arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

ANTMAN:针对BOOM的隐蔽分支预测器攻击的高效且可解释的RTL级运行时检测框架

ANTMAN: An Efficient and Interpretable RTL-Level Run-Time Detection Framework for Stealthy Branch Predictor Attacks on BOOM

Muhammad Hassan, Maria Mushtaq, Jaan Raik, Tara Ghasempouri

arXiv 2608.09498首次发表:更新:

AI 中文总结

针对BOOM RISC-V,提出首个设计安全、可解释的RTL级运行时检测框架ANTMAN,利用离线关联规则,在两类预测器配置下实现零误报、快速检测分支预测器攻击。

AI 中文摘要

与x86和ARM指令集架构(ISA)相比,RISCV中微架构侧信道攻击的运行时检测仍未得到充分探索,对关键应用构成严重威胁。最先进的分支预测器攻击通过直接利用内部历史表的状态绕过传统的数据和指令缓存,本质上具有隐蔽性。近期研究已探索了针对RISC-V微架构攻击的离线检测,但针对RISC-V硬件的高效微架构攻击运行时检测仍未得到解决。最先进的基于硬件的运行时检测方案利用硬件性能计数器(HPC),但存在计数器寄存器数量有限、检测准确率、检测速度和采样粒度之间存在权衡等问题,使其难以应对隐蔽攻击。此外,在不同时间间隔后采样HPC会导致无法观察到不同微架构模块之间的中间关系。另外,专有的x86和ARM ISA限制了研究人员修改处理器微架构设计。为解决这些限制,我们提出了首个针对BOOM RISC-V的隐蔽分支预测器攻击的设计安全、高度可解释、非侵入式的RTL级运行时检测方案,在简化的下一行预测器(NLP)和复杂的TAGE预测器配置下进行了评估。攻击检测依赖于离线提取的关联规则,并作为非侵入式规则监视器嵌入硬件,以实现运行时检测。所提方法实现了出色的检测速度,在秘密泄露前终止执行,零误报,同时保持了检测同一分支预测器攻击家族内先前未见过的变体的灵活性。

英文摘要

Runtime detection of microarchitectural side channel attacks remains significantly underexplored in RISCV compared with x86 and ARM ISAs, posing a serious threat to critical applications. State-of-the-art branch predictor attacks bypass traditional data and instruction caches by directly exploiting the state of internal history tables, making them inherently stealthy. Recent research has explored offline detection of microarchitectural attacks on RISC-V; however, efficient runtime detection of microarchitectural attacks on RISC-V hardware remains significantly unaddressed. State-of-the-art hardware-based runtime detection solutions leverage hardware performance counters (HPCs) but suffer from a restricted set of counter registers and tradeoffs between detection accuracy, detection speed, and sampling granularity, making them impractical for stealthy attacks. Moreover, sampling HPCs after distinct intervals leaves intermediate relationships between different microarchitectural blocks unobserved. Additionally, proprietary x86 and ARM ISAs constrain researchers from modifying processor microarchitectural designs. To address these limitations, we propose the first secure-by-design, highly interpretable, non-intrusive, RTL-level runtime detection solution for stealthy branch predictor attacks on BOOM RISC-V, evaluated under both simplified Next-Line Predictor (NLP) and complex TAGE predictor configurations. The attack detection relies on association rules extracted offline and embedded in hardware as a non-intrusive rule monitor that enables runtime detection. The proposed approach achieves excellent detection speed, terminates execution before secret disclosure, and produces zero false positives while remaining flexible for detecting previously unseen variants within the same family of branch predictor attacks.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑