arrow
Return

Reinforcing Meltdown Attack by Using a Return Stack Buffer

delete2019-01-01
delete7
delete
OA
AI
T
Taehyun Kim
Y
Youngjoo Shin *
DOI:10.1109/ACCESS.2019.2961158delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Meltdown is a microarchitectural side-channel attack that extracts sensitive data in the kernel space of operating systems (OSs). Meltdown deliberately creates transient executions by exploiting an out-of-order execution technique and obtains the execution results through a cache covert channel. In a previous attack, an OS signal handler and hardware transactional memory support (i.e., Intel TSX) were used to establish the cache covert channel. However, both methods restricted the effectiveness of the attack owing to the large amount of system noise caused by the context switching of signal handlers and the narrow range of TSX-enabled processors. Hence, we propose a new variant of the Meltdown attack using a return stack buffer (RSB). The RSB enables the establishment of a low-noise cache covert channel without relying on processor-specific hardware features, such as TSX. The wide usage of the RSB in commodity processors further improves the effectiveness of the proposed attack. We present the details of our implementation of the attack and evaluate the performance. Furthermore, we overview several existing countermeasures against the proposed attack.
Keywords:
Microarchitectural side-channel attacks
transient execution attacks
return stack buffer
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

IEEE Access cover
IEEE Access
IF:
3.6
Papers:
9.8W
Citations:
29.4W

Organization

K
kwangwoon university
Scholars:
3.1K
Papers: 3.3K
Citations: 3