Sie befinden Sich nicht im Netzwerk der Universität Paderborn. Der Zugriff auf elektronische Ressourcen ist gegebenenfalls nur via VPN oder Shibboleth (DFN-AAI) möglich. mehr Informationen...
Ergebnis 5 von 22
2022 IEEE Symposium on Security and Privacy (SP), 2022, p.666-680
2022
Volltextzugriff (PDF)

Details

Autor(en) / Beteiligte
Titel
SoK: Practical Foundations for Software Spectre Defenses
Ist Teil von
  • 2022 IEEE Symposium on Security and Privacy (SP), 2022, p.666-680
Ort / Verlag
IEEE
Erscheinungsjahr
2022
Quelle
IEEE Electronic Library Online
Beschreibungen/Notizen
  • Spectre vulnerabilities violate our fundamental assumptions about architectural abstractions, allowing attackers to steal sensitive data despite previously state-of-the-art countermeasures. To defend against Spectre, developers of verification tools and compiler-based mitigations are forced to reason about microarchitectural details such as speculative execution. In order to aid developers with these attacks in a principled way, the research community has sought formal foundations for speculative execution upon which to rebuild provable security guarantees.This paper systematizes the community's current knowledge about software verification and mitigation for Spectre. We study state-of-the-art software defenses, both with and without associated formal models, and use a cohesive framework to compare the security properties each defense provides. We explore a wide variety of tradeoffs in the expressiveness of formal frameworks, the complexity of defense tools, and the resulting security guarantees. As a result of our analysis, we suggest practical choices for developers of analysis and mitigation tools, and we identify several open problems in this area to guide future work on grounded software defenses.
Sprache
Englisch
Identifikatoren
eISSN: 2375-1207
DOI: 10.1109/SP46214.2022.9833707
Titel-ID: cdi_ieee_primary_9833707

Weiterführende Literatur

Empfehlungen zum selben Thema automatisch vorgeschlagen von bX