Software protection against the LVI attack proposed by Google showed a 14-fold decrease in performance

Zola Bridges from Google a propus for the LLVM compiler set patch with the implementation of SESES (Speculative Execution Side Effect Suppression) protection, helping to block attacks on Intel CPU speculative execution mechanisms, similar to LVI. The protection method is implemented at the compiler level and is based on the compiler adding instructions LFENCE, which are placed before each memory read or write instruction, as well as before the first branching instruction in the group of instructions that completes a block.

The LFENCE instruction waits for all previous memory read operations to complete and prevents speculative execution of subsequent instructions after LFENCE until the completion of the fixation. The use of LFENCE leads to a significant decrease in performance, so the protection is recommended to be used in critical code scenarios. In addition to full protection, the patch offers three flags that allow selective disabling of certain protection levels to reduce negative performance impact.

In tests conducted, the use of SESES protection for the BoringSSL package led to a decrease in the number of operations performed by the library per second by 14 times — the performance of the protected version of the library averaged only 7.1% of the unprotected version's metrics (ranging from 4% to 23%, depending on the test).

Pentru comparație, propus earlier for the GNU Assembler, the mechanism that substitutes LFENCE after each memory load operation and before certain branching instructions showed a performance decrease of about 5 times (22% of the code without protection). The protection method was also sub licența MIT. Instrumentul utilizează metode de învățare automată, împreună cu analiza statică și dinamică a codului JavaScript. Se afirmă că utilizarea învățării automate a permis îmbunătățirea semnificativă a preciziei în identificarea codului pentru identificarea ascunsă și a identificat cu 26% mai multe scripturi problematice și a fost implementat engineered by Intel, but performance testing results for it have not yet been published. Initially, researchers who identified the LVI attack predicted a performance drop of 2-19 times with full protection.

Sursa: opennet.ro

Cumpără un hosting fiabil pentru site-uri cu protecție DDoS, servere VPS VDS 🔥 Cumpără un hosting fiabil pentru site-uri cu protecție DDoS, servere VPS VDS | ProHoster