Researchers at the Massachusetts Institute of Technology (MIT) CSAIL have discovered a new type of attack capable of bypassing the security mechanisms of modern processors. Known as the 'TONTOU' attack, it exploits a temporary vulnerability in processors' predictive mechanisms, allowing attackers to access sensitive information.
The study, led by Daniël Trujillo and Mengjia Yan, highlighted that one of the keys to processor speed is their predictive ability. This mechanism enables processors to anticipate program execution paths, saving time. However, if the prediction is incorrect, the unnecessary work is discarded, but traces remain that attackers can exploit.
The researchers successfully demonstrated the attack on both Intel and AMD processors, where they managed to obtain Linux system password files. In the case of AMD processors, a protection called 'saferet' left a two-instruction-wide vulnerable window that the researchers exploited. For Intel processors, the protection varied across generations, indicating that manufacturers implement security mechanisms differently.
The findings were presented at the Black Hat USA and USENIX Security conferences, and the researchers have already notified the affected manufacturers and Linux kernel maintainers. AMD has released a patch that reduces the attack's effectiveness, which users can access by updating their operating systems.
The research was partially supported by the U.S. Air Force Office of Scientific Research and the DARPA-funded JUMP 2.0 program.
Such attacks underscore the necessity for continuous improvements in hardware security to protect modern computer systems.
Sources:
Scientists turn DNA into a memory device that uses 100x less power
New type of attack can slip past the defenses in your computer’s processor
31 years later, beautiful SNES RPG Terranigma is finally coming to PC, and I must lay the ghost of my console warrior childhood to rest
Comments