Detecting time-fragmented cache attacks against AES using Performance Monitoring Counters

Detecting time-fragmented cache attacks against AES using Performance Monitoring Counters
复制标题

使用性能监控计数器检测针对 AES 的时间碎片缓存攻击

DOI:
--
复制
发表时间:
2019
期刊:
Conference on Cloud Computing & Big Data
影响因子:
--
通讯作者:
Katzalin Olcoz
Katzalin Olcoz
中科院分区:
--
文献类型:
--
作者:
I. Prada;Francisco D. Igual;Katzalin Olcoz

文献摘要

被引文献

相似文献

缓存时正式攻击使用多核处理器中的共享缓存作为侧渠道,以从受害者流程中提取信息。这些攻击在云基础设施中尤其危险,其中部署的对策在绩效损失和能源消耗的增加方面会导致附带影响。我们建议使用独立监视(检测器)过程监视受害者过程,该过程不断衡量选定的性能监控计数器(PMC)以检测攻击的存在。只有在出现这种危险的情况时才能应用临时对策。在我们的情况下,受害者过程是AES加密算法,攻击是通过随机加密请求进行的。我们证明,PMC是检测攻击的可行工具,并且在检测能力方面,在较低频率下进行采样的PMC比在较低频率下进行采样,尤其是当攻击及时散布以及时散布以试图隐藏在检测中时。
Cache timing attacks use shared caches in multi-core processors as side channels to extract information from victim processes. These attacks are particularly dangerous in cloud infrastructures, in which the deployed countermeasures cause collateral effects in terms of performance loss and increase in energy consumption. We propose to monitor the victim process using an independent monitoring (detector) process, that continuously measures selected Performance Monitoring Counters (PMC) to detect the presence of an attack. Ad-hoc countermeasures can be applied only when such a risky situation arises. In our case, the victim process is the AES encryption algorithm and the attack is performed by means of random encryption requests. We demonstrate that PMCs are a feasible tool to detect the attack and that sampling PMCs at high frequencies is worse than sampling at lower frequencies in terms of detection capabilities, particularly when the attack is fragmented in time to try to be hidden from detection.