NetCAT: Practical Cache Attacks from the Network

NetCAT: практические атаки на кэш из сети
Dennis Andriesse, Herbert Bos, Kaveh Razavi, Cristiano Giuffrida, Ben Gras, Michael Kurth
2020-05-01

Data-Direct I/O (DDIO)Direct Cache Access (DCA)Keystroke timing attackLast Level Cache (LLC)Network-based PRIME+PROBE
Increased peripheral performance is causing strain on the memory subsystem of modern processors. For example, available DRAM throughput can no longer sustain the traffic of a modern network card. Scrambling to deliver the promised performance, instead of transferring peripheral data to and from DRAM, modern Intel processors perform I/O operations directly on the Last Level Cache (LLC). While Direct Cache Access (DCA) instead of Direct Memory Access (DMA) is a sensible performance optimization, it is unfortunately implemented without care for security, as the LLC is now shared between the CPU and all the attached devices, including the network card.In this paper, we reverse engineer the behavior of DCA, widely referred to as Data-Direct I/O (DDIO), on recent Intel processors and present its first security analysis. Based on our analysis, we present NetCAT, the first Network-based PRIME+PROBE Cache Attack on the processor's LLC of a remote machine. We show that NetCAT not only enables attacks in cooperative settings where an attacker can build a covert channel between a network client and a sandboxed server process (without network), but more worryingly, in general adversarial settings. In such settings, NetCAT can enable disclosure of network timing-based sensitive information. As an example, we show a keystroke timing attack on a victim SSH connection belonging to another client on the target server. Our results should caution processor vendors against unsupervised sharing of (additional) microarchitectural components with peripherals exposed to malicious input.
1
In adversarial settings, NetCAT can disclose network timing-sensitive information, demonstrated by recovering keystroke timing from another client’s SSH connection.
2
Modern Intel processors use Data-Direct I/O (DDIO) to transfer peripheral data directly through the shared Last Level Cache (LLC), bypassing DRAM.
3
NetCAT enables covert-channel attacks involving a network client and sandboxed server process, even when the server process lacks network access.
4
NetCAT introduces the first network-based PRIME+PROBE attack targeting the LLC of a remote machine through network traffic.
5
The paper reverse engineers DDIO behavior on recent Intel processors and provides its first security analysis.

Direct Cache Access (DCA), also known as Data-Direct I/O (DDIO), and the shared Last Level Cache (LLC) of recent Intel processors

The security vulnerabilities and remote network-based PRIME+PROBE cache-attack behavior enabled by peripheral sharing of the LLC, including leakage of network timing information

Publication Details
Publication Date
2020-05-01
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Dennis Andriesse
Herbert Bos
Kaveh Razavi
Cristiano Giuffrida
Ben Gras
Michael Kurth
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%