Microarchitectural Attacks

Yuval Yarom · 2025

This chapter investigates a class of side-channel attacks that exploit the microarchitecture of the processor. Microarchitecture is the name for the set of components in the processor that implement the functionality it provides, that is, execute the instruction set. When multiple programs run on the same computer, they share the use of microarchitectural components. Microarchitectural components can also be exploited to implement covert channels. Meltdown-type attacks exploit transient execution to overcome hardware-based protection mechanism. In a Meltdown attack, the attacker issues a memory load from an address that is part of the operating system kernel. Microarchitectural channels can be combined with speculative and out-of-orderexecution for mounting transient-execution attacks. In these attacks, transient instructions access data that the program is not allowed to access and transmit it through a microarchitectural channel.

Read the paper · More papers on PaperTik