SearcharxivSearch

arXiv subjects

Ahmad Ibrahim

Publications and source records attributed to Ahmad Ibrahim.

4 recordsLinked to original sources

Jump-starting relativistic flows, and the M87 jet

We point out the dominant importance of plasma injection effects for relativistic winds from pulsars and black holes. We demonstrate that outside the light cylinder the magnetically dominated outflows while sliding along the helical magnetic field move in fact nearly radially with very large Lorentz factors $γ_0 \gg 1 $, imprinted into the flow during pair production within the gaps. Only at larger distances, $r \geq γ_0 (c/Ω)$, the MHD acceleration $Γ\propto r$ takes over. As a result, Blandford-Znajek (BZ) driven outflows would produce spine-brightened images. The best-resolved case of the jet in M87 shows both bright edge-brightened features, as well as weaker spine-brightened feature. Only the spine-brightened component can be BZ-driven/originate from the BH's magnetosphere.

astro-ph.HE

Leasing the Cloud-Edge Continuum, à la Carte

Next-gen computing paradigms foresee deploying applications to virtualised resources along a continuum of Cloud-Edge nodes. Much literature focussed on how to place applications onto such resources so as to meet their requirements. To lease resources to application operators, infrastructure providers need to identify a portion of their Cloud-Edge assets to meet set requirements. This article proposes a novel declarative resource selection strategy prototyped in Prolog to determine a suitable infrastructure portion that satisfies all requirements. The proposal is showcased over a lifelike scenario.

cs.DC

Microarchitectural Leakage Templates and Their Application to Cache-Based Side Channels

The complexity of modern processor architectures has given rise to sophisticated interactions among their components. Such interactions may result in potential attack vectors in terms of side channels, possibly available to user-land exploits to leak secret data. Exploitation and countering of such side channels require a detailed understanding of the target component. However, such detailed information is commonly unpublished for many CPUs. In this paper, we introduce the concept of Leakage Templates to abstractly describe specific side channels and identify their occurrences in binary applications. We design and implement Plumber, a framework to derive the generic Leakage Templates from individual code sequences that are known to cause leakage (e.g., found by prior work). Plumber uses a combination of instruction fuzzing, instructions' operand mutation and statistical analysis to explore undocumented behavior of microarchitectural optimizations and derive sufficient conditions on vulnerable code inputs that, if hold can trigger a distinguishing behavior. Using Plumber we identified novel leakage primitives based on Leakage Templates (for ARM Cortex-A53 and -A72 cores), in particular related to previction (a new premature cache eviction), and prefetching behavior. We show the utility of Leakage Templates by re-identifying a prefetcher-based vulnerability in OpenSSL 1.1.0g first reported by Shin et al. [40].

cs.CR

Osiris: Automated Discovery of Microarchitectural Side Channels

In the last years, a series of side channels have been discovered on CPUs. These side channels have been used in powerful attacks, e.g., on cryptographic implementations, or as building blocks in transient-execution attacks such as Spectre or Meltdown. However, in many cases, discovering side channels is still a tedious manual process. In this paper, we present Osiris, a fuzzing-based framework to automatically discover microarchitectural side channels. Based on a machine-readable specification of a CPU's ISA, Osiris generates instruction-sequence triples and automatically tests whether they form a timing-based side channel. Furthermore, Osiris evaluates their usability as a side channel in transient-execution attacks, i.e., as the microarchitectural encoding for attacks like Spectre. In total, we discover four novel timing-based side channels on Intel and AMD CPUs. Based on these side channels, we demonstrate exploitation in three case studies. We show that our microarchitectural KASLR break using non-temporal loads, FlushConflict, even works on the new Intel Ice Lake and Comet Lake microarchitectures. We present a cross-core cross-VM covert channel that is not relying on the memory subsystem and transmits up to 1 kbit/s. We demonstrate this channel on the AWS cloud, showing that it is stealthy and noise resistant. Finally, we demonstrate Stream+Reload, a covert channel for transient-execution attacks that, on average, allows leaking 7.83 bytes within a transient window, improving state-of-the-art attacks that only leak up to 3 bytes.

cs.CR