A New Prime and Probe Cache Side-Channel Attack for Cloud Computing

Новая атака по побочным каналам кэш-памяти типа Prime and Probe для облачных вычислений
Younis A. Younis, Kashif Kifayat, Qi Shi, Bob Askwith
2015-10-01

Prime and Probe attackcache side-channel attackcloud computingphysical address translationvirtual machine co-residency
Cloud computing is considered one of the most dominant paradigms in the Information Technology (IT) industry nowadays. It supports multi-tenancy to fulfil future increasing demands for accessing and using resources provisioned over the Internet. However, multi-tenancy in cloud computing has unique vulnerabilities such as clients' co-residence and virtual machine physical co-residency. Physical co-residency of virtual machines can facilitate attackers with an ability to interfere with another virtual machine running on the same physical machine due to an insufficient logical isolation. In the worst scenario, attackers can exfiltrate sensitive information of victims on the same physical machine by using hardware side-channels. There are various types of side-channels attacks, which are classified according to hardware medium they target and exploit, for instance, cache side-channel attacks. CPU caches are one of the most hardware devices targeted by adversaries because it has high-rate interactions and sharing between processes. This paper presents a new Prime and Probe cache side-channel attack, which can prime physical addresses. These addresses are translated form virtual addresses used by a virtual machine. Then, time is measured to access these addresses and it will be varied according to where the data is located. If it is in the CPU cache, the time will be less than in the main memory. The attack was implemented in a server machine comparable to cloud environment servers. The results show that the attack needs less effort and time than other types and is easy to be launched.
1
Experimental results indicate that the proposed attack requires less effort and time than other attack types and is easy to launch.
2
The attack infers data locations by timing memory accesses, distinguishing faster CPU-cache hits from slower main-memory accesses.
3
The attack was implemented on a server machine designed to resemble a cloud-computing environment.
4
The paper introduces a Prime and Probe cache side-channel attack capable of priming physical addresses translated from virtual-machine virtual addresses.
5
Virtual-machine physical co-residency and insufficient logical isolation enable attackers to target co-located victims through shared CPU caches.

Prime and Probe cache side-channel attacks on co-resident virtual machines in cloud-computing servers

The effectiveness and efficiency of exploiting CPU-cache access-time variations to infer data locations across insufficiently isolated virtual machines

Publication Details
Publication Date
2015-10-01
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Younis A. Younis
Kashif Kifayat
Qi Shi
Bob Askwith
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%