The Impact of Meltdown and Spectre Attacks

The Impact of Meltdown and Spectre Attacks

Two vulnerabilities which are meltdown and spectre have been detected recently. They are used to capturing data on computer or smartphones by attackers. Vulnerabilities are part of the hardware design of the processor. The only thing is changing the processor to get rid of these vulnerabilities. There are some fixes from manufacturer of OS and BIOS which are trying to fix exploits. In this paper, detailed analysis will be performed for the personal and business impact of meltdown and spectre vulnerabilities.

___

  • Bright, P. (2018, 1 5). Meltdown and Spectre: Here’s what Intel, Apple, Microsoft, others are doing about it. Retrieved from ARS TECHNICA: https://arstechnica.com/gadgets/2018/01/meltdown-and-spectre-heres-what-intel-apple-microsoft-others-are-doing-about-it/
  • Trendmicro, (2018). Detecting Attacks that Exploit Meltdown and Spectre with Performance Counters. (2018, March 13). Retrieved from Trend Micro: https://blog.trendmicro.com/trendlabs-security-intelligence/detecting-attacks-that-exploit-meltdown-and-spectre-with-performance-counters/
  • Francis, R. (2018). How the Meltdown and Spectre bugs work and what you can do to prevent a performance plummet. Ellexus.
  • Grisenthwaite, R. (2018). Cache Speculation Side-channels. arm.
  • Gruss, D., Lipp, M., Schwarz, M., Fellner, R., Maurice, C., & Mangard, S. (2017). Kaslr is dead: long live kaslr. International Symposium on Engineering Secure Software and Systems, 161-176.
  • Innus, M. D., Simakov, N. A., Jones, M. D., White, J. P., Gallo, S. M., DeLeon, R. L., & Furlani, T. R. (2018). Effect of Meltdown and Spectre Patches on the Performance of HPC Applications. arXiv preprint arXiv:1801.04329.
  • Intel. (2018). Intel Analysis of Speculative Execution Side Channels.
  • Kocher, P., Genkin, D., Gruss, D., Haas, W., Hamburg, M., Lipp, M., . . . Yarom, Y. (2018). Spectre Attacks: Exploiting Speculative Execution. arXiv preprint arXiv:1801.01203.
  • Lipp, M., Schwarz, M., Gruss, D., Prescher, T., Haas, W., Mangard, S., . . . Hamburg, M. (2018). Meltdown. arXiv preprint arXiv:1801.01207.
  • Meltdown. (2018). Meltdown and Spectre. (n.d.). Retrieved from Meltdown Attack: https://meltdownattack.com/
International Journal of Multidisciplinary Studies and Innovative Technologies-Cover
  • ISSN: 2602-4888
  • Yayın Aralığı: Yılda 2 Sayı
  • Başlangıç: 2017
  • Yayıncı: SET Teknoloji