Randomized Last-Level Caches Are Still Vulnerable to Cache Side-Channel Attacks! But We Can Fix It
Wei Song, Boya Li, Zihan Xue, Zhenzhen Li, Wenhao Wang, Peng Liu
摘要
Cache randomization has recently been revived as a promising defense against conflict-based cache side-channel attacks. As two of the latest implementations, CEASER-S and ScatterCache both claim to thwart conflict-based cache side-channel attacks using randomized skewed caches. Unfortunately, our experiments show that an attacker can easily find a usable eviction set within the chosen remap period of CEASER-S and increasing the number of partitions without dynamic remapping, such as ScatterCache, cannot eliminate the threat. By quantitatively analyzing the access patterns left by various attacks in the LLC, we have newly discovered several problems with the hypotheses and implementations of randomized caches, which are also overlooked by the research on conflict-based cache side-channel attacks.However, cache randomization is not a false hope and it is an effective defense that should be widely adopted in future processors. The newly discovered problems are corresponding to flaws associated with the existing implementation of cache randomization and are fixable. Several new defense ideas are proposed in this paper. Our experiments show that all the newly discovered problems are fixed within the current performance budget. We also argue that randomized set-associative caches can be sufficiently strengthened and possess a better chance to be actually adopted in commercial processors than their skewed counterparts because they introduce less overhaul to the existing cache structure.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper16
- MeshUp: Stateless Cache Side-channel Attack on CPU MeshJunpeng Wan, Yanxiang Bi, Zhe Zhou, Zhou LiS&P 2022 · 被引用 42 次
- Last-Level Cache Side-Channel Attacks Are Feasible in the Modern Public CloudZirui Neil Zhao, Adam Morrison, Christopher W. Fletcher, Josep TorrellasASPLOS 2024 · 被引用 20 次
- The Maya Cache: A Storage-efficient and Secure Fully-associative Last-level CacheAnubhav Bhatla, Navneet, Biswabandan PandaISCA 2024 · 被引用 12 次
- Abusing Cache Line Dirty States to Leak Information in Commercial ProcessorsYujie Cui, Chun Yang, Xu ChengHPCA 2022 · 被引用 10 次
- Cache Refinement Type for Side-Channel Detection of Cryptographic SoftwareKe Jiang, Yuyan Bao, Shuai Wang, Zhibo Liu 等CCS 2022 · 被引用 7 次
它引用的顶会 Paper7
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLRDaniel Gruss, Clémentine Maurice, Anders Fogh, Moritz Lipp 等CCS 2016 · 被引用 278 次
- ScatterCache: Thwarting Cache Attacks via Cache Set RandomizationMario Werner, Thomas Unterluggauer, Lukas Giner, Michael Schwarz 等USENIX Security 2019 · 被引用 221 次
- Theory and Practice of Finding Eviction SetsPepe Vila, Boris Köpf, José F. MoralesS&P 2019 · 被引用 145 次
相关 Paper
- Are Randomized Caches Truly Random? Formal Analysis of Randomized-Partitioned CachesAnirban Chakraborty, Sarani Bhattacharya, Sayandeep Saha, Debdeep MukhopadhyayHPCA 2023 · 被引用 5 次
- Systematic Analysis of Randomization-based Protected Cache ArchitecturesAntoon Purnal, Lukas Giner, Daniel Gruss, Ingrid VerbauwhedeS&P 2021 · 被引用 93 次
- Systematic Evaluation of Randomized Cache Designs against Cache OccupancyAnirban Chakraborty, Nimish Mishra, Sayandeep Saha, Sarani Bhattacharya 等USENIX Security 2025
- SoK: So, You Think You Know All About Secure Randomized Caches?Anubhav Bhatla, Hari Rohit Bhavsar, Sayandeep Saha, Biswabandan PandaUSENIX Security 2025
- SeqAss: Using SeqUential Associative Caches to Mitigate Conflict-Based Cache Attacks with Reduced Cache Misses and Performance OverheadWei Song, Zhidong Wang, Jinchi Han, Da Xie 等S&P 2026
