To Fight Spectre-Like Attacks, Intel Suggests a New Kind of Memory

Peter Reutemann <[email protected]> Mon, 7 Oct 2019 10:32:34 +1300
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12Jr0iBxZSZmPQ6uc1JCg=Zd_FkT2MApk8cE2QrnkS11_g@mail.gmail.com>
'Intel researchers published a paper last week suggesting a new kind
of CPU memory to block side-channel attacks like Meltdown and Spectre,
according to ZDNet:

SAPM -- or Speculative-Access Protected Memory -- is the work of Intel
STORM (STrategic Offensive Research & Mitigations), a team of elite
security researchers that Intel assembled since 2017 to work on
creating mitigations for all the speculative-execution attacks that
have impacted the CPU maker's products. SAPM is only an idea for the
moment, and there are no silicon prototypes. Intel STORM engineers
only released "the theory and possible implementation options," to
provide "a ground base for other researchers to improve upon and also
for the industry to consider...."

Intel STORM researchers say SAPM will implement protections at the
hardware level and will work with both physical and virtual memory
addresses. "SAPM can be applied to specific memory ranges, with the
attribute that any memory access to such memory type will be
instruction-level serialized, meaning that any speculative execution
beyond the SAPM-accessing instruction will be stopped pending the
successful retirement of this SAPM-accessing instruction," Intel STORM
developers said in their short description of SAPM's basic
principles...

Intel STORM researchers say the second part (backend) of most
speculative execution attacks performs the same actions. SAPM was
designed to introduce hardware-based protections against the backend
part of most attacks. It's because of this concept that Intel's
research team believes that SAPM will also future-proof the next
generations of Intel CPUs against other -- currently undiscovered --
speculative execution attacks.

"Intel STORM researchers don't deny that there's a performance hit,"
the article adds. "However, this impact is low and could be mitigated
further by dropping other existing protections."'

-- source: https://hardware.slashdot.org/story/19/10/05/0315201

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list -- [email protected] | To unsubscribe send an email to [email protected]
Unsubscribe: https://list.waikato.ac.nz/postorius/lists/wlug.list.waikato.ac.nz