DAGguise: mitigating memory timing side channels
Peter W. Deutsch, Yuheng Yang, Thomas Bourgeat, Jules Drean, Joel S. Emer, Mengjia Yan
Abstract
This paper studies the mitigation of memory timing side channels, where attackers utilize contention within DRAM controllers to infer a victim's secrets. Already practical, this class of channels poses an important challenge to secure computing in shared memory environments.
Existing state-of-the-art memory timing side channel mitigations have several key performance and security limitations. Prior schemes require onerous static bandwidth partitioning, extensive profiling phases, or simply fail to protect against attacks which exploit fine-grained timing and bank information.
We present DAGguise, a defense mechanism which fully protects against memory timing side channels while allowing for dynamic traffic contention in order to achieve good performance. DAGguise utilizes a novel abstract memory access representation, the Directed Acyclic Request Graph (𝑟 DAG for short), to model memory access patterns which experience contention. DAGguise shapes a victim's memory access patterns according to a publicly known 𝑟 DAG obtained through a lightweight profiling stage, completely eliminating information leakage.
We formally verify the security of DAGguise, proving that it maintains strong security guarantees. Moreover, by allowing dynamic traffic contention, DAGguise achieves a 12% overall system speedup relative to Fixed Service, which is the state-of-the-art mitigation mechanism, with up to a 20% relative speedup for co-located applications which do not require protection. We further claim that the principles of DAGguise can be generalized to protect against other types of scheduler-based timing side channels, such as those targeting on-chip networks, or functional units in SMT cores.
• Security and privacy → Side-channel analysis and countermeasures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 18eb07ee-e136-41bf-9748-df914e4f28d3Cited by top-tier papers9
- SmartNIC Security Isolation in the Cloud with S-NICYang Zhou, Mark Wilkening, James Mickens, Minlan YuEuroSys 2024 · 25 citations
- Metior: A Comprehensive Model to Evaluate Obfuscating Side-Channel Defense SchemesPeter W. Deutsch, Weon Taek Na, Thomas Bourgeat, Joel S. Emer et al.ISCA 2023 · 15 citations
- Siloz: Leveraging DRAM Isolation Domains to Prevent Inter-VM RowhammerKevin Loughlin, Jonah Rosenblum, Stefan Saroiu, Alec Wolman et al.SOSP 2023 · 13 citations
- Veiled Pathways: Investigating Covert and Side Channels Within GPU UncoreYuanqing Miao, Yingtian Zhang, Dinghao Wu, Danfeng Zhang et al.MICRO 2024 · 8 citations
- Understanding and Mitigating Covert Channel and Side Channel Vulnerabilities Introduced by RowHammer DefensesF. Nisa Bostanci, Oguzhan Canpolat, Ataberk Olgun, Ismail Emir Yüksel et al.MICRO 2025 · 8 citations
Builds on7
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz et al.USENIX Security 2016 · 500 citations
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic et al.EuroSys 2020 · 381 citations
- Port Contention for Fun and ProfitAlejandro Cabrera Aldaya, Billy Bob Brumley, Sohaib ul Hassan, Cesar Pereida García et al.S&P 2019 · 240 citations
- CaSA: End-to-end Quantitative Security Analysis of Randomly Mapped CachesThomas Bourgeat, Jules Drean, Yuheng Yang, Lillian Tsai et al.MICRO 2020 · 41 citations
Related papers
- SecSMT: Securing SMT Processors against Contention-Based Covert ChannelsMohammadkazem Taram, Xida Ren, Ashish Venkat, Dean M. TullsenUSENIX Security 2022
- Don't Mesh Around: Side-Channel Attacks and Mitigations on Mesh InterconnectsMiles Dai, Riccardo Paccagnella, Miguel Gomez-Garcia, John D. McCalpin et al.USENIX Security 2022
- DOLMA: Securing Speculation with the Principle of Transient Non-ObservabilityKevin Loughlin, Ian Neal, Jiacheng Ma, Elisa Tsai et al.USENIX Security 2021 · 94 citations
- Quantifying and Mitigating Cache Side Channel Leakage with Differential SetCong Ma, Dinghao Wu, Gang Tan, Mahmut Taylan Kandemir et al.OOPSLA 2023 · 2 citations
- Jamais vu: thwarting microarchitectural replay attacksDimitrios Skarlatos, Zirui Neil Zhao, Riccardo Paccagnella, Christopher W. Fletcher et al.ASPLOS 2021 · 5 citations
