I know What You Sync: Covert and Side Channel Attacks on File Systems via syncfs
Cheng Gu, Yicheng Zhang, Nael B. Abu-Ghazaleh
Abstract
Operating Systems enforce logical isolation using abstractions such as processes, containers, and isolation tech-nologies to protect a system from malicious or buggy code. In this paper, we show new types of side channels through the file system that break this logical isolation. The file system plays a critical role in the operating system, managing all I/O activities between the application layer and the physical storage device. We observe that the file system implementation is shared, leading to timing leakage when using common I/O system calls. Specifically, we found that modern operating systems take advantage of any flush operation (which saves cached blocks in memory to the SSD or disk) to flush all of the I/O buffers, even those used by other isolation domains. Thus, by measuring the delay of syncfs, the attacker can infer the I/O behavior of victim programs. We then demonstrate a syncfs covert channel attack on multiple file systems, including both Linux native file systems and the Windows file system, achieving a maximum bandwidth of 5 Kbps with an error rate of 0.15% on Linux and 7.6 Kbps with an error rate of 1.9% on Windows. In addition, we construct three side-channel attacks targeting both Linux and Android devices. On Linux devices, we implement a website fingerprinting attack and a video fingerprinting attack by tracking the write patterns of temporary buffering files. On Android devices, we design an application fingerprinting attack that leaks application write patterns during boot-up. The attacks achieve over 90% F1 score, precision, and recall. Finally, we demonstrate that these attacks can be exploited across containers implementing a container detection technique and a cross-container covert channel attack.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3fdd6a61-191b-49ab-b7d1-1692089cd808Cited by top-tier papers1
Ask how each one uses itBuilds on23
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz et al.USENIX Security 2016 · 500 citations
- Rendered Insecure: GPU Side Channel Attacks are PracticalHoda Naghibijouybari, Ajaya Neupane, Zhiyun Qian, Nael B. Abu-GhazalehCCS 2018 · 214 citations
- Lord of the Ring(s): Side Channel Attacks on the CPU On-Chip Ring Interconnect Are PracticalRiccardo Paccagnella, Licheng Luo, Christopher W. FletcherUSENIX Security 2021 · 121 citations
- No Pardon for the Interruption: New Inference Attacks on Android Through Interrupt Timing AnalysisWenrui Diao, Xiangyu Liu, Zhou Li, Kehuan ZhangS&P 2016 · 79 citations
- KeyDrown: Eliminating Software-Based Keystroke Timing Side-Channel AttacksMichael Schwarz, Moritz Lipp, Daniel Gruss, Samuel Weiser et al.NDSS 2018 · 68 citations
Related papers
- Sync+Sync: A Covert Channel Built on fsync with StorageQisheng Jiang, Chundong WangUSENIX Security 2024 · 12 citations
- Page Cache AttacksDaniel Gruss, Erik Kraft, Trishita Tiwari, Michael Schwarz et al.CCS 2019 · 55 citations
- KernelSnitch: Side Channel-Attacks on Kernel Data StructuresLukas Maar, Jonas Juffinger, Thomas Steinbauer, Daniel Gruss et al.NDSS 2025
- Secret Spilling Drive: Leaking User Behavior through SSD ContentionJonas Juffinger, Fabian Rauscher, Giuseppe La Manna, Daniel GrussNDSS 2025
- File Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification System on Linux, Windows, and macOSSudheendra Raghav Neela, Xufan Zhao, Jeanette Angelika Wultsch, Hannes Weissteiner et al.CCS 2026
