{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T05:09:21Z","timestamp":1755839361265},"reference-count":83,"publisher":"IEEE","license":[{"start":{"date-parts":[[2022,5,1]],"date-time":"2022-05-01T00:00:00Z","timestamp":1651363200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2022,5,1]],"date-time":"2022-05-01T00:00:00Z","timestamp":1651363200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,5]]},"DOI":"10.1109\/sp46214.2022.9833599","type":"proceedings-article","created":{"date-parts":[[2022,7,27]],"date-time":"2022-07-27T19:28:05Z","timestamp":1658950085000},"source":"Crossref","is-referenced-by-count":3,"title":["Finding and Exploiting CPU Features using MSR Templating"],"prefix":"10.1109","author":[{"given":"Andreas","family":"Kogler","sequence":"first","affiliation":[{"name":"Graz University of Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniel","family":"Weber","sequence":"additional","affiliation":[{"name":"CISPA Helmholtz Center for Information Security"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Martin","family":"Haubenwallner","sequence":"additional","affiliation":[{"name":"Graz University of Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Moritz","family":"Lipp","sequence":"additional","affiliation":[{"name":"Amazon Web Services"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniel","family":"Gruss","sequence":"additional","affiliation":[{"name":"Graz University of Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michael","family":"Schwarz","sequence":"additional","affiliation":[{"name":"CISPA Helmholtz Center for Information Security"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref57","author":"mavropoulos","year":"2021","journal-title":"CPUMicrocodes"},{"key":"ref13","author":"b\u00f6l\u00fck","year":"2021","journal-title":"Undocumented MSRs with Haruspex"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243761"},{"key":"ref12","author":"b\u00f6l\u00fck","year":"2021","journal-title":"Haruspex"},{"key":"ref59","author":"miller","year":"2004","journal-title":"Safely Searching Process Virtual Address Space"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3320269.3384747"},{"key":"ref58","author":"mechalas","year":"2019","journal-title":"Trusted CPU Feature Detection Library"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363219"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00063"},{"key":"ref52","article-title":"AR-Mageddon: Cache Attacks on Mobile Devices","author":"lipp","year":"2016","journal-title":"USENIX Security Symposium"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66399-9_12"},{"key":"ref11","article-title":"Software Grand Exposure: SGX Cache Attacks Are Practical","author":"brasser","year":"2017","journal-title":"WOOT"},{"key":"ref54","article-title":"Meltdown: Reading Kernel Memory from User Space","author":"lipp","year":"2018","journal-title":"USENIX Security Symposium"},{"key":"ref10","article-title":"Using Dynamic Time Warping to Find Patterns in Time Series","author":"berndt","year":"1994","journal-title":"Proceedings of the 3rd International Conference on Knowledge Discovery and Data Mining"},{"key":"ref17","year":"2020","journal-title":"x86\/hvm disallow access to unknown MSRs"},{"key":"ref16","article-title":"A Systematic Evaluation of Transient Execution Attacks and Defenses","author":"canella","year":"2019","journal-title":"USENIX Security Symposium"},{"key":"ref19","year":"2021","journal-title":"CoreBoot - Bios Update Trigger"},{"key":"ref18","year":"2019","journal-title":"coreboot Fast secure and flexible OpenSource firmware"},{"key":"ref51","article-title":"Amd prefetch attacks through power and time","author":"lipp","year":"2022","journal-title":"USENIX Security Symposium"},{"key":"ref50","article-title":"Reverse engineering x86 processor microcode","author":"koppe","year":"2017","journal-title":"USENIX Security Symposium"},{"key":"ref46","author":"james","year":"2021","journal-title":"ghidra-firmware-utils"},{"key":"ref45","year":"2021","journal-title":"Intel-Linux-Processor-Microcode-Data-Files"},{"key":"ref48","author":"kemkes","year":"2020","journal-title":"Techniques Current use of virtual machine detection methods"},{"key":"ref47","author":"jone","year":"2001","journal-title":"Dave Jone&#x2019;s MSR scanner"},{"key":"ref42","year":"2020","journal-title":"Affected Processors Transient Execution Attacks"},{"key":"ref41","year":"2019","journal-title":"Intel 64 and IA-32 Architectures Software Developer&#x2019;s Manual Volume 4 Model-Specific Registers"},{"key":"ref44","year":"2020","journal-title":"Refined speculative execution terminology"},{"key":"ref43","year":"2020","journal-title":"Intel Xeon Processor Scalable Family Datasheet"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00002"},{"key":"ref8","year":"2020","journal-title":"mbed TLS"},{"key":"ref7","year":"2021","journal-title":"BIOS\/UEFI Utilities"},{"key":"ref9","article-title":"SGX Secure Enclaves in Practice: Security and Crypto Review","author":"aumasson","year":"2016","journal-title":"Black Hat Briefings"},{"key":"ref4","article-title":"AMD64 Architecture Programmer&#x2019;s Manual","year":"2017","journal-title":"Advanced Micro Devices Inc"},{"key":"ref3","year":"2013","journal-title":"Bios and Kernel Developers Guide (Bkdg) for Amd Family 15h Models OOh-Ofh Processors"},{"key":"ref6","year":"2021","journal-title":"Amazon ec2 on-demand pricing"},{"key":"ref5","year":"2018","journal-title":"Open-Source Register Reference For AMD Family 17h Processors Models 00h-2Fh"},{"key":"ref82","year":"2021","journal-title":"XEN&#x2019;s MSR handling"},{"key":"ref81","author":"weisse","year":"2018","journal-title":"Foreshadow-NG Breaking the virtual memory abstraction with transient out-of-order execution"},{"key":"ref40","year":"2019","journal-title":"Intel 64 and IA-32 Architectures Software Developer's Manual Volume 3 System Programming Guide"},{"key":"ref83","author":"yu","year":"2019","journal-title":"The Linux Microcode Loader"},{"key":"ref80","article-title":"AsyncShock: Exploiting Synchronisation Bugs in Intel SGX Enclaves","author":"weichbrodt","year":"2016","journal-title":"ESORICS"},{"key":"ref79","author":"voisin","year":"2021","journal-title":"Spectre exploits in the &#x201D;wild&#x201D;"},{"key":"ref35","year":"2018","journal-title":"Intel analysis of speculative execution side channels"},{"key":"ref78","author":"vlasenko","year":"2017","journal-title":"Better document AMD &#x201D;tweak MSRs&#x201D;"},{"key":"ref34","year":"2016","journal-title":"Intel 64 and IA-32 Architectures Software Developer s Manual Volume 1 Basic Architecture"},{"key":"ref37","year":"2019","journal-title":"Deep Dive CPUID Enumeration and Architectural MSRs"},{"key":"ref36","year":"2018","journal-title":"L1 Terminal Fault SA-00161"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00087"},{"key":"ref31","year":"2008","journal-title":"White Paper Advanced Encryption Standard (Aes) Instruction Set"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1145\/3152701.3152706"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-1992-13-404"},{"key":"ref77","author":"viswanathan","year":"0","journal-title":"Disclosure of hardware prefetcher control on some intel processors"},{"key":"ref33","year":"2016","journal-title":"Intel software guard extensions sdk for linux os developer reference"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1145\/2046660.2046671"},{"key":"ref32","year":"2012","journal-title":"Pin - A dynamic binary instrumentation tool"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/ISPASS48437.2020.00014"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304062"},{"key":"ref39","year":"2019","journal-title":"Intel 64 and IA-32 Architectures Software Developer&#x2019;s Manual Volume 2 (2A 2B & 2C) Instruction Set Reference A-Z"},{"key":"ref38","year":"2019","journal-title":"Intel 64 and IA-32 Architectures Optimization Reference Manual"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-16458-4_2"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354252"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00089"},{"key":"ref72","article-title":"Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order Execution","author":"van bulck","year":"2018","journal-title":"USENIX Security Symposium"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196508"},{"key":"ref24","article-title":"Hardware Backdoors in x86 CPUs","author":"domas","year":"2018","journal-title":"Black Hat USA"},{"key":"ref67","author":"schlej","year":"2020","journal-title":"UEFI firmware image viewer and editor"},{"key":"ref23","article-title":"Breaking the x86 ISA, v. 2017-07-27","author":"domas","year":"2017","journal-title":"Black Hat USA"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4302-6638-9"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60876-1_1"},{"key":"ref25","year":"2021","journal-title":"Feature Detection"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00020"},{"key":"ref20","article-title":"Intel SGX Explained","author":"costan","year":"2016","journal-title":"Cryptology ePrint Archive Report 2016\/086"},{"key":"ref63","author":"petkov","year":"2020","journal-title":"[RFC PATCH] x86\/MSR Filter MSR writes"},{"key":"ref66","author":"sakkinen","year":"2018","journal-title":"Add SGX Launch Control MSR definitions"},{"key":"ref22","first-page":"337","article-title":"Z3: An efficient smt solver","author":"de moura","year":"2008","journal-title":"International Conference on Tools and Algorithms for the Construction and Analysis of Systems"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.7551\/mitpress\/5236.001.0001"},{"key":"ref21","year":"2014","journal-title":"Super-secret debug capabilities of AMD processors !"},{"key":"ref28","author":"henry","year":"2012","journal-title":"Apparatus and method for limiting access to model specific registers in a microprocessor"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978356"},{"key":"ref29","author":"horn","year":"2018","journal-title":"speculative execution variant 4 speculative store bypass"},{"key":"ref60","article-title":"CacheZoom: How SGX amplifies the power of cache attacks","author":"moghimi","year":"2017","journal-title":"CHES"},{"key":"ref62","author":"pau","year":"2020","journal-title":"x86\/hvm disallow access to unknown MSRs"},{"key":"ref61","article-title":"Medusa: Microarchitectural Data Leakage via Automated Attack Synthesis","author":"moghimi","year":"2020","journal-title":"USENIX Security Symposium"}],"event":{"name":"2022 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2022,5,22]]},"end":{"date-parts":[[2022,5,26]]}},"container-title":["2022 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9833550\/9833558\/09833599.pdf?arnumber=9833599","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,11,8]],"date-time":"2023-11-08T23:23:43Z","timestamp":1699485823000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9833599\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,5]]},"references-count":83,"URL":"https:\/\/doi.org\/10.1109\/sp46214.2022.9833599","relation":{},"subject":[],"published":{"date-parts":[[2022,5]]}}}