Unveiling your keystrokes: A Cache-based Side-channel Attack on Graphics Libraries
Daimeng Wang, Ajaya Neupane, Zhiyun Qian, Nael B. Abu-Ghazaleh, Srikanth V. Krishnamurthy, Edward J. M. Colbert, Paul L. Yu
Abstract
Operating systems use shared memory to improve performance. However, as shown in recent studies, attackers can exploit CPU cache side-channels associated with shared memory to extract sensitive information. The attacks that were previously attempted typically only detect the presence of a certain operation and require significant manual analysis to identify and evaluate their effectiveness. Moreover, very few of them target graphics libraries which are commonly used, but difficult to attack. In this paper, we consider the execution time of shared libraries as the side-channel, and showcase a completely automated technique to discover and select exploitable side-channels on shared graphics libraries. In essence, we first collect the cache lines accessed by a victim process during different key presses offline, and then use machine learning to infer the best cache lines (e.g., easily measurable, robust to noise, high information leakage) for a flush and reload attack. We are able to discover effective strategies to classify what keys have been pressed. Using this approach, we not only preclude the need for manual analyses of code and traces — the automated system discovered many previously unknown sidechannels of the type we are interested in, but also achieve high precision in terms of inferring the sensitive information entered on desktop and Android platforms. We show that our approach infers the passwords with lowercase letters and numbers 10,000 1,000,000 times faster than random guessing. For a large fraction of PINs consisting of 4 to 6 digits, we are able to infer them within 20 and 80 guesses respectively. Finally, we suggest ways to mitigate these attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7146439b-3cec-494e-bda7-495456f40c70Cited by top-tier papers21
- : Practical Cache Attacks from the NetworkMichael Kurth, Ben Gras, Dennis Andriesse, Cristiano Giuffrida et al.S&P 2020 · 78 citations
- Invisible Probe: Timing Attacks with PCIe Congestion Side-channelMingtian Tan, Junpeng Wan, Zhe Zhou, Zhou LiS&P 2021 · 52 citations
- Adversarial Prefetch: New Cross-Core Cache Side Channel AttacksYanan Guo, Andrew Zigerelli, Youtao Zhang, Jun YangS&P 2022 · 43 citations
- MeshUp: Stateless Cache Side-channel Attack on CPU MeshJunpeng Wan, Yanxiang Bi, Zhe Zhou, Zhou LiS&P 2022 · 42 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
Builds on8
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim et al.USENIX Security 2017 · 536 citations
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice et al.USENIX Security 2016 · 451 citations
- Leaky Cauldron on the Dark Land: Understanding Memory Side-Channel Hazards in SGXWenhao Wang, Guoxing Chen, Xiaorui Pan, Yinqian Zhang et al.CCS 2017 · 403 citations
- Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLRDaniel Gruss, Clémentine Maurice, Anders Fogh, Moritz Lipp et al.CCS 2016 · 278 citations
- Attack Directories, Not Caches: Side Channel Attacks in a Non-Inclusive WorldMengjia Yan, Read Sprabery, Bhargava Gopireddy, Christopher W. Fletcher et al.S&P 2019 · 201 citations
Related papers
- How to 0wn the NAS in Your Spare TimeSanghyun Hong, Michael Davinroy, Yigitcan Kaya, Dana Dachman-Soled et al.ICLR 2020 · 4 citations
- Return-Oriented Flush-Reload Side Channels on ARM and Their Implications for Android DevicesXiaokuan Zhang, Yuan Xiao, Yinqian ZhangCCS 2016 · 77 citations
- Page Cache AttacksDaniel Gruss, Erik Kraft, Trishita Tiwari, Michael Schwarz et al.CCS 2019 · 55 citations
- Eavesdropping user credentials via GPU side channels on smartphonesBoyuan Yang, Ruirong Chen, Kai Huang, Jun Yang et al.ASPLOS 2022 · 12 citations
- There's always a bigger fish: a clarifying analysis of a machine-learning-assisted side-channel attackJack Cook, Jules Drean, Jonathan Behrens, Mengjia YanISCA 2022 · 35 citations
