InstPro: Provenance-Based Transient Execution Attack Detection and Investigation on Instruction Execution Traces
Yang Zheng, Yu Wen, Ruoyu Wang, Yanna Wu, Boyang Zhang, Dan Meng · IEEE Transactions on Dependable and Secure Computing · 2025
Transient execution attacks (TEAs) are a serious threat to modern computing systems. While software/hardware hardening techniques have been proposed to mitigate the threat, developing detection techniques remains imperative, as they hold promise for flexible extension to address new variants, ease of deployment, and minimal system impact. Existing detection techniques face the following three limitations: unstable information sources, lack of explanation for attack scenarios, and limited training data. To address the limitations, we proposeInstPro, a TEA detection system thatidentifies a TEA program while providing an explanation of the attack scenario, based on instruction execution traces. Specifically,InstProfirst extractsprincipled cluesthat represent instruction sequences semantically close to attack abstraction. These clues provide high-level visualizations of TEA steps. Then,InstProcorrelates the clues into aclue provenance graphby reasoning about their causal dependencies, which provides a concise provenance representation. Finally,InstProreconstructs a scenario graph by using theInfoSubgraphsthat represent the information flows among principled clues. These InfoSubgraphs are more likely to capture a set of crucial principled clues that work together to represent the attack scenario. Our evaluations based on 5 datasets show thatInstProeffectively performs TEA detection and investigation.