Pathfinder: High-Resolution Control-Flow Attacks Exploiting the Conditional Branch Predictor

Dean M. Tullsen, Daniel Genkin, Deian Stefan, Christina Garman, Daniel Moghimi, Andrew Kwong, Hosein Yavarzadeh, Archit Agarwal, Max Christman, Kazem Taram
2024-04-24

SCID:  54.1/zwextbpp
This paper introduces novel attack primitives that enable adversaries to leak (read) and manipulate (write) the path history register (PHR) and the prediction history tables (PHTs) of the conditional branch predictor in high-performance CPUs. These primitives enable two new classes of attacks: first, it can recover the entire control flow history of a victim program by exploiting read primitives, as demonstrated by a practical secret-image recovery based on capturing the entire control flow of libjpeg routines. Second, it can launch extremely high-resolution transient attacks by exploiting write primitives. We demonstrate this with a key recovery attack against AES based on extracting intermediate values.
Publication Details
Publication Date
2024-04-24
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Dean M. Tullsen
Daniel Genkin
Deian Stefan
Christina Garman
Daniel Moghimi
Andrew Kwong
Hosein Yavarzadeh
Archit Agarwal
Max Christman
Kazem Taram
Explore More Research
Use the citation graph to discover related papers and expand your research horizons.
Click any node to explore
Download PDF
100%