Microarchitectural Attacks and Heterogenous Cloud Computing By - - PowerPoint PPT Presentation

▶
microarchitectural attacks and
SMART_READER_LITE
LIVE PREVIEW

Microarchitectural Attacks and Heterogenous Cloud Computing By - - PowerPoint PPT Presentation

Microarchitectural Attacks and Heterogenous Cloud Computing By Daniel Moghimi PhD Candidate Worcester Polytechnic Institute (WPI) @danielmgmi Outline Data Dependency SPOILER: Speculative Load Hazards Boost Rowhammer and Cache Attacks


slide-1
SLIDE 1

Microarchitectural Attacks and Heterogenous Cloud Computing

By Daniel Moghimi PhD Candidate Worcester Polytechnic Institute (WPI) @danielmgmi

slide-2
SLIDE 2

Outline

▪

Data Dependency

▪

SPOILER: Speculative Load Hazards Boost Rowhammer and Cache Attacks

▪

Intel SCAP: Protecting Accelerators in the Cloud

2

slide-3
SLIDE 3

Data Dependency

add %ebx, %eax sub %eax, %edx xor %ecx, %ecx add %eax, %edi sub %ecx, %edi

1 2 3 4 5

3

slide-4
SLIDE 4

Data Dependency - Pipelined Execuction

add %ebx, %eax sub %eax, %edx xor %ecx, %ecx add %eax, %edi sub %ecx, %edi

1 2 3 4 5 IF ID EX

WB

Instruction Fetch Instruction Decode Execute Write Back

IF IF ID

4

slide-5
SLIDE 5

add %ebx, %eax sub %eax, %edx xor %ecx, %ecx add %eax, %edi sub %ecx, %edi

1 2 3 4 5 IF ID EX

WB

Instruction Fetch Instruction Decode Execute Write Back

IF IF ID EX ID IF

5

Data Dependency - Pipelined Execuction

slide-6
SLIDE 6

add %ebx, %eax sub %eax, %edx xor %ecx, %ecx add %eax, %edi sub %ecx, %edi

1 2 3 4 5 IF ID EX

WB

Instruction Fetch Instruction Decode Execute Write Back

IF IF ID EX ID IF

WB

EX ID IF

Data Dependency - Pipelined Execuction

6

slide-7
SLIDE 7

add %ebx, %eax sub %eax, %edx xor %ecx, %ecx add %eax, %edi sub %ecx, %edi

1 2 3 4 5 IF ID EX

WB

Instruction Fetch Instruction Decode Execute Write Back

IF IF ID EX ID IF

WB

EX ID IF EX EX ID IF

WB

ID

WB

EX EX

WB WB

7

Data Dependency - Pipelined Execuction

slide-8
SLIDE 8

4K Aliasing False Dependency

▪

Memory loads/stores are executed out of order and speculatively

▪

The dependency is verified after the execution!

▪

4K Aliasing: Addresses that are 4K apart are assumed dependent

▪

Re-execute the load and corresponding instructions due to false dependency

▪

Virtual-to-physical address translation → Memory disambiguation

mov %eax, (%ebx) mov (%ecx), %edx

Load

Store

Execute

Load

Execute

Store

Dependent?

Yes 8

slide-9
SLIDE 9

SPOILER

9

slide-10
SLIDE 10

1 MB Aliasing False Dependency

10

slide-11
SLIDE 11

1 MB Aliasing False Dependency

11

slide-12
SLIDE 12

1 MB Aliasing False Dependency

12

slide-13
SLIDE 13

Cross-Context Address Leakage?

13

slide-14
SLIDE 14

Rowhammer – Bank Colocation

14

▪

DRAM Banks are mapped based on the physical address

slide-15
SLIDE 15

Rowhammer – Detecting Contiguous Memory

15

▪

Memory is contiguous when the peaks 256 apart

slide-16
SLIDE 16

Cache Attacks

16

▪

Cache sets are mapped based on the physical address.

▪

https://github.com/UzL-ITS/Spoiler

slide-17
SLIDE 17

▪

Optimized Application- specific Hardware Configuration

▪

e.g. Real-time Artificial Intelligence

17

Accelerators in the Cloud

slide-18
SLIDE 18

Side channels on Heterogeneous Accelerators

▪

New Attack Surface:

▪

Accelerator Function Units (AFUs) placed on the FPGA can be used to interact with the CPU

  • r other AFUs for malicious purpose.

▪

AFU to AFU Attack

▪

AFU to HPS Attack

▪

AFU to CPU Attack

▪

CPU to AFU Attack

▪

Across VMS ?

▪

Customizable Hardware → More Devastating Attacks

▪

E.g. Design your own timers, Direct access to memory interface, etc.

▪

Complex Threat Model

18

slide-19
SLIDE 19

Integrated FPGA-CPU Platforms

19

slide-20
SLIDE 20

Attack Vectors

▪

Rowhammer

▪

Trojan Bitstreams

20

▪

Cache Attacks

▪

Cold Boot

▪

DMA/IOMMU

▪

FPGA-centric Attacks

slide-21
SLIDE 21

Replicating μArch Attacks on FPGA-CPU Interface

▪

Memory Interface and the Cache Coherency Protocol

▪

Side-channel Analysis of Memory Operations

21

slide-22
SLIDE 22

Lab/Collaboration Setup

▪

Weekly Meeting ( 2 Faculty + 3 Students = 5 people are actively involved.)

▪

Software

▪

OPAE Stack

▪

Intel Quartus (Synthesis)

▪

KVM (Virtualization Scenario)

▪

Hardware

▪

Remote Access to Intel Labs (Xeon)

▪

Local Server including Intel PAC

▪

Heavy Load Workstation (Synthesis)

22

slide-23
SLIDE 23

Cache Attack and FPGAs

23

slide-24
SLIDE 24

Cache Attack and FPGAs

24

slide-25
SLIDE 25

WPI + Lubeck Team

25

slide-26
SLIDE 26

Other Works

▪

Transient Execution Attacks

▪

Schwarz et al. “ZombieLoad: Cross-Privilege-Boundary Data Sampling”

▪

Minkin et al. “Fallout: Reading Kernel Writes From User Space”

▪

Microarchitectural Side Channels

▪

Islam et al. “SPOILER: Speculative Load Hazards Boost Rowhammer and Cache Attacks”

▪

Moghimi et al. “MemJam: A False Dependency Attack against Constant-Time Crypto Implementations”

▪

Intel SGX / TEE

▪

Moghimi et al. “CacheZoom: How SGX Amplifies The Power of Cache Attacks”

▪

Cryptographic Implementations

▪

Wichelmann et al. “MicroWalk: A Framework for Finding Side Channels in Binaries”

▪

Dall et al. “CacheQuote: Efficiently Recovering Long-term Secrets of SGX EPID via Cache Attacks”

▪

Are remote timing attack being still a thing in 2019 !??!

26

slide-27
SLIDE 27

Acknowledgements

27

▪

Thanks to Carlos Rosaz, Matthias Schunter, Anand Rajan, Evan Custodio and Alpa Trivedi from Intel

slide-28
SLIDE 28

THANKS

▪ Questions?

@danielmgmi

28