A Benchmark Suite for Evaluating Caches' Vulnerability to Timing Attacks
Shuwen Deng, Wenjie Xiong, Jakub Szefer
Abstract
Timing-based side or covert channels in processor caches continue to present a threat to computer systems, and they are the key to many of the recent Spectre and Meltdown attacks. Based on improvements to an existing three-step model for cache timing-based attacks, this work presents 88 Strong types of theoretical timing-based vulnerabilities in processor caches. To understand and evaluate all possible types of vulnerabilities in processor caches, this work further presents and implements a new benchmark suite which can be used to test to which types of cache timing-based attacks a given processor or cache design is vulnerable. In total, there are 1094 automatically-generated test programs which cover the 88 theoretical vulnerabilities. The benchmark suite generates the Cache Timing Vulnerability Score which can be used to evaluate how vulnerable a specific cache implementation is to different attacks. A smaller Cache Timing Vulnerability Score means the design is more secure, and the scores among different machines can be easily compared. Evaluation is conducted on commodity Intel and AMD processors and shows the differences in processor implementations can result in different types of attacks that they are vulnerable to. Beyond testing commodity processors, the benchmarks and the Cache Timing Vulnerability Score can be used to help designers of new secure processor caches evaluate their design's susceptibility to cache timing-based attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers6
- DAGguise: mitigating memory timing side channelsPeter W. Deutsch, Yuheng Yang, Thomas Bourgeat, Jules Drean et al.ASPLOS 2022 · 19 citations
- Leaky Way: A Conflict-Based Cache Covert Channel Bypassing Set AssociativityYanan Guo, Xin Xin, Youtao Zhang, Jun YangMICRO 2022 · 19 citations
- Metior: A Comprehensive Model to Evaluate Obfuscating Side-Channel Defense SchemesPeter W. Deutsch, Weon Taek Na, Thomas Bourgeat, Joel S. Emer et al.ISCA 2023 · 15 citations
- Supporting Secure Multi-GPU Computing with Dynamic and Batched Metadata ManagementSeonjin Na, Jungwoo Kim, Sunho Lee, Jaehyuk HuhHPCA 2024 · 11 citations
- AutoCAT: Reinforcement Learning for Automated Exploration of Cache-Timing AttacksMulong Luo, Wenjie Xiong, Geunbae Lee, Yueying Li et al.HPCA 2023 · 3 citations
Builds on9
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB AttacksBen Gras, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaUSENIX Security 2018 · 357 citations
- ScatterCache: Thwarting Cache Attacks via Cache Set RandomizationMario Werner, Thomas Unterluggauer, Lukas Giner, Michael Schwarz et al.USENIX Security 2019 · 221 citations
- Attack Directories, Not Caches: Side Channel Attacks in a Non-Inclusive WorldMengjia Yan, Read Sprabery, Bhargava Gopireddy, Christopher W. Fletcher et al.S&P 2019 · 201 citations
Related papers
- SPEECHMINER: A Framework for Investigating and Measuring Speculative Execution VulnerabilitiesYuan Xiao, Yinqian Zhang, Radu TeodorescuNDSS 2020
- Leaking Information Through Cache LRU StatesWenjie Xiong, Jakub SzeferHPCA 2020 · 54 citations
- Speculative interference attacks: breaking invisible speculation schemesMohammad Behnia, Prateek Sahu, Riccardo Paccagnella, Jiyong Yu et al.ASPLOS 2021 · 69 citations
- InSpectre: Breaking and Fixing Microarchitectural Vulnerabilities by Formal AnalysisRoberto Guanciale, Musard Balliu, Mads DamCCS 2020 · 51 citations
- A Formal Approach for Detecting Vulnerabilities to Transient Execution Attacks in Out-of-Order ProcessorsMohammad Rahmani Fadiheh, Johannes Müller, Raik Brinkmann, Subhasish Mitra et al.DAC 2020 · 38 citations
