Red Alert for Power Leakage: Exploiting Intel RAPL-Induced Side Channels

Red Alert for Power Leakage: Exploiting Intel RAPL-Induced Side Channels
复制标题

漏电红色警报:利用 Intel RAPL 引发的侧通道

DOI:
10.1145/3433210.3437517
复制
发表时间:
2021
期刊:
ACM Asia Conference on Computer and Communication Security (Asia CSS ’21
影响因子:
--
通讯作者:
Gao, Xing
Gao, Xing
中科院分区:
--
文献类型:
--
作者:
Zhang, Zhenkai;Liang, Sisheng;Yao, Fan;Gao, Xing

文献摘要

参考文献

被引文献

相似文献

RAPL(Running Average Power Limit,运行平均功率限制)是英特尔为促进电源管理而推出的一项硬件功能。尽管RAPL及其支持的软件接口可以极大地促进电源管理,但不幸的是,它们在设计时没有仔细考虑某些安全问题。在这篇文章中,我们证明了通过RAPL诱导的旁路泄露的信息可以被利用来发动现实的攻击。具体地说,我们使用单个AVX指令构建了一个新的基于RAPL的隐蔽通道,它可以跨不同的边界(例如,软件中的容器甚至硬件中的CPU建立的边界)渗透数据;我们研究了第一个基于RAPL的网站指纹识别技术,该技术可以高精度地识别访问的网页(在使用Chrome或Safari等浏览器的常规网络中高达99%,在使用Tor的匿名网络的情况下高达81%)。这两项研究构成了对RAPL强加的安全影响的初步审查。此外,我们还讨论了一些可能的对策。
RAPL (Running Average Power Limit) is a hardware feature introduced by Intel to facilitate power management. Even though RAPL and its supporting software interfaces can benefit power management significantly, they are unfortunately designed without taking certain security issues into careful consideration. In this paper, we demonstrate that information leaked through RAPL-induced side channels can be exploited to mount realistic attacks. Specifically, we have constructed a new RAPL-based covert channel using a single AVX instruction, which can exfiltrate data across different boundaries (e.g., those established by containers in software or even CPUs in hardware); and, we have investigated the first RAPL-based website fingerprinting technique that can identify visited webpages with a high accuracy (up to 99% in the case of the regular network using a browser like Chrome or Safari, and up to 81% in the case of the anonymity network using Tor). These two studies form a preliminary examination into RAPL-imposed security implications. In addition, we discuss some possible countermeasures.
通过随机数生成器的隐蔽通道:机制、容量估计和缓解措施
DOI: 10.1145/2976749.2978374
发表时间: 2016
期刊: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Dmitry Evtyushkin;D. Ponomarev
通讯作者: D. Ponomarev
微架构雷区:Iaas 云中的 4K 别名隐蔽通道和多租户检测
DOI: --
发表时间: 2018
期刊: Network and Distributed System Security Symposium
影响因子: --
作者:
Dean Sullivan;Orlando Arias;Travis Meade;Yier Jin
通讯作者: Yier Jin
测量网站指纹攻击和防御中的信息泄漏
DOI: 10.1145/3243734.3243832
发表时间: 2018
期刊: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Li, Shuai;Guo, Huajun;Hopper, Nicholas
通讯作者: Hopper, Nicholas
DOI: 10.1145/3289602.3293920
发表时间: 2019-02
期刊: Proceedings of the 2019 ACM/SIGDA International Symposium on Field-Programmable Gate Arrays
影响因子: --
作者:
Shanquan Tian;Jakub Szefer
通讯作者: Shanquan Tian;Jakub Szefer
不确定时期值得信赖的浏览器
DOI: --
发表时间: 2016
期刊: USENIX Security Symposium
影响因子: --
作者:
David Kohlbrenner;H. Shacham
通讯作者: H. Shacham