Skip to Content

NetSpectre vulnerability can attack your PC's processor over the Internet

August 8, 2018 by
NetSpectre vulnerability can attack your PC's processor over the Internet
Kleber Leal by Zamak Portal

A group of security experts from the University of Graz, Austria, has detected a new variant of the Spectre vulnerability on the 26th. Dubbed NetSpectre, the security breach operates similarly to the search for data in memory, which is performed by processors. The main difference is that, theoretically, attacks can now occur remotely.

On the other hand, researchers claim the process is very slow, requiring 15 years for 1 MB of data to be stolen. On the topic, Intel states that the measures taken against Spectre also work against the new variant.

The researchers explain that to carry out such an attack, the criminal needs to create a JavaScript code responsible for measuring response times for data requests made to the invaded computer.

The goal is to discover information stored in the processor's internal memory, which can range from passwords to message content, for example. This is done through a series of deductions based on the time it takes for the processor to respond to an "order." From the measurement, the JavaScript code can retrieve the value actually stored in memory.

The issue is that using NetSpectre proves incredibly slow. To discover a single bit of information, an average of one million measurements are needed, with each letter made up of eight bits—or approximately every 30 minutes. According to the experts' calculations, this means that through the vulnerability, the time taken to steal 1 MB from an invaded computer is 15 years.

Although the test was carried out on an Intel processor, it is possible that the flaw could be adapted for AMD platforms (Photo: Disclosure/AMD)
Although the test was carried out on an Intel processor, it is possible that the flaw could be adapted for AMD platforms (Photo: Disclosure/AMD)
 

Intel issued a statement noting that the existing measures to combat the Spectre flaws are also sufficient to block NetSpectre attacks. The manufacturer also reminded that there is documentation guiding developers on what to do to prevent breaches and apply protection barriers.

What the manufacturer says

See Intel's full response:

“NetSpectre is an application of the Bounds Check Bypass type (CVE-2017-5753) and is mitigated the same way—through code inspection and software modifications to ensure there is, when necessary, a barrier capable of stopping speculation when it occurs. We released a guide for developers through our technical documentation Analyzing Potential Bounds Check Bypass Vulnerabilities, which was updated to incorporate this method. We thank Michael Schwarz, Daniel Gruss, Martin Schwarzl, Moritz Lipp, and Stefan Mangard from Graz University of Technology for informing us about their research.”

Source: Techtudo

Frequently asked questions

What is the NetSpectre vulnerability and how does it work?

NetSpectre is a variant of the Spectre vulnerability discovered by researchers at Graz University of Technology in Austria that can exploit processor speculation flaws remotely over the Internet. The attack uses JavaScript code to measure how long an invaded computer takes to respond to data requests, then deduces information stored in the processor's internal memory, such as passwords or message content.

Is NetSpectre an urgent, high-impact threat for businesses?

According to the researchers themselves, the attack is extremely slow: discovering a single bit of information takes an average of one million measurements, roughly every 30 minutes. At that rate, stealing just 1 MB of data from a compromised computer would take 15 years, which makes NetSpectre impractical for large-scale attacks.

How can systems be protected against NetSpectre?

Intel states that the same measures already used against the original Spectre vulnerability also block NetSpectre, including code inspection and software changes that create barriers to stop processor speculation when needed. Intel also provides developers with a technical guide, "Analyzing Potential Bounds Check Bypass Vulnerabilities," covering mitigation steps.

NetSpectre vulnerability can attack your PC's processor over the Internet
Kleber Leal by Zamak Portal August 8, 2018
Share this post
Tags
Archive