arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

远程定时器即服务:利用远程定时器实现的云环境中高效微架构泄露

Remote-Timer-as-a-Service: Efficient Microarchitectural Leakage in the Cloud with Remote Timers

Martin Schwarzl, Haocheng Xiao, Albert Pedersen, Sam Ainsworth, Nigel Topham

arXiv 2608.17043首次发表:更新:

AI 中文总结

该研究发现 Cloudflare Workers 的 DyPrIs 对策存在不足,利用微架构放大和远程定时器实现高效远程 Spectre 攻击泄露 JWT,后推动 Cloudflare Workers 通过多措施完成漏洞修复。

AI 中文摘要

边缘计算方案已成为行业的关键组成部分,为终端用户提供快速、灵活且可扩展的应用,典型用例包括动态内容创建、图像调整和聊天机器人。Cloudflare Workers 是此类框架之一,每秒处理全球数百万个 HTTP 请求。为减少启动延迟,Cloudflare Workers 移除了多个租户间的进程隔离边界,转而采用语言级隔离,该架构存在 Spectre 攻击风险。为缓解此类风险,Cloudflare Workers 此前引入了多项对策,包括受限定时器测量、无共享内存、无多线程以及动态进程隔离(DyPrIs),用于检测潜在攻击并对可疑恶意脚本进行进程隔离。我们证明了 DyPrIs 的生产级实现存在不足,通过采用微架构放大技术,我们发现了在 Cloudflare Workers 生产环境中测量时间的多种可能方式。基于这些技术,我们表明 Cloudflare Workers 安全模型中对定时器的冻结和粗化处理并不充分,结合定时放大与远程定时器,我们展示了一种远程 Spectre 攻击,可从 Cloudflare Workers 生产环境中共位的受害者 worker 中泄露 JWT 令牌。我们的攻击效率远超现有攻击,速率从每分钟 2 比特提升至每秒最高 12 比特,准确率达 99.16%,对客户数据构成直接风险。在我们的端到端攻击后,Cloudflare Workers 通过整合 V8 Sandbox(限制瞬态访问 64 位指针)、提升 DyPrIs 的检测能力,以及部署基于硬件的 MPK 进程内隔离(将每个租户堆限制在专用内存保护密钥下),协同完成了漏洞修复。

英文摘要

Edge computing solutions have become a crucial part of the industry, delivering fast, flexible and scalable applications close to the end users, with typical use cases including dynamic content creation, image resizing and chatbots. Cloudflare Workers is one such framework, which handles millions of HTTP requests per second worldwide. To reduce start-up latency, Cloudflare Workers removes process-isolation boundaries between multiple tenants and leverages language-level isolation. This architecture poses the risk of Spectre attacks. To mitigate these, Cloudflare Workers previously introduced several countermeasures such as restricted timer measurements, no shared memory, no multithreading and Dynamic Process Isolation (DyPrIs), detecting potential attacks and process-isolating potentially malicious scripts. We demonstrate that the production implementation of DyPrIs was insufficient. We adopt microarchitectural amplification techniques and discover various possibilities to measure time in the production environment of Cloudflare Workers. Given these techniques, we show that freezing and coarsening timers in the Cloudflare Workers security model is insufficient. Leveraging both timing amplification and remote timers, we demonstrate a remote Spectre attack that leaks a JWT token from a co-located victim worker in the Cloudflare Workers production environment. We outperform the existing attack by orders of magnitude, going from 2 bit/min to up to 12 bit/s at an accuracy of 99.16%, posing an immediate risk to customer data. Following our end-to-end attack, Cloudflare Workers mitigated it in a coordinated effort by integrating the V8 Sandbox limiting transient access to 64-bit pointers, improving the detection capabilities of DyPrIs, and deploying hardware-assisted MPK-based in-process isolation to confine each tenant heap under a dedicated memory-protection key.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑