Principled Microarchitectural Isolation on Cloud CPUs
Stavros Volos, Cédric Fournet, Jana Hofmann, Boris Köpf, Oleksii Oleksenko
摘要
We present Marghera, a system design that prevents cross-VM microarchitectural side-channel attacks in the cloud. Marghera is based on isolation contracts which, for a given CPU, describe partitions of physical threads and memory that prevent information leakage through shared microarchitectural resources. We develop isolation contracts for the AMD EPYC 7543P, a modern cloud CPU. To this end, we first identify how microarchitectural resources are shared between its physical threads, including caches, cache-coherence directories, and DRAM banks. We then develop coloring schemes-that comprehensively partition these resourcesusing previously unknown, reverse-engineered indexing functions. We implement Marghera in Microsoft Hyper-V and evaluate it using cloud benchmarks. Our results show that our approach effectively eliminates side-channels caused by shared microarchitectural resources with small performance overheads. CCS CONCEPTS • Security and privacy → Virtualization and security; Sidechannel analysis and countermeasures; Hardware reverse engineering.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Understanding and Mitigating Covert Channel and Side Channel Vulnerabilities Introduced by RowHammer DefensesF. Nisa Bostanci, Oguzhan Canpolat, Ataberk Olgun, Ismail Emir Yüksel 等MICRO 2025 · 被引用 8 次
- HardHarvest: Hardware-Supported Core Harvesting for MicroservicesJovan Stojkovic, Chunao Liu, Muhammad Shahbaz, Josep TorrellasISCA 2025 · 被引用 4 次
- Gaussian Elimination of Side-Channels: Linear Algebra for Memory ColoringJana Hofmann, Cédric Fournet, Boris Köpf, Stavros VolosCCS 2024 · 被引用 2 次
- IOValve: Leakage-Free I/O Sandbox for Large-Scale Untrusted Data ProcessingSangho Lee, Jules Drean, Yue Tan, Marcus PeinadoCCS 2025 · 被引用 1 次
- Principled Design of Indexing Functions for Memory ColoringStephan Dübler, Jana Hofmann, Boris Köpf, Stavros VolosUSENIX Security 2026
它引用的顶会 Paper29
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz 等USENIX Security 2016 · 被引用 500 次
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck 等CCS 2019 · 被引用 464 次
相关 Paper
- A Software Approach to Defeating Side Channels in Last-Level CachesZiqiao Zhou, Michael K. Reiter, Yinqian ZhangCCS 2016 · 被引用 155 次
- MeshUp: Stateless Cache Side-channel Attack on CPU MeshJunpeng Wan, Yanxiang Bi, Zhe Zhou, Zhou LiS&P 2022 · 被引用 42 次
- HybCache: Hybrid Side-Channel-Resilient Caches for Trusted Execution EnvironmentsGhada Dessouky, Tommaso Frassetto, Ahmad-Reza SadeghiUSENIX Security 2020
- Enter, Exit, Page Fault, Leak : Testing Isolation Boundaries for Microarchitectural LeaksOleksii Oleksenko, Flavien Solt, Cédric Fournet, Jana Hofmann 等S&P 2026 · 被引用 4 次
- Cross-VM and Cross-Processor Covert Channels Exploiting Processor Idle Power ManagementPaizhuo Chen, Lei Li, Zhice YangUSENIX Security 2021 · 被引用 7 次
