发表机构
Georgia Institute of Technology(佐治亚理工学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
提出SURF类CPU木马,无需任意代码执行即可通过高级语言整数运算的微架构副作用激活,在RISC-V处理器和V8引擎中验证了代码注入攻击,并开源设计。
AI 中文摘要
针对CPU的硬件木马(HT)攻击通常假设一种威胁场景:攻击者针对带有木马化CPU的系统,能够执行任意代码(即机器级指令)以可靠地与植入的木马进行交互。在终端用户设备(如手机、笔记本电脑)上,实践中实现任意代码执行需要针对每个特定目标定制的软件漏洞利用。这种强大的对抗前提降低了现有威胁模型的通用性,使人们对CPU木马攻击作为实用威胁向量的可行性产生怀疑。为了推动针对客户端设备的HT攻击发展,我们引入了SURF类CPU木马,其激活无需任意代码执行。我们的关键洞察是,用高级语言表达的整数运算可以映射到微架构副作用,这些副作用可被SURF触发电路区分。这一观察使得通过运行时引擎(执行不受信任的高级代码的受限环境)激活木马成为可能。我们在RISC-V处理器中演示了一个SURF木马,并利用Google V8引擎中的JavaScript级内存索引操作执行代码注入攻击。重要的是,我们表明SURF木马在多个JavaScript引擎版本中仍然有效,从而能够长期危害终端设备。为促进研究,我们开源了SURF的设计和支持软件。
英文摘要
Hardware trojan (HT) attacks against CPUs typically assume threat scenarios where an attacker targeting a system with a trojanized CPU is able to execute arbitrary code (i.e. machine-level instructions) to reliably interact with the implanted trojan. On end-user devices (i.e., mobiles, laptops), achieving arbitrary code execution in practice requires software exploits tailored to each specific target. Such strong adversarial premises reduce the generality of existing threat models casting doubt on CPU trojan attacks as a pragmatic threat vector. To push the envelope on HT attacks against client devices, we introduce the SURF class of CPU-trojans that can be activated without arbitrary code execution. Our key insight is that integer operations expressed in a high-level language can be mapped to microarchitectural side-effects distinguishable by a SURF trigger circuit. This observation unlocks HT activation via runtime engines, constrained environments executing untrusted high-level code. We demonstrate a SURF trojan inside a RISC-V processor and exploit JavaScript-level memory indexing operations inside Google's V8 engine to perform a code injection attack. Importantly, we show that SURF trojans remain effective across multiple JavaScript engine versions, enabling long-term compromise of endpoint devices. To facilitate research, we opensource SURF's design and supporting software.