遇见数据集

Faulty Point Unit: ABI Poisoning Attacks on Intel SGX (Dataset)

收藏
Zenodo2021-04-28 更新2026-05-25 收录
数据链接:
官方服务:

资源简介:

This repository collects source code and data to reproduce the research published in our paper "Faulty Point Unit: ABI Poisoning Attacks on Intel SGX" to appear at ACSAC'20. <strong>Abstract</strong><br> This paper analyzes a previously overlooked attack surface that allows unprivileged adversaries to impact supposedly secure floating-point computations in Intel SGX enclaves through the Application Binary Interface (ABI). In a comprehensive study across 7 widely used industry-standard and research enclave shielding runtimes, we show that control and state registers of the x87 Floating-Point Unit(FPU) and Intel Streaming SIMD Extensions (SSE) are not always properly sanitized on enclave entry. First, we abuse the adversary's control over precision and rounding modes as a novel "ABI-level fault injection" primitive to silently corrupt enclaved floating-point operations, enabling a new class of stealthy, integrity-only attacks that disturb the result of SGX enclave computations. Our analysis reveals that this threat is especially relevant for applications that use the older x87 FPU, which is still being used under certain conditions for high-precision operations by modern compilers like gcc. We exemplify the potential impact of ABI-level quality-degradation attacks in a case study of an enclaved machine learning service and in a larger analysis on the SPEC benchmark programs. Second,we explore the impact on enclave confidentiality by showing that the adversary's control over floating-point exception masks can be abused as an innovative controlled channel to detect FPU usage and to recover enclaved multiplication operands in certain scenarios. Our findings, affecting 5 out of the 7 studied runtimes, demonstrate the fallacy and challenges of implementing high-assurance trusted execution environments on contemporary x86 hardware. We responsibly disclosed our findings to the vendors and were assigned two CVEs, leading to patches in the Intel SGX-SDK, Microsoft OpenEnclave, and the Rust compiler's SGX target.

本代码仓库收录了用于复现我们发表于ACSAC'20会议的论文"Faulty Point Unit: ABI Poisoning Attacks on Intel SGX"(中文可译为《故障点单元:针对英特尔软件防护扩展(Intel SGX)的ABI投毒攻击》)的研究所需的源代码与数据集。**摘要** 本文分析了此前被忽视的攻击面:非特权攻击者可通过应用二进制接口(Application Binary Interface, ABI),影响英特尔软件防护扩展(Intel SGX)飞地中原本受保护的浮点计算。我们针对7种广泛使用的行业标准与学术飞地隔离运行时展开了全面研究,结果显示,x87浮点单元(Floating-Point Unit, FPU)与英特尔流式单指令多数据扩展(Streaming SIMD Extensions, SSE)的控制与状态寄存器,在飞地入口处并非总能得到正确的清理。 首先,我们将攻击者对浮点精度与舍入模式的控制权,开发为一种新型“ABI级故障注入”原语,可静默破坏飞地内的浮点运算,由此催生了一类全新的隐蔽性仅完整性攻击,能够干扰SGX飞地计算的结果。我们的分析表明,该威胁对使用老旧x87 FPU的应用尤为突出——现代编译器(如gcc)在某些场景下仍会使用x87 FPU来执行高精度运算。我们通过两个案例研究展示了ABI级质量降级攻击的潜在影响:一是飞地机器学习服务,二是对SPEC基准测试程序的大规模分析。 其次,我们探究了该攻击对飞地机密性的影响:通过证明攻击者对浮点异常掩码的控制权可被利用为一种创新的受控信道,能够在特定场景下检测FPU的使用情况,并还原飞地内的乘法操作数。 我们的研究结果影响了7种被测试运行时中的5种,这表明在当代x86硬件上实现高可信执行环境存在谬误与挑战。我们已负责任地将该发现披露给相关厂商,并获得了两个通用漏洞与暴露(Common Vulnerabilities and Exposures, CVE)编号,相关补丁已在英特尔SGX-SDK、微软OpenEnclave以及Rust编译器的SGX目标版本中得到应用。

提供机构:
Zenodo
创建时间:
2021-04-28
二维码
社区交流群
二维码
科研交流群
商业服务