README.md

October 12, 2021 ยท View on GitHub

AMD Prefetch Attacks through Power and Time

This repository contains several experiments and proof-of-concepts for the AMD Prefetch Attacks through Power and Time paper. For more technical information, please refer to the paper:

Prerequisites

The individual proof-of-concept implementations are self-contained and come with a Makefile and an individual description that explains how to build, run and interpret the proof-of-concept.

In order to run the proof-of-concepts, the following prerequisites need to be fulfilled:

Throughout our experiments, we successfully evaluated our implementations on the following CPUs. However, most of the implementation should work on CPUs with the same microarchitecture.

CPUMicrocodeMicroarchitecture
AMD Ryzen 5 2500 U0x810100bZen
AMD Ryzen Threadripper 1920X0x8001137Zen
AMD Ryzen 5 36000x8701021Zen 2
AMD Ryzen 7 3700X0x8701021Zen 2
AMD A10-7870K0x6003106Steamroller
AMD EPYC 7402P0x830104dZen
AMD EPYC 75710x800126cZen

Proof-of-Concepts

The follow tables give an overview of all artifacts provided in this repository. Each folder contains an additional description explaining how to build, run and interpret the artifact.

Leakage Analysis Primitives

NameDescription
Page Table Level
TLB State
Stalling
Retirement

Case Studies

NameDescription
KASLR BreakKernel Address Space Derandomization using Energy Consumption or the Execution Time of the prefetch instruction
Leaking Kernel Memory with SpectreCombination of TLB-Evict+Prefetch and a Spectre Gadget to leak kernel memory