News on Spectre, Meltdown and the like – systematization of x86 processor security

No ratings

Presented at IT-DefenseStuttgart 2019 by

Commercially available x86 processors are an essential component of the trusted computing base in millions of devices. At the same time, the processors’ enormous (and still increasing) complexity leads to errors and sometimes also to exploitable vulnerabilities. This presentation introduces particularly security-critical processor components and how they can be attacked, points out the characteristics of these attacks and concludes what they imply. In doing so, we look at Intel ME (Intel Management Engine), SGX (Software Guard Extensions), cloud-cache attacks and the latest varieties of Spectre & Meltdown. Finally, we will present the defense mechanisms available in each case as well as their security guarantees and effects.