Packet Chasing: Spying on Network Packets over a Cache Side-Channel

Packet Chasing: Spying on Network Packets over a Cache Side-Channel
复制标题

DOI:
10.1109/isca45697.2020.00065
复制
发表时间:
2019-09
期刊:
2020 ACM/IEEE 47th Annual International Symposium on Computer Architecture (ISCA)
影响因子:
--
通讯作者:
Mohammadkazem Taram;A. Venkat;D. Tullsen
Mohammadkazem Taram;A. Venkat;D. Tullsen
中科院分区:
其他
文献类型:
--
作者:
Mohammadkazem Taram;A. Venkat;D. Tullsen

文献摘要

相似文献

本文介绍了Chasing,这是对网络上不需要访问网络的攻击,无论接收数据包的过程的特权级别如何,都可以使用。间谍过程可以轻松探测并发现网络驱动程序使用的每个缓冲区的确切缓存位置。更有用,它可以发现这些缓冲区用于接收数据包的确切序列。然后,这使得可以通过缓存侧通道监视数据包频率和数据包大小。这允许在发件人和远程间谍之间进行秘密渠道,无法访问网络,并且可以直接攻击网络上受害者的网页访问模式。除了确定潜在攻击外,这项工作还提出了基于软件的短期缓解以及轻巧,自适应,缓存缓解缓解措施,该缓解缓解措施阻止了最后一级缓存中I/O和CPU请求的干扰。
This paper presents Packet Chasing, an attack on the network that does not require access to the network, and works regardless of the privilege level of the process receiving the packets. A spy process can easily probe and discover the exact cache location of each buffer used by the network driver. Even more useful, it can discover the exact sequence in which those buffers are used to receive packets. This then enables packet frequency and packet sizes to be monitored through cache side channels. This allows both covert channels between a sender and a remote spy with no access to the network, as well as direct attacks that can identify, among other things, the web page access patterns of a victim on the network. In addition to identifying the potential attack, this work proposes a software-based short-term mitigation as well as a light-weight, adaptive, cache partitioning mitigation that blocks the interference of I/O and CPU requests in the last-level cache.