S&P2017

From Trash to Treasure: Timing-Sensitive Garbage Collection

Mathias V. Pedersen, Aslan Askarov

被引用 12 次

摘要

This paper studies information flows via timing channels in the presence of automatic memory management. We construct a series of example attacks that illustrate that garbage collectors form a shared resource that can be used to reliably leak sensitive information at a rate of up to 1 byte/sec on a contemporary general-purpose computer. The created channel is also observable across a network connection in a datacenter-like setting. We subsequently present a design of automatic memory management that is provably resilient against such attacks.