Double Trouble: Combined Heterogeneous Attacks on Non-Inclusive Cache Hierarchies
Antoon Purnal, Furkan Turan, Ingrid Verbauwhede
摘要
As the performance of general-purpose processors faces diminishing improvements, computing systems are increasingly equipped with domain-specific accelerators. Today's high-end servers tightly integrate such accelerators with the CPU, e.g., giving them direct access to the CPU's last-level cache (LLC). Caches are an important source of information leakage across security domains. This work explores combined cache attacks, complementing traditional co-tenancy with control over one or more accelerators. The constraints imposed on these accelerators, originally perceived as limitations, turn out to be advantageous to an attacker. We develop a novel approach for accelerators to find eviction sets, and leverage precise double-sided control over cache lines to expose undocumented behavior in non-inclusive Intel cache hierarchies. We develop a compact and extensible FPGA hardware accelerator to demonstrate our findings. It constructs eviction sets at unprecedented speeds (< 200 µs), outperforming existing techniques with one to three orders of magnitude. It maintains excellent performance, even under high noise pressure. We also use the accelerator to set up a covert channel with fine spatial granularity, encoding more than 3 bits per cache set. Furthermore, it can efficiently evict shared targets with tiny eviction sets, refuting the common assumption that eviction sets must be as large as the cache associativity.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Leaky Way: A Conflict-Based Cache Covert Channel Bypassing Set AssociativityYanan Guo, Xin Xin, Youtao Zhang, Jun YangMICRO 2022 · 被引用 19 次
- Hacky Racers: Exploiting Instruction-Level Parallelism to Generate Stealthy Fine-Grained TimersHaocheng Xiao, Sam AinsworthASPLOS 2023 · 被引用 11 次
- A4: Microarchitecture-Aware LLC Management for Datacenter Servers with Emerging I/O DevicesHaneul Park, Jiaqi Lou, Sangjin Lee, Yifan Yuan 等ISCA 2025 · 被引用 2 次
- Practice Makes (Im)Perfect: A Look Back at Benchmarking Practices for Microarchitectural Side-Channel AttacksIliana Fayolle, Antoine Geimer, Daniel De Almeida Braga, Clémentine MauriceCCS 2026
它引用的顶会 Paper22
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz 等USENIX Security 2016 · 被引用 500 次
- Drammer: Deterministic Rowhammer Attacks on Mobile PlatformsVictor van der Veen, Yanick Fratantonio, Martina Lindorfer, Daniel Gruss 等CCS 2016 · 被引用 381 次
- Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLRDaniel Gruss, Clémentine Maurice, Anders Fogh, Moritz Lipp 等CCS 2016 · 被引用 278 次
相关 Paper
- ZenLeak: Practical Last-Level Cache Side-Channel Attacks on AMD Zen ProcessorsHan Wang, Ming Tang, Quancheng Wang, Ke Xu 等DAC 2025 · 被引用 2 次
- Leaky Buddies: Cross-Component Covert Channels on Integrated CPU-GPU SystemsSankha Baran Dutta, Hoda Naghibijouybari, Nael B. Abu-Ghazaleh, Andres Marquez 等ISCA 2021 · 被引用 36 次
- Slice+Slice Baby: Generating Last-Level Cache Eviction Sets in the Blink of an EyeBradley Morgan, Gal Horowitz, Sioli O'Connell, Stephan van Schaik 等S&P 2025
- ScatterCache: Thwarting Cache Attacks via Cache Set RandomizationMario Werner, Thomas Unterluggauer, Lukas Giner, Michael Schwarz 等USENIX Security 2019 · 被引用 221 次
- HybCache: Hybrid Side-Channel-Resilient Caches for Trusted Execution EnvironmentsGhada Dessouky, Tommaso Frassetto, Ahmad-Reza SadeghiUSENIX Security 2020
