HomeSecurityBranchScope, a new threat to Intel CPUs

BranchScope, a new threat to Intel CPUs

CPUIn the world of computer security, once a vulnerability, it's enough for security researchers to find similar flaws and suggest new attack mechanisms that could be created. Researchers at the College of William and Mary, the University of California Riverside, Carnegie Mellon University in Qatar, and Binghamton University have found a new attack that looks like Spectre.

Before however we talk about the new type of attack called “BranchScope”, let's refer to “speculative execution” – a characteristic of modern CPUs that is responsible for such attacks.

With speculative execution, your computer's CPU can process the calculation ahead of the current state of a program and try to guess what could happen next. When a program finally proceeds, the CPU discards the wrong guesses and executes the correct action.

In the perfect scenario, the CPU should completely clear the cache memory and get rid of any stored data, as they could contain some secret information. But something like that does not happen. Just like Specter 2, the BranchScope attack also exploits this capability of any data remnants.

The BranchScope attack deals with the branch prediction units «...» (BPUs) of a CPU. A BPU component monitors whether a particular instruction branch is taken or not. Now, when multiple processes run on the same physical core, they end up sharing the same predictive branch.

Theoretically, this gives an attacker the ability to gain access to a shared BPU and create a side channel, thereby leaking sensitive data. For example, if an instruction contains a secret key, it can leak immediately.

There is a chance that the updates for Spectre and Meltdown released by Intel could only cover part of the problem. Thus, there is a chance that the BranchScope attack is still possible.

It should be noted that BranchScope is not the first attack after Meltdown and Spectre. There have also been others such as SgxSpectre, which targets Intel SGX (Software Guard Extension).

“The attacker can also change the prediction state, altering its behavior towards the victim”, the document describing the attack in detail states. It also claims that BranchScope could be expanded and attack SGX enclaves with even lower system rates.

You can read the detailed research here.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS