S$A: A Shared Cache Attack That Works across Cores and Defies VM Sandboxing -- and Its Application to AES
S$A: Атака на общий кэш, работающая между ядрами и обходящая изоляцию виртуальных машин, и её применение к AES
2015-05-01
SCID: 54.1/cd2xh6gj
Discuss with AI
AES key recoverycross-VM side-channel attackcross-core cache attackhuge pagesshared last-level cache
Figures from the paper
Abstract (AI)
The cloud computing infrastructure relies on virtualized servers that provide isolation across guest OS's through sand boxing. This isolation was demonstrated to be imperfect in past work which exploited hardware level information leakages to gain access to sensitive information across co-located virtual machines (VMs). In response virtualization companies and cloud services providers have disabled features such as deduplication to prevent such attacks. In this work, we introduce a fine-grain cross-core cache attack that exploits access time variations on the last level cache. The attack exploits huge pages to work across VM boundaries without requiring deduplication. No configuration changes on the victim OS are needed, making the attack quite viable. Furthermore, only machine co-location is required, while the target and victim OS can still reside on different cores of the machine. Our new attack is a variation of the prime and probe cache attack whose applicability at the time is limited to L1 cache. In contrast, our attack works in the spirit of the flush and reload attack targeting the shared L3 cache instead. Indeed, by adjusting the huge page size our attack can be customized to work virtually at any cache level/size. We demonstrate the viability of the attack by targeting an Open SSL1.0.1f implementation of AES. The attack recovers AES keys in the cross-VM setting on Xen 4.1 with deduplication disabled, being only slightly less efficient than the flush and reload attack. Given that huge pages are a standard feature enabled in the memory management unit of OS's and that besides co-location no additional assumptions are needed, the attack we present poses a significant risk to existing cloud servers.
Key Findings
1
Because huge pages are widely enabled and no assumptions beyond co-location are required, the attack poses a significant security risk to cloud servers.
2
By exploiting huge pages and access-time variations, the technique targets shared L3 cache and can be adapted to virtually any cache level or size.
3
Introduces a fine-grained cross-core last-level-cache attack that crosses VM boundaries without requiring memory deduplication or victim-OS changes.
4
The attack requires only physical machine co-location; attacker and victim VMs may run on different processor cores.
5
The method recovers AES keys from OpenSSL 1.0.1f across VMs on Xen 4.1 with deduplication disabled, with only slightly lower efficiency than Flush+Reload.
Research Object
cross-VM last-level cache behavior in virtualized cloud servers, demonstrated through an OpenSSL AES implementation
Research Subject
fine-grained cross-core cache-access timing variations enabling AES key recovery across VM boundaries without deduplication
Publication Details
Publication Date
2015-05-01
Journal
Publisher
ISSN
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest