Covert Timing Channels Exploiting Non-Uniform Memory Access based Architectures

Covert Timing Channels Exploiting Non-Uniform Memory Access based Architectures
复制标题

利用基于非均匀内存访问的架构的隐蔽时序通道

DOI:
--
复制
发表时间:
2017
期刊:
ACM Great Lakes Symposium on VLSI
影响因子:
--
通讯作者:
M. Doroslovački
M. Doroslovački
中科院分区:
--
文献类型:
--
作者:
Fan Yao;Guru Venkataramani;M. Doroslovački

文献摘要

被引文献

相似文献

隐蔽定时通道是一类信息泄漏攻击,其中两个进程(即特洛伊木马和间谍)合谋意图偷偷地泄露特权信息,即使底层系统安全策略禁止两个进程之间的任何直接通信。在本文中,我们提出了一种新型的隐蔽定时通道,利用非均匀内存访问(NUMA)为基础的架构,特别是多插槽CPU的各种缓存之间的访问定时差。我们展示了一个现实的隐蔽定时通道上实现的双插槽英特尔至强服务器。然后,我们探讨使用统计分析技术来表征和量化的存在下,隐蔽的时间通道活动。我们的实验结果表明,这种量化技术可能是一个有用的第一步,制定一个有效的防御基于NUMA的隐蔽定时通道。
Covert timing channels are a class of information leakage attacks where two processes, namely the trojan and spy, collude with intent to stealthily exfiltrate privileged information even when the underlying system security policy prohibits any direct communication between the two processes. In this paper, we present a new type of covert timing channel that exploits the access timing difference between various caches in Non-Uniform Memory Access (NUMA)-based architectures, especially multi-socket CPUs. We demonstrate a realistic covert timing channel implemented on a dual-socket Intel Xeon server. We then explore use of statistical analysis techniques to characterize and quantify the presence of covert timing channel activity. Our experimental results show that such quantification techniques could be a useful first step in formulating an effective defense against NUMA-based covert timing channels.