Lost and Found in Speculation: Hybrid Speculative Vulnerability Detection
Abstract
Microarchitectural attacks represent a challenging and persistent threat to modern processors, exploiting inherent design vulnerabilities in processors to leak sensitive information or compromise systems. Of particular concern is the susceptibility of Speculative Execution, a fundamental part of performance enhancement, to such attacks. We introduce Specure, a novel pre-silicon verification method composing hardware fuzzing with Information Flow Tracking (IFT) to address speculative execution leakages. Integrating IFT enables two significant and non-trivial enhancements over the existing fuzzing approaches: i) automatic detection of microarchitectural information leakages vulnerabilities without golden model and ii) a novel Leakage Path coverage metric for efficient vulnerability detection. Specure identifies previously overlooked speculative execution vulnerabilities on the RISC-V BOOM processor and explores the vulnerability search space 6.45x faster than existing fuzzing techniques. Moreover, Specure detected known vulnerabilities 20x faster.
Cite
@article{arxiv.2410.22555,
title = {Lost and Found in Speculation: Hybrid Speculative Vulnerability Detection},
author = {Mohamadreza Rostami and Shaza Zeitouni and Rahul Kande and Chen Chen and Pouya Mahmoody and Jeyavijayan and Rajendran and Ahmad-Reza Sadeghi},
journal= {arXiv preprint arXiv:2410.22555},
year = {2024}
}