Institute of Information Engineering Chinese Academy of Sciences
被引用0|浏览0
摘要
The disclosure of Spectre and Meltdown vulnerabilities has significantly challenged processor security, exposing inherent flaws in microarchitectural design and revealing the limitations of existing countermeasures. Despite extensive mitigation efforts, completely preventing information leakage resulting from speculative execution continues to pose a significant challenge. A significant gap remains in the lack of a quantitative evaluation framework that rigorously assesses the effectiveness of these mitigation strategies. In this research, the SPECTECTOR analytical framework is utilized to introduce two novel quantitative metrics: Relative Leakage Entropy (RLE) and Normalized Conditional Entropy (NCE). These metrics are designed to evaluate the relative information leakage between speculative and non-speculative execution traces, providing distinct insights on leakage quantification. By utilizing these metrics to assess 15 example programs compiled with Intel ICC and CLANG compilers across different optimization levels and mitigation strategies, the analysis reveals that compiler optimization strategies markedly affect the magnitude of information leakage. The results indicate that, despite advanced mitigation techniques, substantial information leakage persists, highlighting the need for more effective security architectures in future processors and software systems.