Fetching the paper…
Reading the bibliography…
Recent transient-execution attacks, such as RIDL, Fallout, and ZombieLoad, demonstrated that attackers can leak information while it transits through microarchitectural buffers.
H. Akkary, J. M. Abramson, A. F. Glew, G. J. Hinton, K. G. Konigsfeld, P. D. Madland, M. S. Joshi, and B. E. Lince, “Methods and apparatus for caching data in a non-blocking manner using a plurality of fill buffers,” US Patent 5,671,444, Oct 1996
1996
Earlier work this paper cites.
——, “Cache memory system having data and tag arrays and multi-purpose buffer assembly with multiple line buffers,” US Patent 5,680,572, Jul 1996
1996
Earlier work this paper cites.
D. Coppersmith, “Small solutions to polynomial equations, and low exponent rsa vulnerabilities,” Journal of cryptology , vol. 10, no. 4, pp. 233–260, 1997
1997
Earlier work this paper cites.
C. Cowan, C. Pu, D. Maier, H. Hinton, J. Walpole, P. Bakke, S. Beattie, A. Grier, P. Wagle, and Q. Zhang, “StackGuard: Automatic adaptive detection and prevention of buffer-overflow attacks,” in USENIX Security , 1998
1998
Earlier work this paper cites.
C. Percival, “Cache missing for fun and profit,” 2005
2005
Earlier work this paper cites.
D. A. Osvik, A. Shamir, and E. Tromer, “Cache attacks and countermeasures: the case of AES,” in CT-RSA , 2006
2006
Earlier work this paper cites.
J. A. Halderman, S. D. Schoen, N. Heninger, W. Clarkson, W. Paul, J. A. Calandrino, A. J. Feldman, J. Appelbaum, and E. W. Felten, “Lest we remember: cold-boot attacks on encryption keys,” Communications of the ACM , vol. 52, no. 5, pp. 91–98, 2009
2009
Earlier work this paper cites.
N. Heninger and H. Shacham, “Reconstructing RSA private keys from random key bits,” in CRYPTO , Aug. 2009, pp. 1–17
2009
Earlier work this paper cites.
——, “Copying accelerated video decode frame buffers,” 2009. [Online]. Available: https://software.intel.com/content/www/us/en/develop/articles/copying-accelerated-video-decode-frame-buffers.html
2009
Earlier work this paper cites.
D. Gullasch, E. Bangerter, and S. Krenn, “Cache games–bringing access-based cache attacks on AES to practice,” in IEEE SP , 2011, pp. 490–505
2011
Earlier work this paper cites.
Y. Yarom and K. Falkner, “Flush+Reload: A high resolution, low noise, L3 cache side-channel attack,” in USENIX Security , 2014
2014
Earlier work this paper cites.
G. Irazoqui, T. Eisenbarth, and B. Sunar, “S$A: A shared cache attack that works across cores and defies VM sandboxing–and its application to AES,” in IEEE SP , 2015
2015
Earlier work this paper cites.
F. Liu, Y. Yarom, Q. Ge, G. Heiser, and R. B. Lee, “Last-level cache side-channel attacks are practical,” in IEEE SP , 2015
2015
Earlier work this paper cites.
Y. Xu, W. Cui, and M. Peinado, “Controlled-channel attacks: Deterministic side channels for untrusted operating systems,” in IEEE SP , 2015, pp. 640–656
2015
Earlier work this paper cites.
——, “Intel 64 and IA-32 architectures software developer’s manual,” 2016
2016
Earlier work this paper cites.
M. Kayaalp, N. Abu-Ghazaleh, D. Ponomarev, and A. Jaleel, “A high-resolution side-channel attack on last-level cache,” in DAC , 2016
2016
Earlier work this paper cites.
J. Corbet, “The current state of kernel page-table isolation,” https://lwn.net/Articles/741878/ , 2017
2017
Earlier work this paper cites.
Y. Fu, E. Bauman, R. Quinonez, and Z. Lin, “SGX-LAPD: Thwarting controlled side channel attacks via enclave verifiable page faults,” in RAID . Springer, 2017, pp. 357–380
2017
Earlier work this paper cites.
D. Gruss, M. Lipp, M. Schwarz, R. Fellner, C. Maurice, and S. Mangard, “KASLR is dead: Long live KASLR,” in International Symposium on Engineering Secure Software and Systems , 2017, pp. 161–176
2017
Cited alongside, same era.
S. Sasy, S. Gorbunov, and C. W. Fletcher, “Zerotrace: Oblivious memory primitives from intel sgx.” IACR Cryptology ePrint Archive , vol. 2017, p. 549, 2017
2017
Cited alongside, same era.
M.-W. Shih, S. Lee, T. Kim, and M. Peinado, “T-SGX: Eradicating controlled-channel attacks against enclave programs.” in NDSS , 2017
2017
Cited alongside, same era.
G. Chen, W. Wang, T. Chen, S. Chen, Y. Zhang, X. Wang, T.-H. Lai, and D. Lin, “Racing in hyperspace: Closing hyper-threading side channels on sgx with contrived data races,” in IEEE SP , 2018, pp. 178–194
2018
Cited alongside, same era.
J. Horn, “Speculative execution, variant 4: Speculative store bypass,” https://bugs.chromium.org/p/project-zero/issues/detail?id=1528 , 2018
C. Canella, J. Van Bulck, M. Schwarz, M. Lipp, B. Von Berg, P. Ortner, F. Piessens, D. Evtyushkin, and D. Gruss, “A systematic evaluation of transient execution attacks and defenses,” in USENIX Security , 2019, pp. 249–266
2019
Later among the works it cites.
G. Chen, S. Chen, Y. Xiao, Y. Zhang, Z. Lin, and T.-H. Lai, “SgxPectre: Stealing Intel secrets from SGX enclaves via speculative execution,” in Euro S&P , 2019, pp. 142–157
2019
Later among the works it cites.
——, “Deep dive: Intel analysis of microarchitectural data sampling,” https://software.intel.com/security-software-guidance/insights/deep-dive-intel-analysis-microarchitectural-data-sampling , May 2019
2019
Later among the works it cites.
——, “Deep dive: Intel transactional synchronization extensions (Intel TSX) asynchronous abort,” https://software.intel.com/security-software-guidance/insights/deep-dive-intel-transactional-synchronization-extensions-intel-tsx-asynchronous-abort , Nov 2019
2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2018
Cited alongside, same era.
Intel, “Deep dive: Intel analysis of L1 terminal fault,” https://software.intel.com/security-software-guidance/insights/deep-dive-intel-analysis-l1-terminal-fault , Aug 2018
2018
Cited alongside, same era.
——, “Deep dive: Mitigation overview for side channel exploits in Linux,” https://software.intel.com/security-software-guidance/insights/deep-dive-mitigation-overview-side-channel-exploits-linux , Jan 2018
2018
Cited alongside, same era.
2018
Cited alongside, same era.
E. M. Koruyeh, K. N. Khasawneh, C. Song, and N. Abu-Ghazaleh, “Spectre returns! speculation attacks using the return stack buffer,” in WOOT , 2018
2018
Cited alongside, same era.
M. Lipp, M. Schwarz, D. Gruss, T. Prescher, W. Haas, A. Fogh, J. Horn, S. Mangard, P. Kocher, D. Genkin, Y. Yarom, and M. Hamburg, “Meltdown: Reading kernel memory from user space,” in USENIX Security , 2018
2018
Cited alongside, same era.
G. Maisuradze and C. Rossow, “ret2spec: Speculative execution using return stack buffers,” in CCS , 2018, pp. 2109–2122
2018
Cited alongside, same era.
O. Oleksenko, B. Trach, R. Krahn, M. Silberstein, and C. Fetzer, “Varys: Protecting SGX enclaves from practical side-channel attacks,” in USENIX ATC , 2018, pp. 227–240
2018
Cited alongside, same era.
——, “Microcode revision guidance,” https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance.pdf , Aug 2019
2019
Later among the works it cites.
——, “2019.2 IPU – Intel SGX with Intel processor graphics update advisory,” https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00219.html , Nov 2019
2019
Later among the works it cites.
——, “Performance monitoring impact of Intel transactional synchronization extension memory,” https://cdrdv2.intel.com/v1/dl/getContent/604224 , Mar 2019
2019
Later among the works it cites.
S. Islam, A. Moghimi, I. Bruhns, M. Krebbel, B. Gulmezoglu, T. Eisenbarth, and B. Sunar, “SPOILER: Speculative load hazards boost Rowhammer and cache attacks,” in USENIX Security , 2019, pp. 621–637
2019
Later among the works it cites.
P. Kocher, J. Horn, A. Fogh, , D. Genkin, D. Gruss, W. Haas, M. Hamburg, M. Lipp, S. Mangard, T. Prescher, M. Schwarz, and Y. Yarom, “Spectre attacks: Exploiting speculative execution,” in IEEE SP , 2019
2019
Later among the works it cites.
A. Lutas and D. Lutas, “Security implications of speculatively executing segmentation related instructions on Intel CPUs,” https://businessresources.bitdefender.com/hubfs/noindex/Bitdefender-WhitePaper-INTEL-CPUs.pdf , Aug 2019
2019
Later among the works it cites.
M. Schwarz, M. Lipp, D. Moghimi, J. Van Bulck, J. Stecklina, T. Prescher, and D. Gruss, “ZombieLoad: Cross-privilege-boundary data sampling,” in CCS , 2019
2019
Later among the works it cites.
S. van Schaik, A. Milburn, S. Österlund, P. Frigo, G. Maisuradze, K. Razavi, H. Bos, and C. Giuffrida, “Rogue in-flight data load,” in IEEE SP , 2019
2019
Later among the works it cites.
——, “L1d eviction sampling,” https://software.intel.com/security-software-guidance/software-guidance/l1d-eviction-sampling , Jan 2020
2020
Closest in time.
D. Moghimi, M. Lipp, B. Sunar, and M. Schwarz, “Medusa: Microarchitectural data leakage via automated attack synthesis,” in 29th USENIX Security Symposium (USENIX Security 20) . Boston, MA: USENIX Association, Aug. 2020. [Online]. Available: https://www.usenix.org/conference/usenixsecurity20/presentation/moghimi-medusa
2020
Closest in time.
K. Murdock, D. Oswald, F. D. Garcia, J. Van Bulck, D. Gruss, and F. Piessens, “Plundervolt: Software-based fault injection attacks against Intel SGX,” in 2020 IEEE Symposium on Security and Privacy (SP) , 2020
2020
Closest in time.
J. Van Bulck, D. Moghimi, M. Schwarz, M. Lipp, M. Minkin, D. Genkin, Y. Yuval, B. Sunar, D. Gruss, and F. Piessens, “LVI: Hijacking Transient Execution through Microarchitectural Load Value Injection,” in 41th IEEE Symposium on Security and Privacy (S&P’20) , 2020
2020
Closest in time.
S. van Schaik, A. Kwong, D. Genkin, and Y. Yarom, “SGAxe: How sgx fails in practice,” https://cacheoutattack.com/ , 2020
2020
Closest in time.