Just-in-time, or JIT, compilation could be considered a fundamental backbone of modern computing. JIT compilation turns scripting languages like JavaScript or intermediary binary forms like Web Assembly into native code on the fly, giving web apps, and things that are web apps under the covers like Electron-based tools, near native speed. A new paper explores leveraging JIT systems to revive Spectre-v2 attacks against processors.
Most modern processors gain performance by using a trick called “speculative execution”. The processor guesses the likely result of a compare, and begins executing some of the next instructions before the results are actually known. If the processor guessed right, things continue and there is a speed gain because it can jump ahead, but if the processor guessed wrong, any instructions that were run and any side effects of running them are discarded and execution resumes on the actual path. In theory, anyhow.
In practice, the Spectre class of attacks targets branch prediction. It was discovered that when the wrong branch was chosen, not all of the results were truly hidden; Patterns of failures in guessing branches can be used to leak behavior processing encryption keys and other activities. The attacks evolved with the research dubbed Spectre-V2, which showed that non-privileged contexts, like non-root users and virtual machines, could poison the instruction prediction and use it to read arbitrary memory. Fixes to the Linux kernel and other platforms were required to mitigate the worst of the effects.
The paper shows that by using self-modifying code in the JIT, the processor can be tricked into loading cached versions of the instructions. The fixes to the kernel to prevent Spectre attacks include identifying malicious code patterns that attack the branch prediction, and stopping or changing them: By causing the CPU to execute the cached copy of instructions instead of the live copy, the attack ignores the fixed instructions entirely and can attack the branch prediction algorithm.
To prove the attack is feasible in the real world, the researchers targeted several JIT compilers, including the SpiderMonkey JavaScript engine used by Firefox, the eBPF JIT found in the Linux kernel, and GraalVM, the JIT used in Python. They found success with each, demonstrating that the attack is at least plausible.
Research like this is unlikely to be an instant world-melter, and will help find possible mitigations in the future to prevent these sorts of attacks. Operating systems that support a high-security “lock-down” mode, like macOS and iOS, often disable JIT entirely, out of concern about these sorts of attacks. There’s probably no need to start disabling JIT on every system, but attacks like these have a tendency to evolve.
Continue reading “This Week In Security: New Spectre Attacks, Crushing Quantity Of Linux Vulns, Google Gets Too Much AI, And Hacking Lawnmowers” →