In recent years, modern processors have achieved high performance through aggressive micro-architectural optimisations such as speculative execution, branch prediction, cache hierarchies and out-of-order execution. However, these performance gains have led to the emergence of transient execution vulnerabilities, a novel class of micro-architectural flaws that enable the leakage of sensitive information through traces left behind during transient execution. Evaluating whether the combinations and interactions of such optimisations will lead to exploitable behaviours remains an open challenge, especially for independent analysis. Existing approaches still rely on privileged knowledge of microarchitectural designs or on ad hoc reverse-engineering techniques that limit their reproducibility and portability across different architectures. This thesis proposes a systematic architecture-agnostic, software-only approach to infer the presence and properties that enable transient execution effects based purely on observable timing effects. Moreover, we introduce a novel security framework for evaluating these timing measurements and assessing the processor resilience against different transient execution attack families. By relying solely on timing measures, our approach aims to be extremely portable across all different CPU architectures. Our results show that runtime behaviour analysis can be used to infer security properties of modern processors by using the measurable execution leakage associated with transient execution. This demonstrates that such effects can be systematically measured at runtime across different security boundaries and execution contexts. Lastly, we show that these properties can be used to infer a processor's vulnerability with respect to a class of transient execution attacks. Aggregated vulnerability scores of 45.4\% and 33.1\% for the Intel Core Ultra 7 and AMD Ryzen 9, respectively, reflect measurable differences in hardware resilience across platforms.
Negli ultimi anni, i processori moderni hanno raggiunto elevate prestazioni grazie ad aggressive ottimizzazioni micro-architetturali, come l’esecuzione speculativa, il branch prediction, le gerarchie di cache e l’esecuzione out-of-order. Tuttavia, queste innovazioni e miglioramenti di prestazione hanno portato all'emergere delle vulnerabilità di transient execution, una nuova classe di difetti micro-architetturali che consentono la fuga di informazioni sensibili attraverso tracce residue lasciate durante l’esecuzione transiente. La valutazione della sfruttabilità dei comportamenti derivanti dalle interazioni di tali ottimizzazioni rimane una sfida aperta, soprattutto nel contesto di valutazione indipendente dei processori. Gli approcci esistenti si basano ancora su informazioni privilegiate relative alle microarchitetture o su tecniche di reverse engineering ad-hoc, che ne limitano la riproducibilità e la portabilità tra architetture differenti. Questo lavoro propone un approccio sistematico di tipo architecture-agnostic, interamente basato su software, per inferire la presenza e le proprietà di effetti di transient execution a partire unicamente da misure temporali. Inoltre, viene introdotto un nuovo framework di sicurezza per valutare tali osservazioni e per analizzare la resilienza dei processori rispetto alle diverse famiglie di attacchi di transient execution. Basandosi interamente su misure temporali, il metodo proposto mira a essere altamente portabile su differenti architetture di CPU. I nostri risultati mostrano che l’analisi del comportamento a tempo di esecuzione può essere utilizzata per inferire proprietà di sicurezza dei processori moderni sfruttando le fughe di informazione misurabili associate all’esecuzione transiente. Questo dimostra che tali effetti possono essere osservati e misurati in modo sistematico durante l’esecuzione, in diversi contesti e livelli di isolamento. Infine, mostriamo che tali proprietà possono essere utilizzate per valutare la vulnerabilità di un processore rispetto a una classe di attacchi di transient execution. Punteggi di vulnerabilità aggregati del 45.4\% e 33.1\% rispettivamente per Intel Core Ultra 7 e AMD Ryzen 9 riflettono differenze misurabili nella resilienza hardware tra le piattaforme.
An automatic framework to detect transient execution vulnerabilities in modern CPUs through an architecture-agnostic analysis
BANCALE, LUCA
2025/2026
Abstract
In recent years, modern processors have achieved high performance through aggressive micro-architectural optimisations such as speculative execution, branch prediction, cache hierarchies and out-of-order execution. However, these performance gains have led to the emergence of transient execution vulnerabilities, a novel class of micro-architectural flaws that enable the leakage of sensitive information through traces left behind during transient execution. Evaluating whether the combinations and interactions of such optimisations will lead to exploitable behaviours remains an open challenge, especially for independent analysis. Existing approaches still rely on privileged knowledge of microarchitectural designs or on ad hoc reverse-engineering techniques that limit their reproducibility and portability across different architectures. This thesis proposes a systematic architecture-agnostic, software-only approach to infer the presence and properties that enable transient execution effects based purely on observable timing effects. Moreover, we introduce a novel security framework for evaluating these timing measurements and assessing the processor resilience against different transient execution attack families. By relying solely on timing measures, our approach aims to be extremely portable across all different CPU architectures. Our results show that runtime behaviour analysis can be used to infer security properties of modern processors by using the measurable execution leakage associated with transient execution. This demonstrates that such effects can be systematically measured at runtime across different security boundaries and execution contexts. Lastly, we show that these properties can be used to infer a processor's vulnerability with respect to a class of transient execution attacks. Aggregated vulnerability scores of 45.4\% and 33.1\% for the Intel Core Ultra 7 and AMD Ryzen 9, respectively, reflect measurable differences in hardware resilience across platforms.| File | Dimensione | Formato | |
|---|---|---|---|
|
2026_06_Bancale.pdf
accessibile in internet per tutti
Descrizione: testo tesi
Dimensione
977.27 kB
Formato
Adobe PDF
|
977.27 kB | Adobe PDF | Visualizza/Apri |
|
2026_06_Bancale_Executive_Summary.pdf
accessibile in internet per tutti
Descrizione: Executive Summary
Dimensione
621.59 kB
Formato
Adobe PDF
|
621.59 kB | Adobe PDF | Visualizza/Apri |
I documenti in POLITesi sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/10589/260821