현대 프로세서에서 공식 ISA 명세와 실제 하드웨어 구현 사이의 간극(Gap)은 치명적이지만 아직 깊 이 있게 연구되지 않아 수많은 공격 표면(attack surface)을 만들어내고 있다. 이러한 간극에서 ...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T17379769
춘천 : 강원대학교 대학원, 2026
2026
한국어
강원특별자치도
31 ; 26 cm
지도교수: 송원준
I804:42002-000000035510
0
상세조회0
다운로드현대 프로세서에서 공식 ISA 명세와 실제 하드웨어 구현 사이의 간극(Gap)은 치명적이지만 아직 깊 이 있게 연구되지 않아 수많은 공격 표면(attack surface)을 만들어내고 있다. 이러한 간극에서 ...
현대 프로세서에서 공식 ISA 명세와 실제 하드웨어 구현 사이의 간극(Gap)은 치명적이지만 아직 깊 이 있게 연구되지 않아 수많은 공격 표면(attack surface)을 만들어내고 있다. 이러한 간극에서 비롯되는 비문서화 명령어는 시스템의 안정성과 보안을 위협하는 중요한 요인으로 부상하고 있다. 기존 연구들은 주로 이러한 명령어를 '탐색'하는 초기 단계에 집중했지만, 발견된 명령어의 동작을 규명하고 보안적 영 향을 평가하는 후속 분석은 여전히 수작업에 의존하여 비체계적으로 이루어지는 한계가 있다. 특히, 발 견된 위협을 정량적으로 평가하고 분류하는 보안 중심의 방법론은 부재했다.
본 논문은 해당 공백을 메우는 데 집중하여, 상용 RISC 프로세서에 잠재된 비문서화 명령어의 보안적 특성을 심층 분석하고, 그 위험성을 체계적으로 검증하는 프레임워크를 제시한다. 이를 위해 명령어의 아키텍처 상태 변화를 기반으로 동작을 자동 분류하는 분류기(Classifier)를 설계했으며, 발견된 명령어 의 실제 위협 수준을 평가하는 검증 방법론을 정립했다.
실험 평가 결과, 제안된 분석 프레임워크를 통해 총 23개의 고유한 비문서화 명령어를 식별했다. 개발 된 분류기는 약 99.8357%의 정확도로 29개 명령어의 동작을 자동으로 분류하여, 수동 분석의 한계를 극 복하였다. 더 나아가, 제안된 보안 위협 평가 기법을 적용하여 이 중 5개의 명령어가 실제로 시스템에 중대한 보안 영향을 미칠 수 있음을 검증함으로써, ISA 명세와 구현 간의 간극이 초래하는 실질적인 위 험성을 분석하였다.
다국어 초록 (Multilingual Abstract)
In modern processors, the gap between the official ISA specification and the actual hardware implementation creates a critical, yet often overlooked, attack surface. Undocumented instructions arising from this gap pose a serious threat to system stabi...
In modern processors, the gap between the official ISA specification and the actual hardware implementation creates a critical, yet often overlooked, attack surface. Undocumented instructions arising from this gap pose a serious threat to system stability and security. However, previous research has largely been limited to discovery of these instructions. The subsequent steps of behavioral analysis and security impact assessment still rely on unsystematic manual efforts, lacking a security-centric methodology for quantitative evaluation.
To address this deficiency, this paper presents a comprehensive framework for analyzing the security properties of undocumented instructions in commercial RISC processors. We introduce an automated classifier that identifies instruction behavior based on architectural state changes, alongside a rigorous verification methodology to evaluate real-world threat levels.
Through our experiments, we identified 23 unique undocumented instructions. Our classifier achieved an accuracy of 99.8357% in automatically categorizing the behavior of 29 instructions, successfully overcoming the bottlenecks of manual analysis. Moreover, we confirmed that five of these instructions have the potential to inflict significant security damage on the system. These findings underscore the tangible risks inherent in the gap between ISA specifications and hardware implementations.
목차 (Table of Contents)