Eviction Notice: Reviving and Advancing Page Cache Attacks
Sudheendra Raghav Neela, Jonas Juffinger, Lukas Maar, Daniel Gruss
摘要
—Page cache attacks are hardware-agnostic and can have a high temporal and spatial resolution. With mitigations deployed since 2019, only Evict+Reload-style timing measurements remain, but suffer from a very low temporal resolution and a high impact on system performance due to eviction. In this paper, we show that the problem of page cache attacks is significantly larger than anticipated. We first present a new systematic approach to page cache attacks based on four primitives: flush, reload, evict, and monitor. From these primitives, we derive five generic attack techniques on the page cache: Flush+ Monitor, Flush+Reload, Flush+Flush, Evict+Monitor, and Evict+ Reload. We show mechanisms for all primitives that operate on fully up-to-date Linux kernels, bypassing existing mitigations. We demonstrate the practicality of our revived page cache attacks in three scenarios, showing that we advance the state of the art by orders of magnitude in terms of spatial and temporal attack resolution: First, the channel capacity with our fastest attack (Flush+Monitor) achieves an average capacity of 37 . 7 kB/s in a cross-process covert channel. Second, for low-frequency attacks, we demonstrate inter-keystroke timing and event detection attacks across processes, with a spatial resolution of 4 kB and a temporal resolution of 0 . 8 µs, improving the state of the art by 6 orders of magnitude. Third, in a website-fingerprinting attack, we achieve an F 1 score of 90 . 54 % in a top-100 closed-world scenario. We conclude that further mitigations are necessary against the page cache side channel.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper23
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz 等USENIX Security 2016 · 被引用 500 次
- Another Flip in the Wall of Rowhammer DefensesDaniel Gruss, Moritz Lipp, Michael Schwarz, Daniel Genkin 等S&P 2018 · 被引用 288 次
- ASLR on the Line: Practical Cache Attacks on the MMUBen Gras, Kaveh Razavi, Erik Bosman, Herbert Bos 等NDSS 2017 · 被引用 276 次
- Hello from the Other Side: SSH over Robust Cache Covert Channels in the CloudClémentine Maurice, Manuel Weber, Michael Schwarz, Lukas Giner 等NDSS 2017 · 被引用 174 次
- Cloak and Dagger: From Two Permissions to Complete Control of the UI Feedback LoopYanick Fratantonio, Chenxiong Qian, Simon P. Chung, Wenke LeeS&P 2017 · 被引用 126 次
相关 Paper
- Page Cache AttacksDaniel Gruss, Erik Kraft, Trishita Tiwari, Michael Schwarz 等CCS 2019 · 被引用 55 次
- A Systematic Evaluation of Novel and Existing Cache Side ChannelsFabian Rauscher, Carina Fiedler, Andreas Kogler, Daniel GrussNDSS 2025
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice 等USENIX Security 2016 · 被引用 451 次
- I know What You Sync: Covert and Side Channel Attacks on File Systems via syncfsCheng Gu, Yicheng Zhang, Nael B. Abu-GhazalehS&P 2025
- GhostCache: Timer- and Counter-Free Cache Attacks Exploiting Weak Coherence on RISC-V and ARM ChipsYu Jin, Minghong Sun, Dongsheng Wang, Pengfei Qiu 等CCS 2025
