Attack Directories, Not Caches: Side Channel Attacks in a Non-Inclusive World
Атакуйте каталоги, а не кэши: атаки по побочному каналу в мире неинклюзивных кэшей
2019-05-01
SCID: 54.1/g8ey6vv8
Discuss with AI
Evict+ReloadPrime+Probecache side-channel attacksdirectory-based attacksnon-inclusive caches
Figures from the paper
Abstract (AI)
Although clouds have strong virtual memory isolation guarantees, cache attacks stemming from shared caches have proved to be a large security problem. However, despite the past effectiveness of cache attacks, their viability has recently been called into question on modern systems, due to trends in cache hierarchy design moving away from inclusive cache hierarchies. In this paper, we reverse engineer the structure of the directory in a sliced, non-inclusive cache hierarchy, and prove that the directory can be used to bootstrap conflict-based cache attacks on the last-level cache. We design the first cross-core Prime+Probe attack on non-inclusive caches. This attack works with minimal assumptions: the adversary does not need to share any virtual memory with the victim, nor run on the same processor core. We also show the first high-bandwidth Evict+Reload attack on the same hardware. We demonstrate both attacks by extracting key bits during RSA operations in GnuPG on a state-of-the-art non-inclusive Intel Skylake-X server.
Key Findings
1
Both attacks successfully extract RSA key bits from GnuPG running on a state-of-the-art Intel Skylake-X server.
2
It introduces the first cross-core Prime+Probe attack against non-inclusive caches without requiring shared virtual memory or co-location on the victim’s processor core.
3
It presents the first high-bandwidth Evict+Reload attack demonstrated on the same non-inclusive cache hardware.
4
The findings show that non-inclusive cache designs do not eliminate practical cache side-channel attacks, because directories can bootstrap them.
5
The paper reverse engineers directory structures in sliced, non-inclusive cache hierarchies and shows they enable conflict-based last-level-cache attacks.
Research Object
the directory and last-level cache in a sliced, non-inclusive cache hierarchy, including the Intel Skylake-X server hardware
Research Subject
the structure of the directory and its use in conflict-based cross-core Prime+Probe and high-bandwidth Evict+Reload side-channel attacks, including RSA key-bit extraction
Publication Details
Publication Date
2019-05-01
Journal
Publisher
ISSN
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest