Fetching the paper…
Reading the bibliography…
Practical attacks that exploit speculative execution can leak confidential information via microarchitectural side channels.
Lockup-free Instruction Fetch/Prefetch Cache Organization. In Proceedings of the 8th Annual Symposium on Computer Architecture (ISCA ’81) . IEEE Computer Society Press, Los Alamitos, CA, USA, 81–87
David Kroft. 1981 · 1981
Earlier work this paper cites.
The MIPS R10000 Superscalar Microprocessor
K.C. Yeager. 1996 · 1996
Earlier work this paper cites.
Memory Dependence Prediction Using Store Sets. In Proceedings of the 25th Annual International Symposium on Computer Architecture (ISCA ’98) . Washington, DC, USA, 142–153
George Z. Chrysos and Joel S. Emer. 1998 · 1998
Earlier work this paper cites.
StackGhost: Hardware Facilitated Stack Protection. In Proceedings of the 10th Conference on USENIX Security Symposium - Volume 10 (SSYM’01) . USENIX Association, Berkeley, CA, USA, Article 5
Mike Frantzen and Mike Shuey. 2001 · 2001
Earlier work this paper cites.
Secure Execution via Program Shepherding. In Proceedings of the 11th USENIX Security Symposium . USENIX Association, Berkeley, CA, USA, 191–206
Vladimir Kiriansky, Derek Bruening, and Saman Amarasinghe. 2002 · 2002
Earlier work this paper cites.
Secure Execution Environment via Program Shepherding
Vladimir Kiriansky. 2003 · 2003
Earlier work this paper cites.
Execution Model Enforcement Via Program Shepherding
Vladimir Kiriansky, Derek Bruening, and Saman Amarasinghe. 2003 · 2003
Earlier work this paper cites.
The Microarchitecture of the Intel Pentium 4 Processor on 90nm Technology
Darrell Boggs, Aravindh Baktha, Jason Hawkins, Deborah Marr, J. Alan Miller, Patrice Roussel, Ronak Singhal, Bret Toll, and K.S. Venkatraman. 2004 · 2004
Earlier work this paper cites.
Control-flow Integrity. In Proceedings of the 12th ACM Conference on Computer and Communications Security (CCS ’05) . ACM, New York, NY, USA, 340–353
Martín Abadi, Mihai Budiu, Úlfar Erlingsson, and Jay Ligatti. 2005 · 2005
Earlier work this paper cites.
Remote timing attacks are practical
David Brumley and Dan Boneh. 2005 · 2005
Earlier work this paper cites.
Preventing Memory Error Exploits with WIT. In Proceedings of the 2008 IEEE Symposium on Security and Privacy (SP ’08) . IEEE Computer Society, Washington, DC, USA, 263–277
Periklis Akritidis, Cristian Cadar, Costin Raiciu, Manuel Costa, and Miguel Castro. 2008 · 2008
Earlier work this paper cites.
The Secure Sockets Layer (SSL) Protocol Version 3.0
Alan O. Freier, Philip Karlton, and Paul C. Kocher. 2011 · 2011
Earlier work this paper cites.
Software defense: mitigating stack corruption vulnerabilties
Microsoft. 2013 · 2013
Earlier work this paper cites.
Intel Xeon Processor E5 v3 Family Uncore Performance Monitoring
Intel. 2014 · 2014
Earlier work this paper cites.
Flipping bits in memory without accessing them: An experimental study of DRAM disturbance errors. In ISCA . IEEE Press
Yoongu Kim, Ross Daly, Jeremie Kim, Chris Fallin, Ji Hye Lee, Donghyuk Lee, Chris Wilkerson, Konrad Lai, and Onur Mutlu. 2014 · 2014
Earlier work this paper cites.
Code-pointer Integrity. In Proceedings of the 11th USENIX Conference on Operating Systems Design and Implementation (OSDI’14) . USENIX Association, Berkeley, CA, USA, 147–163
Volodymyr Kuznetsov, László Szekeres, Mathias Payer, George Candea, R. Sekar, and Dawn Song. 2014 · 2014
Earlier work this paper cites.
Enforcing Forward-edge Control-flow Integrity in GCC & LLVM. In Proceedings of the 23rd USENIX Conference on Security Symposium (SEC’14) . USENIX Association, Berkeley, CA, USA, 941–955
Caroline Tice, Tom Roeder, Peter Collingbourne, Stephen Checkoway, Úlfar Erlingsson, Luis Lozano, and Geoff Pike. 2014 · 2014
Earlier work this paper cites.
The RISC-V Instruction Set Manual, Volume I: User-Level ISA, Version 2.0
Andrew Waterman, Yunsup Lee, David A. Patterson, and Krste Asanović. 2014 · 2014
Earlier work this paper cites.
FLUSH+RELOAD: A High Resolution, Low Noise, L3 Cache Side-Channel Attack. In USENIX Security Symposium
Yuval Yarom and Katrina Falkner. 2014 · 2014
Earlier work this paper cites.
ARM Cortex-A72 MPCore Processor Technical Reference Manual
ARM. 2015 · 2015
Earlier work this paper cites.
Last-Level Cache Side-Channel Attacks are Practical. In Security and Privacy . IEEE
Fangfei Liu, Yuval Yarom, Qian Ge, Gernot Heiser, and Ruby B Lee. 2015 · 2015
Cited alongside, same era.
The Spy in the Sandbox: Practical Cache Attacks in JavaScript and Their Implications. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security (CCS ’15) . ACM, New York, NY, USA, 1406–1418
Yossef Oren, Vasileios P. Kemerlis, Simha Sethumadhavan, and Angelos D. Keromytis. 2015 · 2015
Cited alongside, same era.
Jump over ASLR: Attacking Branch Predictors to Bypass ASLR. In The 49th Annual IEEE/ACM International Symposium on Microarchitecture (MICRO-49) . IEEE Press, Piscataway, NJ, USA, Article 40, 13 pages
Dmitry Evtyushkin, Dmitry Ponomarev, and Nael Abu-Ghazaleh. 2016 · 2016
Cited alongside, same era.
Windows 10 Mitigation Improvements
David Weston and Matt Miller. 2016 · 2016
Cited alongside, same era.
Analyzing Potential Bounds Check Bypass Vulnerabilities
Intel. 2018b · 2018
Closest in time.
Intel 64 and IA-32 Architectures Software Developer’s Manual, Volume 3: System Programming Guide
Intel. 2018c · 2018
Closest in time.
Speculative Execution Side Channel Mitigations. Revision 2.0
Intel. 2018d · 2018
Closest in time.
DAWG: A Defense Against Cache Timing Attacks in Speculative Execution Processors
Vladimir Kiriansky, Ilia Lebedev, Saman Amarasinghe, Srinivas Devadas, and Joel Emer. 2018 · 2018
Closest in time.
Spectre Attacks: Exploiting Speculative Execution
Paul Kocher, Daniel Genkin, Daniel Gruss, Werner Haas, Mike Hamburg, Moritz Lipp, Stefan Mangard, Thomas Prescher, Michael Schwarz, and Yuval Yarom. 2018 · 2018
Closest in time.
Speculation Documentation
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Ferdinand Brasser, Lucas Davi, David Gens, Christopher Liebchen, and Ahmad-Reza Sadeghi. 2017 · 2017
Cited alongside, same era.
KAISER: hiding the kernel from user space
Jonathan Corbet. 2017 · 2017
Cited alongside, same era.
ASLR on the Line: Practical Cache Attacks on the MMU
Ben Gras and Kaveh Razavi. 2017 · 2017
Cited alongside, same era.
Control-flow Enforcement Technology Preview
Intel. 2017a · 2017
Cited alongside, same era.
Unleashing use-before-initialization vulnerabilities in the Linux kernel using targeted stack spraying (NDSS’17)
Kangjie Lu, Marie-Therese Walter, David Pfaff, Stefan Nürnberger, Wenke Lee, and Michael Backes. 2017 · 2017
Cited alongside, same era.
Software Techniques for Managing Speculation on AMD Processors, Revision 1.24.18
Advanced Micro Devices, Inc. 2018 · 2018
Cited alongside, same era.
Introduce the "retpoline" x86 mitigation technique for variant #2 of the speculative execution vulnerabilities
Chandler Carruth. 2018a · 2018
Cited alongside, same era.
Speculative Load Hardening: A Spectre Variant #1 Mitigation Technique
Chandler Carruth. 2018b · 2018
Cited alongside, same era.
Linux Kernel. 2018 · 2018
Closest in time.
Moritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher, Werner Haas, Stefan Mangard, Paul Kocher, Daniel Genkin, Yuval Yarom, and Mike Hamburg. 2018 · 2018
Closest in time.
Add JIT mitigations for Spectre
Microsoft. 2018 · 2018
Closest in time.
MDN web docs — performance.now()
Mozilla. 2018 · 2018
Closest in time.
Spectre mitigations in MSVC
Andrew Pardoe. 2018 · 2018
Closest in time.
Cache Speculation Side-channels
Richard Grisenthwaite. 2018 · 2018
Closest in time.
Exploiting the DRAM RowHammer bug to gain kernel privileges
Mark Seaborn and Thomas Dullien. 2015 · 2018
Closest in time.
Itanium: A cautionary tale
Stephen Shankland. 2005 · 2018
Closest in time.
SpecHammer = Spectre1.1 + RowHammer
Stelios Sidiroglou-Douskos. 2018 · 2018
Closest in time.
Throwhammer: Rowhammer Attacks over the Network and Defenses. In 2018 USENIX Annual Technical Conference (USENIX ATC 18) . USENIX Association, Boston, MA
Andrei Tatar, Radhesh Krishnan Konoth, Elias Athanasopoulos, Cristiano Giuffrida, Herbert Bos, and Kaveh Razavi. 2018 · 2018
Closest in time.
Retpoline: a software construct for preventing branch-target-injection
Paul Turner. 2018 · 2018
Closest in time.
ERIM: Secure and Efficient In-process Isolation with Memory Protection Keys
Anjo Vahldiek-Oberwagner, Eslam Elnikety, Deepak Garg, and Peter Druschel. 2018 · 2018
Closest in time.
EternalBlue
Wikipedia. 2018a · 2018
Closest in time.
Memory safety — Types of memory errors
Wikipedia. 2018b · 2018
Closest in time.