Microarchitectural Minefields: 4K-Aliasing Covert Channel and Multi-Tenant Detection in Iaas Clouds
Dean Sullivan, Orlando Arias, Travis Meade, Yier Jin
Abstract
We introduce a new microarchitectural timing covert channel using the processor memory order buffer (MOB). Specifically, we show how an adversary can infer the state of a spy process on the Intel 64 and IA-32 architectures when predicting dependent loads through the store buffer, called 4K-aliasing. The 4K-aliasing event is a side-effect of memory disambiguation misprediction while handling write-after-read data hazards wherein the lower 12-bits of a load address will falsely match with store addresses resident in the MOB. In this work, we extensively analyze 4K-aliasing and demonstrate a new timing channel measureable across processes when executed as hyperthreads. We then use 4K-aliasing to build a robust covert communication channel on both the Amazon EC2 and Google Compute Engine capable of communicating at speeds of 1.28 Mbps and 1.49 Mbps, respectively. In addition, we show that 4K-aliasing can also be used to reliably detect multi-tenancy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3eb15721-1cb6-4043-a148-3aa7bfffe249Cited by top-tier papers17
- Lord of the Ring(s): Side Channel Attacks on the CPU On-Chip Ring Interconnect Are PracticalRiccardo Paccagnella, Licheng Luo, Christopher W. FletcherUSENIX Security 2021 · 121 citations
- SPOILER: Speculative Load Hazards Boost Rowhammer and Cache AttacksSaad Islam, Ahmad Moghimi, Ida Bruhns, Moritz Krebbel et al.USENIX Security 2019 · 86 citations
- Osiris: Automated Discovery of Microarchitectural Side ChannelsDaniel Weber, Ahmad Ibrahim, Hamed Nemati, Michael Schwarz et al.USENIX Security 2021 · 75 citations
- Racing in Hyperspace: Closing Hyper-Threading Side Channels on SGX with Contrived Data RacesGuoxing Chen, Wenhao Wang, Tianyu Chen, Sanchuan Chen et al.S&P 2018 · 70 citations
- Houdini's Escape: Breaking the Resource Rein of Linux Control GroupsXing Gao, Zhongshu Gu, Zhengfa Li, Hani Jamjoom et al.CCS 2019 · 62 citations
Builds on2
- Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLRDaniel Gruss, Clémentine Maurice, Anders Fogh, Moritz Lipp et al.CCS 2016 · 278 citations
- Covert Channels through Random Number Generator: Mechanisms, Capacity Estimation and MitigationsDmitry Evtyushkin, Dmitry V. PonomarevCCS 2016 · 75 citations
Related papers
- Leaky Way: A Conflict-Based Cache Covert Channel Bypassing Set AssociativityYanan Guo, Xin Xin, Youtao Zhang, Jun YangMICRO 2022 · 19 citations
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz et al.USENIX Security 2016 · 500 citations
- Exploitation of Security Vulnerability on RetirementKe Xu, Ming Tang, Quancheng Wang, Han WangHPCA 2024 · 3 citations
- Leaking Information Through Cache LRU StatesWenjie Xiong, Jakub SzeferHPCA 2020 · 54 citations
- Abusing Cache Line Dirty States to Leak Information in Commercial ProcessorsYujie Cui, Chun Yang, Xu ChengHPCA 2022 · 10 citations
