Shielding Software From Privileged Side-Channel Attacks

Shielding Software From Privileged Side-Channel Attacks
复制标题

DOI:
--
复制
发表时间:
2018
期刊:
ArXiv
影响因子:
--
通讯作者:
Xiaowan Dong;Zhuojia Shen;J. Criswell;A. Cox;S. Dwarkadas
Xiaowan Dong;Zhuojia Shen;J. Criswell;A. Cox;S. Dwarkadas
中科院分区:
其他
文献类型:
--
作者:
Xiaowan Dong;Zhuojia Shen;J. Criswell;A. Cox;S. Dwarkadas

文献摘要

被引文献

相似文献

商品操作系统(OS)内核(例如Windows,Mac OS X,Linux和FreeBSD)易受许多安全漏洞的影响。避风港和虚拟幽灵保护敏感的应用程序数据免于受损的OS内核。攻击更糟糕的是,折衷的OS内核可以利用特权的硬件状态来加剧现有的侧面渠道; CACHE(LLC)侧渠道攻击由折衷的OS内核定义了OS内核的读写能力页面和抗辩分配攻击,我们的LLC防御使用Intel Cache分配技术以及内存隔离原料。 - 渠道防御在现实世界应用程序上,通道防御添加了1%至18%(一个应用程序的最高为86%)开销。
Commodity operating system (OS) kernels, such as Windows, Mac OS X, Linux, and FreeBSD, are susceptible to numerous security vulnerabilities. Their monolithic design gives successful attackers complete access to all application data and system resources. Shielding systems such as InkTag, Haven, and Virtual Ghost protect sensitive application data from compromised OS kernels. However, such systems are still vulnerable to side-channel attacks. Worse yet, compromised OS kernels can leverage their control over privileged hardware state to exacerbate existing side channels; recent work has shown that a compromised OS kernel can steal entire documents via side channels. This paper presents defenses against page table and last-level cache (LLC) side-channel attacks launched by a compromised OS kernel. Our page table defenses restrict the OS kernel’s ability to read and write page table pages and defend against page allocation attacks, and our LLC defenses utilize the Intel Cache Allocation Technology along with memory isolation primitives. We prototype our solution in a system we call Apparition, building on an optimized version of Virtual Ghost. Our evaluation shows that our side-channel defenses add 1% to 18% (with up to 86% for one application) overhead to the optimized Virtual Ghost (relative to the native kernel) on real-world applications.