AsyncShock: Exploiting Synchronisation Bugs in Intel SGX Enclaves
File(s)esorics2016 (1).pdf (510.38 KB)
Accepted version
Author(s)
Pietzuch, PR
Weichbrodt, N
Kurmus, A
Kurmus,, R
Type
Conference Paper
Abstract
Intel’s Software Guard Extensions (SGX) provide a new hardware-based trusted execution environment on Intel CPUs using secure enclaves that are resilient to accesses by privileged code and physical attackers. Originally designed for securing small services, SGX bears promise to protect complex, possibly cloud-hosted, legacy applications. In this paper, we show that previously considered harmless synchronisation bugs can turn into severe security vulnerabilities when using SGX. By exploiting use-after-free and time-of-check-to-time-of-use (TOCTTOU) bugs in enclave code, an attacker can hijack its control flow or bypass access control.
We present AsyncShock, a tool for exploiting synchronisation bugs of multithreaded code running under SGX. AsyncShock achieves this by only manipulating the scheduling of threads that are used to execute enclave code. It allows an attacker to interrupt threads by forcing segmentation faults on enclave pages. Our evaluation using two types of Intel Skylake CPUs shows that AsyncShock can reliably exploit use-after-free and TOCTTOU bugs.
We present AsyncShock, a tool for exploiting synchronisation bugs of multithreaded code running under SGX. AsyncShock achieves this by only manipulating the scheduling of threads that are used to execute enclave code. It allows an attacker to interrupt threads by forcing segmentation faults on enclave pages. Our evaluation using two types of Intel Skylake CPUs shows that AsyncShock can reliably exploit use-after-free and TOCTTOU bugs.
Date Issued
2016-09-15
Date Acceptance
2016-07-12
Citation
Lecture Notes in Computer Science - Computer Security – ESORICS 2016, 2016, 9878, pp.440-457
ISBN
978-3-319-45743-7
ISSN
0302-9743
Publisher
Springer International Publishing
Start Page
440
End Page
457
Journal / Book Title
Lecture Notes in Computer Science - Computer Security – ESORICS 2016
Volume
9878
Copyright Statement
© Springer International Publishing Switzerland 2016. The final publication is available at Springer via http://dx.doi.org/10.1007/978-3-319-45744-4_22
Sponsor
Commission of the European Communities
Grant Number
645011
Source
21st European Symposium on Research in Computer Security (ESORICS)
Subjects
Artificial Intelligence & Image Processing
08 Information And Computing Sciences
Publication Status
Published
Start Date
2016-09-28
Finish Date
2016-09-30
Coverage Spatial
Heraklion, Greece