Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch Shadowing
arXiv:1611.06952
Abstract
In this paper, we explore a new, yet critical, side-channel attack against Intel Software Guard Extension (SGX), called a branch shadowing attack, which can reveal fine-grained control flows (i.e., each branch) of an enclave program running on real SGX hardware. The root cause of this attack is that Intel SGX does not clear the branch history when switching from enclave mode to non-enclave mode, leaving the fine-grained traces to the outside world through a branch-prediction side channel. However, exploiting the channel is not so straightforward in practice because 1) measuring branch prediction/misprediction penalties based on timing is too inaccurate to distinguish fine-grained control-flow changes and 2) it requires sophisticated control over the enclave execution to force its execution to the interesting code blocks. To overcome these challenges, we developed two novel exploitation techniques: 1) Intel PT- and LBR-based history-inferring techniques and 2) APIC-based technique to control the execution of enclave programs in a fine-grained manner. As a result, we could demonstrate our attack by breaking recent security constructs, including ORAM schemes, Sanctum, SGX-Shield, and T-SGX. Not limiting our work to the attack itself, we thoroughly studied the feasibility of hardware-based solutions (e.g., branch history clearing) and also proposed a software-based countermeasure, called Zigzagger, to mitigate the branch shadowing attack in practice.
A revised version of this paper will be presented at USENIX Security Symposium 2017. Please cite this paper as Sangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim, Hyesoon Kim, and Marcus Peinado, "Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch Shadowing," in Proceedings of the 26th USENIX Security Symposium (Security), Vancouver, Canada, August 2017
References in corpus (1)
Cited by in corpus (46)
- Leaky Cauldron on the Dark Land: Understanding Memory Side-Channel Hazards in SGX
- SgxPectre Attacks: Stealing Intel Secrets from SGX Enclaves via Speculative Execution
- Software Grand Exposure: SGX Cache Attacks Are Practical
- PAC it up: Towards Pointer Integrity using ARM Pointer Authentication
- Migrating SGX Enclaves with Persistent State
- HybCache: Hybrid Side-Channel-Resilient Caches for Trusted Execution Environments
- CURE: A Security Architecture with CUstomizable and Resilient Enclaves
- Privado: Practical and Secure DNN Inference with Enclaves
- ConTExT: Leakage-Free Transient Execution
- Mitigating Branch-Shadowing Attacks on Intel SGX using Control Flow Randomization
- Swivel: Hardening WebAssembly against Spectre
- Composite Enclaves: Towards Disaggregated Trusted Execution
- Toward Scalable Fully Homomorphic Encryption Through Light Trusted Computing Assistance
- ObliDB: Oblivious Query Processing for Secure Databases
- TEE-aided Write Protection Against Privileged Data Tampering
- Helen: Maliciously Secure Coopetitive Learning for Linear Models
- Confidential Machine Learning Computation in Untrusted Environments: A Systems Security Perspective
- A Survey of Microarchitectural Side-channel Vulnerabilities, Attacks and Defenses in Cryptography
- Visor: Privacy-Preserving Video Analytics as a Cloud Service
- MAGE: Mutual Attestation for a Group of Enclaves without Trusted Third Parties
- Reflections on trusting distributed trust
- StealthDB: a Scalable Encrypted Database with Full SQL Query Support
- A Lightweight Isolation Mechanism for Secure Branch Predictors
- Code Renewability for Native Software Protection
- KloakDB: A Platform for Analyzing Sensitive Data with -anonymous Query Processing
- BliMe: Verifiably Secure Outsourced Computation with Hardware-Enforced Taint Tracking
- Speculative Dereferencing of Registers:Reviving Foreshadow
- It Takes Two to #MeToo - Using Enclaves to Build Autonomous Trusted Systems
- DMON: A Distributed Heterogeneous N-Variant System
- Towards a Trusted Execution Environment via Reconfigurable FPGA
- Confidential Attestation: Efficient in-Enclave Verification of Privacy Policy Compliance
- An Off-Chip Attack on Hardware Enclaves via the Memory Bus
- SafetyPin: Encrypted Backups with Human-Memorable Secrets
- Authenticated Key-Value Stores with Hardware Enclaves
- Secure Collaborative Training and Inference for XGBoost
- Leaking Secrets through Modern Branch Predictor in the Speculative World
- Lightning-Fast and Privacy-Preserving Outsourced Computation in the Cloud
- SoK: Hardware Security Support for Trustworthy Execution
- One-Time Programs made Practical
- Secrecy: Secure collaborative analytics on secret-shared data
- Secure and Efficient Trajectory-Based Contact Tracing using Trusted Hardware
- Concealer: SGX-based Secure, Volume Hiding, and Verifiable Processing of Spatial Time-Series Datasets
- A Tale of Two Trees: One Writes, and Other Reads. Optimized Oblivious Accesses to Large-Scale Blockchains
- An Exploratory Analysis of Microcode as a Building Block for System Defenses
- Accelerating 2PC-based ML with Limited Trusted Hardware
- Stockade: Hardware Hardening for Distributed Trusted Sandboxes