A Benchmark Suite for Evaluating Caches' Vulnerability to Timing Attacks

A Benchmark Suite for Evaluating Caches' Vulnerability to Timing Attacks
复制标题

DOI:
10.1145/3373376.3378510
复制
发表时间:
2019-11
期刊:
Proceedings of the Twenty-Fifth International Conference on Architectural Support for Programming Languages and Operating Systems
影响因子:
--
通讯作者:
Shuwen Deng;Wenjie Xiong;Jakub Szefer
Shuwen Deng;Wenjie Xiong;Jakub Szefer
中科院分区:
其他
文献类型:
--
作者:
Shuwen Deng;Wenjie Xiong;Jakub Szefer

文献摘要

被引文献

相似文献

基于对基于缓存时间攻击的现有三步模型的改进,这项工作介绍了88种强大的基于理论计时的漏洞。它还提出并实施了一个新的基准套件,该套件可用于测试处理器缓存是否容易受到其中一次攻击的影响。总共有1094个自动生成的测试程序,涵盖了88个强大的理论漏洞。基准套件生成缓存定时漏洞得分(CTV),可用于评估特定的缓存实现对不同攻击的脆弱性。较小的CTV意味着设计更安​​全。评估是对商品Intel和AMD处理器进行的,并展示了处理器实施的差异如何导致它们容易受到影响的不同类型的攻击。此外,可以将基准和CTV用于模拟中,以帮助新的安全处理器的设计人员和缓存评估其设计对基于缓存时间攻击的敏感性。
Based on improvements to an existing three-step model for cache timing-based attacks, this work presents 88 Strong types of theoretical timing-based vulnerabilities in processor caches. It also presents and implements a new benchmark suite that can be used to test if processor cache is vulnerable to one of the attacks. In total, there are 1094 automatically-generated test programs which cover the 88 Strong theoretical vulnerabilities. The benchmark suite generates the Cache Timing Vulnerability Score (CTVS) which can be used to evaluate how vulnerable a specific cache implementation is to different attacks. A smaller CTVS means the design is more secure. Evaluation is conducted on commodity Intel and AMD processors and shows how the differences in processor implementations can result in different types of attacks that they are vulnerable to. Further, the benchmarks and the CTVS can be used in simulation to help designers of new secure processors and caches evaluate their designs' susceptibility to cache timing-based attacks.