CaSA: End-to-end Quantitative Security Analysis of Randomly Mapped Caches

CaSA: End-to-end Quantitative Security Analysis of Randomly Mapped Caches
复制标题

DOI:
10.1109/micro50266.2020.00092
复制
发表时间:
2020-10
期刊:
2020 53rd Annual IEEE/ACM International Symposium on Microarchitecture (MICRO)
影响因子:
--
通讯作者:
Thomas Bourgeat;Jules Drean;Yuheng Yang;L. Tsai;J. Emer;Mengjia Yan
Thomas Bourgeat;Jules Drean;Yuheng Yang;L. Tsai;J. Emer;Mengjia Yan
中科院分区:
其他
文献类型:
--
作者:
Thomas Bourgeat;Jules Drean;Yuheng Yang;L. Tsai;J. Emer;Mengjia Yan

文献摘要

被引文献

相似文献

众所周知,有一些微构造的脆弱性使攻击者能够使用缓存者从受害者那里删除秘密。违反攻击者使用缓存进行交流的能力的不同形式。我们表明,用于评估这些方案的分析以各种方式不完整,因为它们仅专注于秘密的渗透中的一个步骤。可以监视发射机地址使用的缓存线,我们通过提供通信过程的整体视图来扩大微观架构侧渠道的分析。影响随机映射的缓存的安全性,但通过先前的工作设计框架,即CASA忽略了,以全面和定量分析这些随机映射的缓存的安全性。除了进行定量分析的不同,我们利用电信领域的概念将安全性分析用于统计问题最新的随机映射缓存中使用的随机机制是不安全的。
It is well known that there are micro-architectural vulnerabilities that enable an attacker to use caches to exfiltrate secrets from a victim. These vulnerabilities exploit the fact that the attacker can detect cache lines that were accessed by the victim. Therefore, architects have looked at different forms of randomization to thwart the attacker’s ability to communicate using the cache. The security analysis of those randomly mapped caches is based upon the increased difficulty for the attacker to determine the addresses that touch the same cache line that the victim has accessedIn this paper, we show that the analyses used to evaluate those schemes were incomplete in various ways. For example, they were incomplete because they only focused on one of the steps used in the exfiltration of secrets. Specifically, the step that the attacker uses to determine the set of addresses that can monitor the cache lines used by the transmitter address. Instead, we broaden the analysis of micro-architecture side channels by providing an overall view of the communication process. This allows us to identify the existence of other communication steps that can also affect the security of randomly mapped caches, but have been ignored by prior workWe design an analysis framework, CaSA, to comprehensively and quantitatively analyze the security of these randomly mapped caches. We comprehensively consider the end-to-end communication steps and study the statistical relationship between different steps. In addition, to perform quantitative analysis, we leverage the concepts from the field of telecommunications to formulate the security analysis into a statistical problem. We use CaSA to evaluate a wide range of attack strategies and cache configurations. Our result shows that the randomization mechanisms used in the state-of-the-art randomly mapped caches are insecure.