Kemerlis, V. P., Portokalidis, G., and Keromytis, A. D. (2012). kGuard: Lightweight kernel protection against Return-to-User attacks. In 21st USENIX Security Symposium (USENIX Security 12), pages 459–474, Bellevue, WA. USENIX Association.
Kocher, P., Horn, J., Fogh, A., , Genkin, D., Gruss, D., Haas, W., Hamburg, M., Lipp, M., Mangard, S., Prescher, T., Schwarz, M., and Yarom, Y. (2019). Spectre attacks: Exploiting speculative execution. In 40th IEEE Symposium on Security and Privacy (S&P’19).
Koruyeh, E. M., Shirani, P., Khalid, A., and Abu-Ghazaleh, N. (2018). Spectre returns! Speculative execution using the return stack buffer. In 12th USENIX Workshop on Offensive Technologies (WOOT 18), Baltimore, MD. USENIX Association.
Linux. The linux kernel documentation: Spectre side channels. [link].
Lipp, M., Schwarz, M., Gruss, D., Prescher, T., Haas, W., Fogh, A., Horn, J., Mangard, S., Kocher, P., Genkin, D., Yarom, Y., and Hamburg, M. (2018). Meltdown: Reading kernel memory from user space. In 27th USENIX Security Symposium (USENIX Security 18).
Luyi Li, H. Y. and Tullsen, D. (2024). Indirector: High-precision branch target injection attacks exploiting the indirect branch predictor. In 33rd USENIX Security Symposium (USENIX Security 24).
Mambretti, A., Sandulescu, A., Neugschwandtner, M., Sorniotti, A., and Kurmus, A. (2019). Two methods for exploiting speculative control flow hijacks. In 13th USENIX Workshop on Offensive Technologies (WOOT 19), Santa Clara, CA. USENIX Association.
Microsoft. Mitigating speculative execution side channel hardware vulnerabilities. [link].
Oliveira, J. and Branco, R. (2023). Ret2aslr - leaking aslr from return instructions. [link].
Ragab, H., Milburn, A., Razavi, K., Bos, H., and Giuffrida, C. (2021). Crosstalk: Speculative data leaks across cores are real. In 2021 IEEE Symposium on Security and Privacy (SP), pages 1852–1867.
Schwarz, M., Schwarzl, M., Lipp, M., Masters, J., and Gruss, D. (2019). Netspectre: Read arbitrary memory over the network. In European Symposium on Research in Computer Security (ESORICS), pages 98–115. Springer.
Van Bulck, J., Moghimi, D., Schwarz, M., Lippi, M., Minkin, M., Genkin, D., Yarom, Y., Sunar, B., Gruss, D., and Piessens, F. (2020). Lvi: Hijacking transient execution through microarchitectural load value injection. In 2020 IEEE Symposium on Security and Privacy (SP), pages 54–72.
van Schaik, S., Milburn, A., Österlund, S., Frigo, Pietro Ridl: Rogue in-flight data load. In 2019 IEEE Symposium on Security and Privacy (SP), pages 88–105.
Wikner, J. and Razavi, K. (2022). RETBLEED: Arbitrary speculative code execution with return instructions. In 31st USENIX Security Symposium (USENIX Security 22), pages 3825–3842, Boston, MA. USENIX Association.
Yarom, Y. and Falkner, K. (2014). FLUSH+RELOAD: A high resolution, low noise, l3 cache Side-Channel attack. In 23rd USENIX Security Symposium (USENIX Security 14), pages 719–732, San Diego, CA. USENIX Association.
