Ghost Thread: Effective User-Space Cache Side Channel Protection

Ghost Thread: Effective User-Space Cache Side Channel Protection
复制标题

DOI:
10.1145/3422337.3447846
复制
发表时间:
2021-04
期刊:
Proceedings of the Eleventh ACM Conference on Data and Application Security and Privacy
影响因子:
--
通讯作者:
Robert Brotzman;Danfeng Zhang;M. Kandemir;Gang Tan
Robert Brotzman;Danfeng Zhang;M. Kandemir;Gang Tan
中科院分区:
其他
文献类型:
--
作者:
Robert Brotzman;Danfeng Zhang;M. Kandemir;Gang Tan

文献摘要

相似文献

基于缓存的旁路攻击对计算机安全构成了严重威胁。大量的缓存攻击已经被证明,突出了有效和高效的防御机制,以保护系统免受这种威胁的需要。在本文中,我们提出了一种新的应用程序级保护机制,称为鬼线程。Ghost Thread是一个灵活的库,允许用户保护对请求的敏感区域的缓存访问,以减轻基于缓存的侧通道攻击。这是通过由单独的线程将随机高速缓存访问注入到敏感高速缓存区域来实现的。与以前的工作,注入噪声在修改后的操作系统和硬件相比,我们的新方法是适用于商品操作系统和硬件。与其他用户空间缓解机制相比,我们的新方法不需要任何特殊的硬件支持,它只需要在受保护的应用程序中进行轻微的代码更改,使其易于部署。在Apache服务器上的评估结果表明,Ghost Thread在实际应用程序中提供了强大的保护,并且仅需要保护片段的开销可以忽略不计。在整个应用程序都需要保护的最坏情况下,Ghost Thread在系统未充分利用时仍然会产生可忽略不计的开销,而在系统充分利用时会产生适度的开销。
Cache-based side channel attacks pose a serious threat to computer security. Numerous cache attacks have been demonstrated, highlighting the need for effective and efficient defense mechanisms to shield systems from this threat. In this paper, we propose a novel application-level protection mechanism, called Ghost Thread. Ghost Thread is a flexible library that allows a user to protect cache accesses to a requested sensitive region to mitigate cache-based side channel attacks. This is accomplished by injecting random cache accesses to the sensitive cache region by separate threads. Compared with prior work that injects noise in a modified OS and hardware, our novel approach is applicable to commodity OS and hardware. Compared with other user-space mitigation mechanisms, our novel approach does not require any special hardware support, and it only requires slight code changes in the protected application making it readily deployable. Evaluation results on an Apache server show that Ghost Thread provides both strong protection and negligible overhead on real-world applications where only a fragment requires protection. In the worst-case scenario where the entire application requires protection, Ghost Thread still incurs negligible overhead when a system is under utilized, and moderate overhead when a system is fully utilized.