USENIX Security2019Top-tier venue
Pythia: Remote Oracles for the Masses
Shin-Yeh Tsai, Mathias Payer, Yiying Zhang
Abstract
Remote Direct Memory Access (RDMA) is a technology that allows direct access from the network to a machine's main memory without involving its CPU. RDMA offers lowlatency, high-bandwidth performance and low CPU utilization. While RDMA provides massive performance boosts and has thus been adopted by several major cloud providers, security concerns have so far been neglected. The need for RDMA NICs to bypass CPU and directly access memory results in them storing various metadata like page table entries in their on-board SRAM. When the SRAM is full, RNICs swap metadata to main memory across the PCIe bus. We exploit the resulting timing difference to establish side channels and demonstrate that these side channels can leak access patterns of victim nodes to other nodes. We design Pythia, a set of RDMA-based remote sidechannel attacks that allow an attacker on one client machine to learn how victims on other client machines access data a server exports as an in-memory data service. We reverse engineer the memory architecture of the most widely used RDMA NIC and use this knowledge to improve the efficiency of Pythia. We further extend Pythia to build side-channel attacks on Crail, a real RDMA-based key-value store application. We evaluated Pythia on four different RDMA NICs both in a laboratory and in a public cloud setting. Pythia is fast (57 µs), accurate (97% accuracy), and can hide all its traces from the victim or the server.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 88b18282-a783-4bc7-afe8-9c29586cabedCited by top-tier papers13
- Clio: a hardware-software co-designed disaggregated memory systemZhiyuan Guo, Yizhou Shan, Xuhao Luo, Yutong Huang et al.ASPLOS 2022 · 110 citations
- Understanding RDMA Microarchitecture Resources for Performance IsolationXinhao Kong, Jingrong Chen, Wei Bai, Yechen Xu et al.NSDI 2023 · 81 citations
- sRDMA - Efficient NIC-based Authentication and Encryption for Remote Direct Memory AccessKonstantin Taranov, Benjamin Rothenberger, Adrian Perrig, Torsten HoeflerUSENIX ATC 2020 · 59 citations
- ReDMArk: Bypassing RDMA Security MechanismsBenjamin Rothenberger, Konstantin Taranov, Adrian Perrig, Torsten HoeflerUSENIX Security 2021 · 56 citations
- Invisible Probe: Timing Attacks with PCIe Congestion Side-channelMingtian Tan, Junpeng Wan, Zhe Zhou, Zhou LiS&P 2021 · 52 citations
Builds on9
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB AttacksBen Gras, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaUSENIX Security 2018 · 357 citations
- SMoTherSpectre: Exploiting Speculative Execution through Port ContentionAtri Bhattacharyya, Alexandra Sandulescu, Matthias Neugschwandtner, Alessandro Sorniotti et al.CCS 2019 · 267 citations
Related papers
- Bedrock: Programmable Network Support for Secure RDMA SystemsJiarong Xing, Kuo-Feng Hsu, Yiming Qiu, Ziyang Yang et al.USENIX Security 2022
- Ragnar: Exploring Volatile-Channel Vulnerabilities on RDMA NICYunpeng Xu, Yuchen Fan, Teng Ma, Shuwen DengDAC 2025 · 1 citation
- DevIOus: Device-Driven Side-Channel Attacks on the IOMMUTaehun Kim, Hyeongjin Park, Seokmin Lee, Seunghee Shin et al.S&P 2023
- Remote Direct Memory IntrospectionHongyi Liu, Jiarong Xing, Yibo Huang, Danyang Zhuo et al.USENIX Security 2023
- INSERT: In-Network Stateful End-to-End RDMA TelemetryHyunseok Chang, Walid A. Hanafy, Sarit Mukherjee, Limin WangINFOCOM 2024 · 3 citations
