arXiv Open Access 2024

Lost and Found in Speculation: Hybrid Speculative Vulnerability Detection

Mohamadreza Rostami Shaza Zeitouni Rahul Kande Chen Chen Pouya Mahmoody +3 lainnya
Lihat Sumber

Abstrak

Microarchitectural attacks represent a challenging and persistent threat to modern processors, exploiting inherent design vulnerabilities in processors to leak sensitive information or compromise systems. Of particular concern is the susceptibility of Speculative Execution, a fundamental part of performance enhancement, to such attacks. We introduce Specure, a novel pre-silicon verification method composing hardware fuzzing with Information Flow Tracking (IFT) to address speculative execution leakages. Integrating IFT enables two significant and non-trivial enhancements over the existing fuzzing approaches: i) automatic detection of microarchitectural information leakages vulnerabilities without golden model and ii) a novel Leakage Path coverage metric for efficient vulnerability detection. Specure identifies previously overlooked speculative execution vulnerabilities on the RISC-V BOOM processor and explores the vulnerability search space 6.45x faster than existing fuzzing techniques. Moreover, Specure detected known vulnerabilities 20x faster.

Topik & Kata Kunci

Penulis (8)

M

Mohamadreza Rostami

S

Shaza Zeitouni

R

Rahul Kande

C

Chen Chen

P

Pouya Mahmoody

Jeyavijayan

Rajendran

A

Ahmad-Reza Sadeghi

Format Sitasi

Rostami, M., Zeitouni, S., Kande, R., Chen, C., Mahmoody, P., Jeyavijayan et al. (2024). Lost and Found in Speculation: Hybrid Speculative Vulnerability Detection. https://arxiv.org/abs/2410.22555

Akses Cepat

Lihat di Sumber
Informasi Jurnal
Tahun Terbit
2024
Bahasa
en
Sumber Database
arXiv
Akses
Open Access ✓