Modern processors rely on aggressive microarchitectural optimizations such as speculative execution, branch prediction, and hardware prefetching to maximize performance. However, these optimizations often introduce subtle side channels that can be exploited to leak sensitive information across security boundaries. In this thesis, we present two novel microarchitectural attacks, Reverse Spectre-RSB and CacheEcho and evaluate them on both x86-64 and ARM processors. Reverse Spectre-RSB is a guest-to-host transient execution attack exploiting stale values contained in the Return Stack Buffer during host to guest transitions to break user space and kernel space address randomization, a key mitigation against a huge amount of exploits. We discover how this attack is already mitigated in hardware on recent CPUs, but is still effective on the majority of CPUs released prior to 2023, in which software mitigations are needed. CacheEcho is a cache-timing attack exploiting undocumented microarchitectural features, primarily linked to L2 hardware prefetchers and victim caches, which retain a short-term memory of prior access patterns and produces small but measurable timing differences correlated with secret-dependent memory accesses. We demonstrate partial key recovery against an AES S-BOX implementation, leaking up to 3 most significant bits per key byte, and systematically investigate the contributions of individual microarchitectural components in the attack.
I processori moderni si basano su ottimizzazioni microarchitetturali aggressive come l'esecuzione speculative, la predizione dei salti e il prefetching hardware per massimizzare le prestazioni. Tuttavia, queste ottimizzazioni spesso introducono canali laterali sottili che possono essere sfruttati per estrapolare informazioni sensibili attraverso i confini di sicurezza. In questa tesi, presentiamo due nuovi attacchi microarchitetturali, Reverse Spectre-RSB e CacheEcho, e li valutiamo su processori x86-64 e ARM. Reverse Spectre-RSB è un attacco di esecuzione transitoria da guest a host che sfrutta i valori obsoleti contenuti nel Return Stack Buffer durante le transizioni da host a guest per rompere la randomizzazione degli indirizzi di memoria user space e kernel space, una mitigazione chiave contro un'enorme quantità di attacchi. Scopriamo come questo attacco è già mitigato in hardware su recenti CPU, ma è ancora efficace sulla maggior parte delle CPU rilasciate prima del 2023, in cui sono necessarie mitigazioni software. CacheEcho è un attacco basato sui tempi di accesso alla cache che sfrutta caratteristiche microarchitetturali non documentate, principalmente legate ai prefetcher hardware L2 e alle victim cache, che mantengono una memoria a breve termine dei pattern di accesso di esecuzioni precedenti e producono piccole ma misurabili differenze di tempo di esecuzione correlate agli accessi in memoria dipendenti da segreti. Dimostriamo il recupero parziale della chiave contro un'implementazione AES S-BOX, estraendo fino a 3 bit più significativi per byte della chiave, e indaghiamo sistematicamente i contributi dei singoli componenti microarchitetturali nell'attacco.
The never ending fight between microarchitectural optimizations and vulnerabilities
Meinardi, Marco
2024/2025
Abstract
Modern processors rely on aggressive microarchitectural optimizations such as speculative execution, branch prediction, and hardware prefetching to maximize performance. However, these optimizations often introduce subtle side channels that can be exploited to leak sensitive information across security boundaries. In this thesis, we present two novel microarchitectural attacks, Reverse Spectre-RSB and CacheEcho and evaluate them on both x86-64 and ARM processors. Reverse Spectre-RSB is a guest-to-host transient execution attack exploiting stale values contained in the Return Stack Buffer during host to guest transitions to break user space and kernel space address randomization, a key mitigation against a huge amount of exploits. We discover how this attack is already mitigated in hardware on recent CPUs, but is still effective on the majority of CPUs released prior to 2023, in which software mitigations are needed. CacheEcho is a cache-timing attack exploiting undocumented microarchitectural features, primarily linked to L2 hardware prefetchers and victim caches, which retain a short-term memory of prior access patterns and produces small but measurable timing differences correlated with secret-dependent memory accesses. We demonstrate partial key recovery against an AES S-BOX implementation, leaking up to 3 most significant bits per key byte, and systematically investigate the contributions of individual microarchitectural components in the attack.| File | Dimensione | Formato | |
|---|---|---|---|
|
2026_03_Meinardi_Tesi.pdf
accessibile in internet per tutti a partire dal 01/03/2027
Descrizione: Tesi
Dimensione
4.53 MB
Formato
Adobe PDF
|
4.53 MB | Adobe PDF | Visualizza/Apri |
|
2026_03_Meinardi_Executive_Summary.pdf
accessibile in internet per tutti a partire dal 01/03/2027
Descrizione: Executive Summary
Dimensione
479.66 kB
Formato
Adobe PDF
|
479.66 kB | Adobe PDF | Visualizza/Apri |
I documenti in POLITesi sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/10589/253120