MIT’s Canny TONTOU Skates Beyond Spectre on Intel, AMD Processors

Introduction to the Latest Speculative Execution Attack

Two researchers from MIT are poised to reveal a novel speculative execution attack at DEF CON 34, utilizing precise interrupts to circumvent protections against Spectre v2. Daniël Trujillo and Mengjia Yan, hailing from MIT’s Computer Science and Artificial Intelligence Laboratory (CSAIL), have provided us at GadgetLad with an exclusive look at their research. Their attack targets the safeguards intended to manage dubious branch predictor states prior to the execution of sensitive code.

Neutralization Mitigations: What’s the Buzz?

The neutralization mitigations vary depending on the chip manufacturer. Intel’s eIBRS manages branch predictors during context switches, while AMD’s Safe RET, introduced following the Inception attack in 2023, addresses the stage just before a protected branch executes. The researchers refer to these as entry neutralization and in-place neutralization, respectively.

The Post-Neutralization Interval

Both types rely on the belief that attackers cannot manipulate branch predictor states during what is termed the “post-neutralization interval.” This period occurs between neutralization and the activation of the branch predictor, presumed to be a secure zone, yet Trujillo and Yan dispute this notion.

TONTOU: A Playful Attack in Development

The attack concocted by Trujillo and Yan, dubbed TONTOU (Time-of-Neutralization to Time-of-Use), demonstrates that adversaries can interfere with the branch predictor during this supposedly secure post-neutralization interval. They have developed an attack primitive termed “interrupt injection.”

Understanding Interrupt Injection

An unprivileged application establishes high-frequency timer interrupts, aiming for one to align perfectly within the post-neutralization interval. This method allows attackers to manipulate control flow so that an interrupt handler activates after sanitization yet before the target branch completes its execution.

Practical Attacks: A Bit of a Struggle

The researchers assert that their TONTOU attacks have been effective on both Intel and AMD-based Linux systems. They tested on Intel Cascade Lake Refresh, Arrow Lake processors, and AMD Zen 2 and Zen 4 chips. For Zen 2, they achieved a complete end-to-end exploit, while the Intel attack demanded some complex software conditions.

The Real-World Challenge

Side-channel attacks like these are notoriously difficult to execute, akin to trying to wring a free pint out of a reluctant Geordie. You’re more likely to encounter ransomware than a Spectre attack in the real world. Furthermore, each complete attempt took around 18 minutes. Witness the action unfold in Trujillo’s YouTube video.

Overcoming KASLR: A Clever Tactic

Trujillo and Yan pinpointed the exact moment to introduce their interruptions, enabling them to bypass Linux’s kernel address space layout randomization (KASLR). They achieved this ten times, consistently breaching KASLR, though they only managed to extract the contents of etc/shadow half the time. As Trujillo remarked, “It’s a challenging attack, but we’ve demonstrated it’s achievable on AMD Zen 2.”

Striking a Nerve: Implications for the Industry

The duo from MIT aspires to ignite further research into interrupt injections and TONTOU attacks. They advocate for enhanced defenses against Spectre-type vulnerabilities. Discussions with companies like Intel, Arm, and AMD were carried out. Only AMD appeared willing to address the issue with kernel patches. As for Intel? They consider the real-world obstacles too significant, although they did contribute some funds from their bug bounty program. Arm simply dismissed it as “passive leakage.”

Conclusion: Technology Gone Awry

In the unpredictable realm of technology, safety cannot be taken for granted. MIT’s Trujillo and Yan illustrate that even with robust defenses against Spectre-like attacks, there is always potential for a clever new exploit. Thus, if you’re operating on a multi-tenant container platform, remain vigilant about who you share your environment with, lest they peer over your shoulder and pilfer your secrets.