컴퓨터/노트북/인터넷
IT 컴퓨터 기기를 좋아하는 사람들의 모임방
단축키
Prev이전 문서
Next다음 문서
단축키
Prev이전 문서
Next다음 문서
AMD 에픽 CPU 1, 2, 3세대 모델에 존재하는 캐시워프라는 취약점이 공개됐습니다.
SEV(Secure Encrypted Virtualization)의 취약점을 사용해 암호화 상태에서 실행되는 가상 머신의 캐시 메모리를 조작하는 소프트웨어 기반 결함
Securing Virtual Machines.
AMD SEV.
AMD Secure Encrypted Virtualization (SEV) is a CPU extension enabling a more secure separation between virtual machines (VMs) and the underlying hypervisor. AMD SEV allows developers to deploy VMs in an untrusted hypervisor environment securely. In other words, this means that computations in the cloud can be performed on confidential data even if the cloud provider is untrusted or compromised.
AMD SEV achieves this level of protection by encrypting the VM’s data. The encryption applies to the VM’s memory as well as its register state upon context switches. The latest and most secure variant of SEV, namely, AMD SEV-SNP, additionally prevents cloud providers from altering the data stored inside the VM.
https://cachewarpattack.com/#home