当前位置:首页 > 报告详情

SysBumps:利用系统调用中的推测执行来破坏 macOS for Apple Silicon 中的 KASLR.pdf

上传人: 竿*** 编号:981545 2025-11-29 102页 5.40MB

1、#BHEU BlackHatEventsSysBumps:Exploiting Speculative Execution in System Calls for Breaking KASLR in macOS for Apple SiliconSpeaker:Hyerean Jang$WhoamiHyerean JangPh.D Student Korea University Email:hr_jangkorea.ac.kr Research interests:Microarchitectural side-channel vulnerability,System security Co

2、ntributorsTaehun KimPh.D Student Korea University Email:taehunkkorea.ac.krYoungjoo ShinProfessor Korea University Email:syoungjookorea.ac.krApple SiliconApples proprietary arm-based processorApple SiliconApples proprietary arm-based processorExploring Microarchitectural Side-Channel Vulnerabilities

3、on macOS for Apple SiliconmacOSWhat is SysBumps Attack?KASLR breaking attack on macOS for Apple siliconWhat is SysBumps Attack?KASLR breaking attack on macOS for Apple siliconSpeculativeExecutionIn system callWhat is SysBumps Attack?KASLR breaking attack on macOS for Apple siliconSpeculativeExecutio

4、nTLB-basedSide-channelIn system callOutline Background Existing Microarchitectural Attack on KASLR Challenges Our Approaches SysBumps Attack Mitigations TakeawayMicroarchitectural Side-Channel Attack Exploit CPU design flaws to extract information through indirect leakages-Cache,TLB,branch predictor

5、s,Kernel Address Space Layout Randomization Load kernel into random location-Prevent attackers from predicting target kernel addresses for exploitsKernelKernelKernelNext bootingNext bootingKernel Address Space Layout Randomization Kernel is loaded within a reserved range of kernel addresses-Aligned

6、address to a specific sizeKernel address rangeAligned addressKernelKernel Address Space Layout Randomization Kernel is loaded within a reserved range of kernel addresses-Aligned address to a specific size Linux :0 xFFFFFFFF 8000 0000 0 xFFFF FFFF C000 0000(16MB aligned)Windows:0 xFFFF F800 0000 0000

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
根据《SysBumps:Exploiting Speculative Execution in System Calls for Breaking KASLR in macOS for Apple Silicon》的内容,以下是全文关键点的概括: 1. **SysBumps攻击**:一种针对macOS for Apple Silicon的KASLR(内核地址空间布局随机化)的破坏性攻击,利用了系统调用中的推测执行。 2. **攻击原理**:通过系统调用中的推测执行和TLB(转换后备缓冲区)的侧信道漏洞,攻击者可以推断出内核地址。 3. **攻击效果**:在3秒内,平均准确率达到96.58%,可以找到内核基址。 4. **挑战**:包括如何缓存内核地址在TLB中、如何检查内核地址是否在TLB中缓存,以及macOS for Apple Silicon的KASLR实现细节。 5. **缓解措施**:包括使用fence指令防止推测执行、限制推测执行窗口、为无效地址分配TLB条目以及分区dTLB。 6. **影响**:KASLR在macOS for Apple Silicon上存在微架构侧信道攻击的漏洞,这可以通过硬件或软件改进来缓解。
"苹果芯片 macOS KASLR 存漏洞?" SysBumps 攻击!" SysBumps 攻击解析!"
客服
商务合作
小程序
服务号
折叠