{"id":110821,"date":"2020-11-11T21:45:47","date_gmt":"2020-11-11T18:45:47","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/platypus-reveals-new-vulnerabilities-discovered-in-intel-processors\/"},"modified":"2020-11-11T21:45:47","modified_gmt":"2020-11-11T18:45:47","slug":"platypus-reveals-new-vulnerabilities-discovered-in-intel-processors","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/platypus-reveals-new-vulnerabilities-discovered-in-intel-processors\/","title":{"rendered":"#PLATYPUS reveals new vulnerabilities discovered in Intel processors"},"content":{"rendered":"<p>&#8220;<strong>#PLATYPUS reveals new vulnerabilities discovered in Intel processors<\/strong>&#8221;<\/p>\n<div>\n<div class=\"article-gallery lightGallery\">\n<div data-thumb=\"https:\/\/scx1.b-cdn.net\/csz\/news\/tmb\/2020\/platypusreve.jpg\" data-src=\"https:\/\/scx2.b-cdn.net\/gfx\/news\/2020\/platypusreve.jpg\" data-sub-html=\"Credit: University of Birmingham\">\n<figure class=\"article-img\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/scx1.b-cdn.net\/csz\/news\/800\/2020\/platypusreve.jpg\" alt=\"PLATYPUS reveals new vulnerabilities discovered in Intel processors\" title=\"Credit: University of Birmingham\" width=\"617\" height=\"457\"\/><figcaption class=\"text-darken text-low-up text-truncate-js text-truncate mt-3\">\n                Credit: University of Birmingham<br \/>\n            <\/figcaption><\/figure>\n<\/div>\n<\/div>\n<p>An international team of security researchers, including experts from the University of Birmingham, is presenting new side-channel attacks, which use fluctuations in software power consumption to access sensitive data on Intel CPUs.<\/p>\n<p>                                                                                Power side-channel attacks are attacks that exploit fluctuations in power consumption to extract sensitive data such as cryptographic keys. Because power measurements by malware were previously very inaccurate, such attacks required physical access to the target device and special measurement tools such as an oscilloscope.<\/p>\n<p>The project, called<a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/platypusattack.com\/\"> PLATYPUS<\/a>, is led by the Institute of <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">App<\/a>lied Information Processing and Communications at Graz University of <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/technology\/\" data-internallinksmanager029f6b8e52c=\"4\" title=\"Technology\" target=\"_blank\" rel=\"noopener\">Technology<\/a> together with the University of Birmingham, UK and the Helmholtz Center for Information Security (CISPA), shows a method that allows power side-channel attacks that can access sensitive data with unprecedented accuracy\u2014even without physical access.<\/p>\n<p>The team have demonstrated their method can affect devices including desktop PCs, laptops and cloud computing servers from Intel and AMD.<\/p>\n<p>Dr. David Oswald, senior lecturer in Cyber Security at the University of Birmingham, says: &#8220;PLATYPUS attacks show that power side channels\u2014which were previously only relevant to small embedded devices like payment cards\u2014are a relevant threat to processors in our laptops and servers. Our work connects the dots between two research areas and highlights that power side channel leakage has much wider relevance than previously thought.&#8221;<\/p>\n<p><b>RAPL interface and SGX enclaves as key <\/b><\/p>\n<p>The researchers used two key approaches. In the first, they used the RAPL interface (running average power limit), which is built into Intel and AMD CPUs. This interface monitors the energy consumption in the devices and ensures that they don&#8217;t overheat or consume too much power. RAPL has been configured so that power consumption can be logged even without administrative rights. This means that the measured values can be read out without any authorizations. <\/p>\n<p>In the second approach, the group misuses Intel&#8217;s security function Software Guard Extensions (SGX). This functionality moves data and critical programs to an isolated environment (called an enclave) where they are secure\u2014even if the normal operating system is already compromised by malware.<\/p>\n<p><b>Combination leads to (un)desired result<\/b><\/p>\n<p>The researchers combined these two techniques in their methods of attack. Using a compromised operating system targeting Intel SGX, they made the processor execute certain instructions tens of thousands of times within an SGX enclave. The power consumption of each of these commands was measured via the RAPL interface. The fluctuations in the measured values finally allow to reconstruct data and cryptographic keys.<\/p>\n<p>In further scenarios, the researchers also show that even attackers without administrative rights can attack the operating system and steal secret data from it.<\/p>\n<p><b>New security updates resolve the threat<\/b><\/p>\n<p>The TU Graz computer scientists Moritz Lipp, Andreas Kogler and Daniel Gruss together with their ex-colleague Michael Schwarz (researching at CISPA in Saarbr\u00fccken since summer 2020) and with David Oswald from the University of Birmingham informed Intel about their discoveries in November 2019. The company has now developed solutions that users should definitely adopt. A security update for operating systems permits access to the RAPL measurement functions only with administrator rights. And further updates for the affected processors themselves ensure that the power consumption is returned in such a way that the subtle differences in the power consumption of programs are no longer visible.\n                                                                                                                        <\/p>\n<hr\/>\n<div class=\"article-main__explore my-4 d-print-none\">\n<p>                                            Reports: Intel chips have new security flaws\n                                        <\/p><\/div>\n<hr class=\"mb-4\"\/>\n<div class=\"d-inline-block text-medium my-4\">\n                                                Provided by<br \/>\n                                                                                                    University of Birmingham<br \/>\n                                                                                                        <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" class=\"icon_open\" href=\"http:\/\/www.bham.ac.uk\/\"><br \/>\n                                                        <svg><use href=\"https:\/\/techx.b-cdn.net\/tmpl\/v2\/img\/svg\/sprite.svg#icon_open\" x=\"0\" y=\"0\"\/><\/svg><\/a><\/p><\/div>\n<p>                                        <!-- print only --><\/p>\n<div class=\"d-none d-print-block\">\n<p>                                                 <strong>Citation<\/strong>:<br \/>\n                                                 PLATYPUS reveals new vulnerabilities discovered in Intel processors (2020, November 11)<br \/>\n                                                 retrieved 12 November 2020<br \/>\n                                                 from https:\/\/techxplore.com\/<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">news<\/a>\/2020-11-platypus-reveals-vulnerabilities-intel-processors.html<\/p>\n<p>                                            This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no<br \/>\n                                            part may be reproduced without the written permission. The content is provided for information purposes only.<\/p><\/div>\n<\/p><\/div>\n<p><script id=\"facebook-jssdk\" async=\"\" src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js\"><\/script><\/p>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more Like this articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/science\/\" target=\"_blank\" rel=\"noopener noreferrer\">Science category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/techxplore.com\/news\/2020-11-platypus-reveals-vulnerabilities-intel-processors.html\" target=\"_blank\" rel=\"noopener noreferrer\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#PLATYPUS reveals new vulnerabilities discovered in Intel processors&#8221; Credit: University of Birmingham An international team of security researchers, including experts from the University of Birmingham, is presenting new side-channel attacks, which use fluctuations in software power consumption to access sensitive data on Intel CPUs. Power side-channel attacks are attacks that exploit fluctuations in power consumption&#8230;<\/p>\n","protected":false},"author":1,"featured_media":110822,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/scx2.b-cdn.net\/gfx\/news\/2020\/platypusreve.jpg","fifu_image_alt":"","footnotes":""},"categories":[16],"tags":[],"class_list":["post-110821","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sciencee"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/110821","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=110821"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/110821\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/110822"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=110821"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=110821"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=110821"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}