AI 中文总结
针对边信道攻击致使CPU泄漏敏感信息的问题,提出一种方法,以最少人工干预为主要CPU架构提取指令中心泄漏契约,并在malcos工具中实现,经评估其合成的契约精确合理,证明从黑盒CPU学习泄漏契约可行。
AI 中文摘要
边信道攻击对现代计算平台构成重大安全威胁,因其利用CPU行为的细微差异来泄露敏感信息。为了对CPU通过微架构边信道泄漏的信息进行建模,近期工作提出了泄漏契约,这是一种ISA级安全抽象,为安全的CPU编程奠定基础。然而,由于当前微架构的复杂性,为CPU设计泄漏契约需要大量人工,导致现代CPU缺乏专用泄漏契约。我们提出一种方法,以最少的人工干预为主要CPU架构提取以指令为中心的泄漏契约。我们在malcos中实现了此技术,它是首个为黑盒CPU自动合成泄漏契约的无模板工具。我们在x86和ARM CPU上评估了malcos,结果表明它合成的契约对于合成期间观察到的所有泄漏都是精确且合理的。我们的结果证明从黑盒CPU学习泄漏契约是可行的。
英文摘要
Side-channel attacks pose a significant security threat for modern computing platforms, because they exploit subtle discrepancies in CPU behaviors to leak sensitive information. To model the information leaked by a CPU via microarchitectural side-channels, recent work proposed leakage contracts: an ISA-level security abstraction that provides the foundations for secure CPU programming. Unfortunately, due to the complexity of current microarchitectures, devising a leakage contract for a CPU requires extensive manual effort and thus modern CPUs lack dedicated leakage contracts. We present a methodology to extract instruction-centric leakage contracts for major CPU architectures with minimal manual intervention. We implemented this technique in malcos, the first template-free tool that automates the synthesis of leakage contracts for black-box CPUs. We evaluate malcos on x86 and ARM CPUs, and show that the contracts it synthesizes are precise and sound with respect to all leaks observed during synthesis. Our results demonstrate that learning leakage contracts from black-box CPUs is feasible.
Comments16 pages (12 pages main body, 4 pages bibliography and appendix), 4 figures, 6 tables