Pasquale Convertini
A large scale analysis of cloud providers against transient execution attacks.
Rel. Antonio Lioy. Politecnico di Torino, Corso di laurea magistrale in Ingegneria Informatica (Computer Engineering), 2020
Abstract
Modern CPU optimizations such as branch prediction and out-of-order execution are fundamental for performance and are widely adopted by almost all CPU vendors. Recent research works showed, however, how transient execution attacks could exploit these CPU performance optimization solutions to retrieve secrets leveraging secret-dependent traces left in the microarchitectural state of the CPU. New classes of attacks, as Meltdown and Spectre, have been built on top of this new class of vulnerabilities. Mitigations have been developed both at CPU and OS level, but some of these can provoke a significant performance drop not acceptable in some computing domains. Therefore these mitigations are not always enabled or enforced in both the kernel space and user space, leaving the machine vulnerable to some extent.
Particular requirements in terms of performance are nowadays demanded to the cloud providers, which offer high computation power to the IT industry
Relatori
Anno Accademico
Tipo di pubblicazione
Numero di pagine
Informazioni aggiuntive
Corso di laurea
Classe di laurea
Ente in cotutela
Aziende collaboratrici
URI
![]() |
Modifica (riservato agli operatori) |
