Build AI Apps with Azure, Copilot, and Generative AI — Microsoft Certified
Get 20% off all career paths from fullstack to AI
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Explore a 17-minute IEEE conference talk that delves into modeling attacks on speculative evaluation. Gain insights into the Spectre attack and its exploitation of dynamic security checks, speculative evaluation, and cache timing. Discover a proposed pomset-based model designed to capture speculative evaluation, which is abstract enough to express known attacks like Spectre and Prime+Abort while verifying their countermeasures. Learn about the model's potential to predict new information flow attacks, including two novel attacks exploiting compiler optimizations. Understand how these attacks were experimentally validated against gcc and clang, and grasp the importance of formal modeling in identifying and mitigating security vulnerabilities in modern computer architectures.
Syllabus
The Code That Never Ran: Modeling Attacks on Speculative Evaluation
Taught by
IEEE Symposium on Security and Privacy