(Press-News.org) Researchers have found two novel types of attacks that target the conditional branch predictor found in high-end Intel processors, which could be exploited to compromise billions of processors currently in use.
The multi-university and industry research team led by computer scientists at University of California San Diego will present their work at the 2024 ACM ASPLOS Conference that begins tomorrow. The paper, "Pathfinder: High-Resolution Control-Flow Attacks Exploiting the Conditional Branch Predictor," is based on findings from scientists from UC San Diego, Purdue University, Georgia Tech, the University of North Carolina Chapel Hill and Google.
They discover a unique attack that is the first to target a feature in the branch predictor called the Path History Register, which tracks both branch order and branch addresses. As a result, more information with more precision is exposed than with prior attacks that lacked insight into the exact structure of the branch predictor.
Their research has resulted in Intel and Advanced Micro Devices (AMD) addressing the concerns raised by the researchers and advising users about the security issues. Today, Intel is set to issue a Security Announcement, while AMD will release a Security Bulletin.
In software, frequent branching occurs as programs navigate different paths based on varying data values. The direction of these branches, whether "taken" or "not taken," provides crucial insights into the executed program data. Given the significant impact of branches on modern processor performance, a crucial optimization known as the "branch predictor" is employed. This predictor anticipates future branch outcomes by referencing past histories stored within prediction tables. Previous attacks have exploited this mechanism by analyzing entries in these tables to discern recent branch tendencies at specific addresses.
In this new study, researchers leverage modern predictors' utilization of a Path History Register (PHR) to index prediction tables. The PHR records the addresses and precise order of the last 194 taken branches in recent Intel architectures. With innovative techniques for capturing the PHR, the researchers demonstrate the ability to not only capture the most recent outcomes but also every branch outcome in sequential order. Remarkably, they uncover the global ordering of all branches. Despite the PHR typically retaining the most recent 194 branches, the researchers present an advanced technique to recover a significantly longer history.
“We successfully captured sequences of tens of thousands of branches in precise order, utilizing this method to leak secret images during processing by the widely used image library, libjpeg,” said Hosein Yavarzadeh, a UC San Diego Computer Science and Engineering Department PhD student and lead author of the paper.
The researchers also introduce an exceptionally precise Spectre-style poisoning attack, enabling attackers to induce intricate patterns of branch mispredictions within victim code. “This manipulation leads the victim to execute unintended code paths, inadvertently exposing its confidential data,” said UC San Diego computer science Professor Dean Tullsen.
"While prior attacks could misdirect a single branch or the first instance of a branch executed multiple times, we now have such precise control that we could misdirect the 732nd instance of a branch taken thousands of times,” said Tullsen.
The team presents a proof-of-concept where they force an encryption algorithm to transiently exit earlier, resulting in the exposure of reduced-round ciphertext. Through this demonstration, they illustrate the ability to extract the secret AES encryption key.
"Pathfinder can reveal the outcome of almost any branch in almost any victim program, making it the most precise and powerful microarchitectural control-flow extraction attack that we have seen so far," said Kazem Taram, an assistant professor of computer science at Purdue University and a UC San Diego computer science PhD graduate.
In addition to Dean Tullsen and Hosein Yavarzadeh, other UC San Diego coauthors are. Archit Agarwal and Deian Stefan. Other coauthors include Christina Garman and Kazem Taram, Purdue University; Daniel Moghimi, Google; Daniel Genkin, Georgia Tech; Max Christman and Andrew Kwong, University of North Carolina Chapel Hill.
This work was partially supported by the Air Force Office of Scientific Research (FA9550- 20-1-0425); the Defense Advanced Research Projects Agency (W912CG-23-C-0022 and HR00112390029); the National Science Foundation (CNS-2155235, CNS-1954712, and CAREER CNS-2048262); the Alfred P. Sloan Research Fellowship; and gifts from Intel, Qualcomm, and Cisco.
Responsible disclosure
Researchers communicated the security findings outlined in the paper to both Intel and AMD in November 2023. Intel has informed other affected hardware/software vendors about the issues. Both Intel and AMD plan to address the concerns raised in the paper today through a Security Announcement and a Security Bulletin (AMD-SB-7015), respectively. The findings have been shared with the Vulnerability Information and Coordination Environment (VINCE), Case VU#157097: Class of Attack Primitives Enable Data Exposure on High End Intel CPUs.
END
Computer scientists unveil novel attacks on cybersecurity
Intel and AMD will issue security alerts today based on the findings
2024-04-26
ELSE PRESS RELEASES FROM THIS DATE:
Florida International University graduate student selected for inaugural IDEA2 public policy fellowship
2024-04-26
The American Institute of Biological Sciences (AIBS) and the Southeastern Universities Research Association (SURA) are pleased to announce that Kristine Zikmanis has been selected for the 2024 Inclusive, Diverse, Equitable, Accepting, and Accessible (IDEA2) Public Policy Fellowship. This new professional development opportunity provides young scientists with valuable first-hand experience in science policy.
Kristine Zikmanis is a Ph.D. candidate in the Department of Biological Sciences at Florida International University. As an ecologist, Zikmanis studies animal behavior and has a strong interest in research at the intersection of ecology and ...
Gene linked to epilepsy, autism decoded in new study
2024-04-26
SCN2A related-disorders, although rare in the general population, are one of the more common single-gene neurodevelopmental conditions characterized by infantile seizures, autism spectrum disorder and intellectual disabilities
Severity of these disorders varies widely from person to person
Findings should help better identify patients who are most appropriate for clinical trials of new precision medicines and gene therapies
CHICAGO --- A genetic change or variant in a gene called SCN2A is a known cause of infantile seizures, autism spectrum disorder and intellectual disability, as well as a wide range of other moderate-to-profound impairments in mobility, ...
OHSU study finds big jump in addiction treatment at community health clinics
2024-04-26
The number of health care professionals able to write a prescription for a key medication to treat addiction quadrupled at community health clinics from 2016 to 2021, according to a new study by researchers at Oregon Health & Science University.
The findings, published online today in the journal JAMA Health Forum, provides a glimmer of hope amid a national overdose epidemic that has claimed more than 100,000 lives in the United States in each of the past few years.
The study examined community health centers serving low-income people primarily in West Coast states. Researchers ...
Location, location, location
2024-04-26
Riverside, Calif. -- In unincorporated communities in the United States-Mexico borderlands, historically and socially marginalized populations become invisible to the healthcare system, showing that geography acts as a structural determinant of health for low-income populations. So concludes a study by a University of California, Riverside, team that focused its attention on the borderland in Southern California, specifically, eastern Coachella Valley.
From September to December 2020, the team, led by Ann Cheney, an associate professor of social medicine, population, and public health in the School of Medicine, conducted interviews in collaboration with ...
Getting dynamic information from static snapshots
2024-04-26
Imagine predicting the exact finishing order of the Kentucky Derby from a still photograph taken 10 seconds into the race.
That challenge pales in comparison to what researchers face when using single-cell RNA-sequencing (scRNA-seq) to study how embryos develop, cells differentiate, cancers form, and the immune system reacts.
In a paper published today in Proceedings of the National Academy of Sciences, researchers from the UChicago Pritzker School of Molecular Engineering and the Chemistry ...
Food insecurity is significant among inhabitants of the region affected by the Belo Monte dam in Brazil
2024-04-26
The social and environmental impact of the Belo Monte dam and hydroelectric power plant in Pará state, Brazil, has been called a “disaster” by researchers, environmentalists and several media outlets. The damage has again been highlighted recently in an inspection report issued by the Brazilian Institute for the Environment and Renewable Natural Resources (IBAMA), an agency of the Ministry for the Environment and Climate Change. The inspectors detected silting and erosion of the Xingu River, obstacles to river navigation, a significant ...
The Society of Thoracic Surgeons launches new valve surgery risk calculators
2024-04-26
CHICAGO (April 26, 2024) ─ The expanding use of transcatheter technologies has changed the landscape in the treatment of valvular disease in adult cardiac patients, with valve surgery rapidly shifting to more complex interventions frequently involving other concomitant procedures.
To inform heart team and patient decision-making on valve surgery, The Society of Thoracic Surgeons (STS) has launched new risk calculators for isolated tricuspid valve repair and replacement; surgical aortic valve replacement (SAVR) after ...
Component of keto diet plus immunotherapy may reduce prostate cancer
2024-04-26
Adding a pre-ketone supplement — a component of a high-fat, low-carb ketogenic diet — to a type of cancer therapy in a laboratory setting was highly effective for treating prostate cancer, researchers from the University of Notre Dame found.
Recently published online in the journal Cancer Research, the study from Xin Lu, the John M. and Mary Jo Boler Collegiate Associate Professor in the Department of Biological Sciences, and collaborators tackled a problem oncologists have battled: Prostate cancer is resistant to a type of immunotherapy called immune checkpoint blockade (ICB) ...
New circuit boards can be repeatedly recycled
2024-04-26
A recent United Nations report found that the world generated 137 billion pounds of electronic waste in 2022, an 82% increase from 2010. Yet less than a quarter of 2022’s e-waste was recycled. While many things impede a sustainable afterlife for electronics, one is that we don’t have systems at scale to recycle the printed circuit boards (PCBs) found in nearly all electronic devices.
PCBs — which house and interconnect chips, transistors and other components — typically consist of layers of thin glass fiber sheets coated ...
Blood test finds knee osteoarthritis up to eight years before it appears on x-rays
2024-04-26
DURHAM, N.C. – A blood test successfully predicted knee osteoarthritis at least eight years before tell-tale signs of the disease appeared on x-rays, Duke Health researchers report.
In a study appearing April 26 in the journal Science Advances, the researchers validated the accuracy of the blood test that identifies key biomarkers of osteoarthritis. They showed that it predicted development of the disease, as well as its progression, which was demonstrated in their earlier work.
The research advances the utility of a blood test that would be superior to current ...
LAST 30 PRESS RELEASES:
An eye-opening year of extreme weather and climate
Scientists engineer substrates hostile to bacteria but friendly to cells
New tablet shows promise for the control and elimination of intestinal worms
Project to redesign clinical trials for neurologic conditions for underserved populations funded with $2.9M grant to UTHealth Houston
Depression – discovering faster which treatment will work best for which individual
Breakthrough study reveals unexpected cause of winter ozone pollution
nTIDE January 2025 Jobs Report: Encouraging signs in disability employment: A slow but positive trajectory
Generative AI: Uncovering its environmental and social costs
Lower access to air conditioning may increase need for emergency care for wildfire smoke exposure
Dangerous bacterial biofilms have a natural enemy
Food study launched examining bone health of women 60 years and older
CDC awards $1.25M to engineers retooling mine production and safety
Using AI to uncover hospital patients’ long COVID care needs
$1.9M NIH grant will allow researchers to explore how copper kills bacteria
New fossil discovery sheds light on the early evolution of animal nervous systems
A battle of rafts: How molecular dynamics in CAR T cells explain their cancer-killing behavior
Study shows how plant roots access deeper soils in search of water
Study reveals cost differences between Medicare Advantage and traditional Medicare patients in cancer drugs
‘What is that?’ UCalgary scientists explain white patch that appears near northern lights
How many children use Tik Tok against the rules? Most, study finds
Scientists find out why aphasia patients lose the ability to talk about the past and future
Tickling the nerves: Why crime content is popular
Intelligent fight: AI enhances cervical cancer detection
Breakthrough study reveals the secrets behind cordierite’s anomalous thermal expansion
Patient-reported influence of sociopolitical issues on post-Dobbs vasectomy decisions
Radon exposure and gestational diabetes
EMBARGOED UNTIL 1600 GMT, FRIDAY 10 JANUARY 2025: Northumbria space physicist honoured by Royal Astronomical Society
Medicare rules may reduce prescription steering
Red light linked to lowered risk of blood clots
Menarini Group and Insilico Medicine enter a second exclusive global license agreement for an AI discovered preclinical asset targeting high unmet needs in oncology
[Press-News.org] Computer scientists unveil novel attacks on cybersecurityIntel and AMD will issue security alerts today based on the findings