{"id":104811,"date":"2022-08-11T03:36:41","date_gmt":"2022-08-11T01:36:41","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/aepic-leak-ataka-privodyashhaya-k-utechke-klyuchej-iz-anklavov-intel-sgx"},"modified":"2022-08-11T03:36:41","modified_gmt":"2022-08-11T01:36:41","slug":"aepic-leak-ataka-privodyashhaya-k-utechke-klyuchej-iz-anklavov-intel-sgx","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/aepic-leak-ataka-privodyashhaya-k-utechke-klyuchej-iz-anklavov-intel-sgx","title":{"rendered":"AEPIC Leak \u2014 attacco che porta a una fuga di chiavi dagli enclavi Intel SGX","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Sono emerse informazioni su un nuovo attacco ai processori Intel \u2014 AEPIC Leak (CVE-2022-21233), che porta a una fuga di dati riservati da enclave isolate Intel SGX (Software Guard eXtensions). Il problema coinvolge i processori Intel di 10\u00aa, 11\u00aa e 12\u00aa generazione (compresi i nuovi modelli Ice Lake e Alder Lake) ed \u00e8 causato da un difetto architetturale che consente l'accesso a dati non inizializzati rimasti nei registri APIC (Advanced Programmable Interrupt Controller) dopo l'esecuzione di operazioni precedenti.     <\/p>\n<p>A differenza degli attacchi di tipo Spectre, la fuga di dati nell'AEPIC Leak avviene senza l'uso di metodi di recupero tramite canali alternativi \u2014 le informazioni riservate vengono trasferite direttamente attraverso la lettura del contenuto dei registri, riflessi nella pagina di memoria MMIO (memory-mapped I\/O). In sintesi, l'attacco consente di determinare i dati trasmessi tra le cache di secondo e ultimo livello, inclusi il contenuto dei registri e i risultati delle operazioni di lettura dalla memoria, che erano stati precedentemente elaborati dallo stesso core della CPU.     <\/p>\n<p>Poich\u00e9 per attuare l'attacco \u00e8 necessario avere accesso alle pagine fisiche APIC MMIO, cio\u00e8 sono necessari privilegi da amministratore, il metodo \u00e8 limitato all'attacco agli enclave SGX, ai quali l'amministratore non ha accesso diretto. I ricercatori hanno sviluppato uno strumento che consente di identificare in pochi secondi le chiavi AES-NI e RSA memorizzate in SGX, oltre alle chiavi di attestazione Intel SGX e ai parametri del generatore di numeri pseudo-casuali. Il codice per eseguire l'attacco \u00e8 stato pubblicato su GitHub.     <\/p>\n<p>La Intel ha dichiarato di essere in procinto di rilasciare una correzione sotto forma di aggiornamento del microcodice, che implementa il supporto per la pulizia dei buffer e aggiunge ulteriori misure per proteggere i dati degli enclave. \u00c8 stato inoltre preparato un nuovo rilascio del SDK per Intel SGX con modifiche che prevengono le fuoriuscite di dati. Gli sviluppatori di sistemi operativi e hypervisor sono stati consigliati di utilizzare, al posto del vecchio modo xAPIC, il modo x2APIC, nel quale per accedere ai registri APIC vengono utilizzati i registri MSR invece di MMIO.<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=57623\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043d\u043e\u0432\u043e\u0439 \u0430\u0442\u0430\u043a\u0435 \u043d\u0430 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u044b Intel &#8212; AEPIC Leak (CVE-2022-21233), \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0435\u0439 \u043a \u0443\u0442\u0435\u0447\u043a\u0435 \u043a\u043e\u043d\u0444\u0438\u0434\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0438\u0437 \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u0430\u043d\u043a\u043b\u0430\u0432\u043e\u0432 Intel SGX (Software Guard eXtensions). \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 10, 11 \u0438 12 \u043f\u043e\u043a\u043e\u043b\u0435\u043d\u0438\u044f CPU Intel (\u0432\u043a\u043b\u044e\u0447\u0430\u044f \u043d\u043e\u0432\u044b\u0435 \u0441\u0435\u0440\u0438\u0438 Ice Lake \u0438 Alder Lake) \u0438 \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u0430\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u0443\u0440\u043d\u043e\u0439 \u043d\u0435\u0434\u043e\u0440\u0430\u0431\u043e\u0442\u043a\u043e\u0439, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043d\u0435\u0438\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c \u0434\u0430\u043d\u043d\u044b\u043c, \u043e\u0441\u0442\u0430\u0432\u0448\u0438\u043c\u0441\u044f \u0432 \u0440\u0435\u0433\u0438\u0441\u0442\u0440\u0430\u0445 APIC [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-104811","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043d\u043e\u0432\u043e\u0439 \u0430\u0442\u0430\u043a\u0435 \u043d\u0430 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u044b Intel - AEPIC Leak (CVE-2022-21233), \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0435\u0439 \u043a \u0443\u0442\u0435\u0447\u043a\u0435 \u043a\u043e\u043d\u0444\u0438\u0434\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0438\u0437 \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u0430\u043d\u043a\u043b\u0430\u0432\u043e\u0432 Intel SGX (Software Guard eXtensions).\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/aepic-leak-ataka-privodyashhaya-k-utechke-klyuchej-iz-anklavov-intel-sgx\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47AEPIC Leak \u2014 \u0430\u0442\u0430\u043a\u0430, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0443\u0442\u0435\u0447\u043a\u0435 \u043a\u043b\u044e\u0447\u0435\u0439 \u0438\u0437 \u0430\u043d\u043a\u043b\u0430\u0432\u043e\u0432 Intel SGX | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043d\u043e\u0432\u043e\u0439 \u0430\u0442\u0430\u043a\u0435 \u043d\u0430 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u044b Intel - AEPIC Leak (CVE-2022-21233), \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0435\u0439 \u043a \u0443\u0442\u0435\u0447\u043a\u0435 \u043a\u043e\u043d\u0444\u0438\u0434\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0438\u0437 \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u0430\u043d\u043a\u043b\u0430\u0432\u043e\u0432 Intel SGX (Software Guard eXtensions).\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/aepic-leak-ataka-privodyashhaya-k-utechke-klyuchej-iz-anklavov-intel-sgx\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-08-11T01:36:41+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-08-11T01:36:41+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47AEPIC Leak \u2014 attacco che porta alla fuoriuscita di chiavi dagli enclave Intel SGX | ProHoster","description":"Sono emerse informazioni su un nuovo attacco ai processori Intel - AEPIC Leak (CVE-2022-21233), che porta alla fuoriuscita di dati riservati dagli enclave isolati Intel SGX (Software Guard eXtensions).","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/aepic-leak-ataka-privodyashhaya-k-utechke-klyuchej-iz-anklavov-intel-sgx","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47AEPIC Leak \u2014 \u0430\u0442\u0430\u043a\u0430, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0443\u0442\u0435\u0447\u043a\u0435 \u043a\u043b\u044e\u0447\u0435\u0439 \u0438\u0437 \u0430\u043d\u043a\u043b\u0430\u0432\u043e\u0432 Intel SGX | ProHoster","og:description":"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e \u043d\u043e\u0432\u043e\u0439 \u0430\u0442\u0430\u043a\u0435 \u043d\u0430 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0440\u044b Intel - AEPIC Leak (CVE-2022-21233), \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0435\u0439 \u043a \u0443\u0442\u0435\u0447\u043a\u0435 \u043a\u043e\u043d\u0444\u0438\u0434\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0438\u0437 \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u0430\u043d\u043a\u043b\u0430\u0432\u043e\u0432 Intel SGX (Software Guard eXtensions).","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/aepic-leak-ataka-privodyashhaya-k-utechke-klyuchej-iz-anklavov-intel-sgx","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-08-11T01:36:41+00:00","article:modified_time":"2022-08-11T01:36:41+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"104811","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-08-11 01:37:52","updated":"2022-10-01 23:35:37","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/104811","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=104811"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/104811\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=104811"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=104811"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=104811"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}