The drive to create thinner, lighter, and more energy efficient devices has resulted in modern SoCs being forced to balance a delicate tradeoff between power consumption, heat dissipation, and execution speed (i.e., frequency). While beneficial, these DVFS mechanisms have also resulted in software-visible hybrid side-channels, which use software to probe analog properties of computing devices. Such hybrid attacks are an emerging threat that can bypass countermeasures for traditional microarchitectural side-channel attacks. Given the rise in popularity of both Arm SoCs and GPUs, in this paper we investigate the susceptibility of these devices to information leakage via power, temperature and frequency, as measured via internal sensors. We demonstrate that the sensor data observed correlates with both instructions executed and data processed, allowing us to mount software-visible hybrid side-channel attacks on these devices. To demonstrate the real-world impact of this issue, we present JavaScript-based pixel stealing and history sniffing attacks on Chrome and Safari, with all side channel countermeasures enabled. Finally, we also show website fingerprinting attacks, without any elevated privileges.
翻译:为打造更薄、更轻、更节能的设备,现代SoC被迫在功耗、散热与执行速度(即频率)之间权衡利弊。虽然这些DVFS机制有益,但也催生了软件可见的混合侧信道,这类攻击利用软件探测计算设备的模拟特性。作为新兴威胁,混合攻击能绕过传统微架构侧信道攻击的防御措施。鉴于Arm SoC与GPU的广泛普及,本文通过内部传感器测量,研究了这些设备在功率、温度与频率方面信息泄露的敏感性。我们证实所观测的传感器数据与执行的指令及处理的数据均存在相关性,从而能对设备实施软件可见的混合侧信道攻击。为展示该问题的实际影响,我们在Chrome和Safari浏览器上启用了所有侧信道防御措施后,展示了基于JavaScript的像素窃取与历史嗅探攻击。最后,我们还展示了无需任何高级权限即可实施的网站指纹识别攻击。