Leaky Way: A Conflict-Based Cache Covert Channel Bypassing Set Associativity
Yanan Guo, Xin Xin, Youtao Zhang, Jun Yang
Abstract
Modern 86 processors feature many prefetch instructions that developers can use to enhance performance. However, with some prefetch instructions, users can more directly manipulate cache states which may result in powerful cache covert channel and side channel attacks. In this work, we reverse-engineer the detailed cache behavior of PREFETCHNTA on various Intel processors. Based on the results, we first propose a new conflict-based cache covert channel named NTP+NTP. Prior conflict-based channels often require priming the cache set in order to cause cache conflicts. In contrast, in NTP+NTP, the data of the sender and receiver can compete for one specific way in the cache set, achieving cache conflicts without cache set priming for the first time. As a result, NTP+NTP has higher bandwidth than prior conflict-based channels such as Prime+Probe. The channel capacity of NTP+NTP is 302 KB/s. Second, we found that PREFETCHNTA can also be used to boost the performance of existing side channel attacks that utilize cache replacement states, making those attacks much more efficient than before.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d0e0e76f-48da-4a82-b1fa-96f06ec96bd8Cited by top-tier papers9
- Last-Level Cache Side-Channel Attacks Are Feasible in the Modern Public CloudZirui Neil Zhao, Adam Morrison, Christopher W. Fletcher, Josep TorrellasASPLOS 2024 · 20 citations
- TunneLs for Bootlegging: Fully Reverse-Engineering GPU TLBs for Challenging Isolation Guarantees of NVIDIA MIGZhenkai Zhang, Tyler N. Allen, Fan Yao, Xing Gao et al.CCS 2023 · 18 citations
- Uncore Encore: Covert Channels Exploiting Uncore Frequency ScalingYanan Guo, Dingyuan Cao, Xin Xin, Youtao Zhang et al.MICRO 2023 · 9 citations
- Prune+PlumTree - Finding Eviction Sets at ScaleTom Kessous, Niv GilboaS&P 2024 · 7 citations
- Bending microarchitectural weird machines towards practicalityPing-Lun Wang, Riccardo Paccagnella, Riad S. Wahby, Fraser BrownUSENIX Security 2024 · 2 citations
Builds on31
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz et al.USENIX Security 2016 · 500 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo et al.S&P 2019 · 408 citations
Related papers
- PREFETCHX: Cross-Core Cache-Agnostic Prefetcher-based Side-Channel AttacksYun Chen, Ali Hajiabadi, Lingfeng Pei, Trevor E. CarlsonHPCA 2024 · 15 citations
- Adversarial Prefetch: New Cross-Core Cache Side Channel AttacksYanan Guo, Andrew Zigerelli, Youtao Zhang, Jun YangS&P 2022 · 43 citations
- Prime+Scope: Overcoming the Observer Effect for High-Precision Cache Contention AttacksAntoon Purnal, Furkan Turan, Ingrid VerbauwhedeCCS 2021 · 55 citations
- Abusing Cache Line Dirty States to Leak Information in Commercial ProcessorsYujie Cui, Chun Yang, Xu ChengHPCA 2022 · 10 citations
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice et al.USENIX Security 2016 · 451 citations
