SGXlinger: A New Side-Channel Attack Vector Based on Interrupt Latency Against Enclave Execution

SGXlinger: A New Side-Channel Attack Vector Based on Interrupt Latency Against Enclave Execution
复制标题

SGXlinger:针对 Enclave 执行的基于中断延迟的新侧通道攻击向量

DOI:
--
复制
发表时间:
2018
期刊:
ICCD
影响因子:
--
通讯作者:
Yang Liu
Yang Liu
中科院分区:
--
文献类型:
--
作者:
Wenjian He;Wei Zhang;Sanjeev Das;Yang Liu

文献摘要

被引文献

相似文献

软件保护扩展(SGX)是最近在英特尔商用处理器中发布的一项新安全功能。它旨在为用户程序提供一个针对系统中的其他组件(包括操作系统、固件和硬件外围设备)的强屏蔽环境。有了SGX,开发人员可以在不受信任的远程平台上安全地部署关键应用程序,而不会担心信息泄露。然而,研究人员发现了几起针对新交所的攻击,这表明盲目依赖新交所是不可取的,并推动了对新交所安全属性进行全面研究的必要性。在本文中,我们发现了一种新的攻击向量SGXlinger,它可以泄露受保护程序内部的信息。我们的攻击监视SGX保护程序的中断延迟,这是第一次将中断延迟用作旁路。我们开发了一个框架来重复测量Enclave程序的中断延迟,评估表明我们可以在屏蔽环境中学习粗粒度信息。在实验环境中,我们测量了所提出的边信道的信息泄漏率可达35Kbps。
Software Guard Extension (SGX) is a new security feature that has been released in recent Intel commodity processors. It is designed to provide a user program with a strongly shielded environment against other components in the system, including the OS, firmware and hardware peripherals. With SGX, developers can securely deploy critical applications on untrusted remote platforms without the concern of information leakage. However, researchers have found several attacks against SGX, suggesting blind reliance on SGX is inadvisable, and promoting the need for a comprehensive study on the security property of SGX. In this paper, we discover a new attack vector SGXlinger to disclose information inside the protected program. Our attack monitors the interrupt latency of the SGX-protected program, and it is the first time that the interrupt latency is leveraged as a side-channel. We develop a framework to repeatedly measure the interrupt latency of an enclave program, and the evaluation shows we can learn coarse-grained information inside the shielded environment. In an experimental setting, we measure that the information leakage rate of the proposed side-channel can reach up to 35 Kbps.