Hardware-Based Detection of Spectre Attacks: A Machine Learning Approach

Yunjie Zhang, Yiorgos Makris · 2020

The Spectre vulnerability, which has been found in a variety of processors, enables attackers to take advantage of speculative execution in modern computer architectures to access unauthorized memory content through temporal side channels. Herein, we propose a hardware-based defense mechanism that can detect Spectre attacks by utilizing the profile of a small fraction of malicious program execution. More specifically, we focus on malicious attempts to read data from theoretically inaccessible memory space. The corresponding instruction sequence is divided into consecutive windows, from which a performance counter-based tracker extracts descriptive features. These features are, then, processed by a trained machine learning model to analyze program behaviors and identify suspicious ones. Our experiment shows that Spectre attacks on thirteen vulnerable purpose-built victim code patterns can be detected by our system. Additionally, testing with benign benchmarks demonstrates that our framework is able to distinguish Spectre attacks from normal behavior.

Read the paper · More papers on PaperTik