Prime+Scope: Overcoming the Observer Effect for High-Precision Cache Contention Attacks
Antoon Purnal, Furkan Turan, Ingrid Verbauwhede
摘要
Modern processors expose software to information leakage through shared microarchitectural state. One of the most severe leakage channels is cache contention, exploited by attacks referred to as Prime+Probe, which can infer fine-grained memory access patterns while placing only limited assumptions on attacker capabilities.
In this work, we strengthen the cache contention channel with a near-optimal time resolution. We propose Prime+Scope, a crosscore cache contention attack that performs back-to-back cache contention measurements that access only a single cache line. It offers a time resolution of around 70 cycles (25ns), while maintaining the wide applicability of Prime+Probe. To enable such a rapid measurement, we rely on the deterministic nature of modern replacement policies and their (non-)interaction across cache levels. We provide a methodology to, essentially, prepare multiple cache levels simultaneously, and apply it to Intel processors with both inclusive and non-inclusive cache hierarchies. We characterize the resolution of Prime+Scope, and confirm it with a cross-core covert channel (capacity up to 3.5 Mbps, no shared memory) and an improved attack on AES T-tables. Finally, we use the properties underlying Prime+Scope to bootstrap the construction of the eviction sets needed for the attack. The resulting routine outperforms state-of-the-art techniques by two orders of magnitude.
Ultimately, our work shows that interference through cache contention can provide richer temporal precision than state-of-theart attacks that directly interact with monitored memory addresses.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper45
- Adversarial Prefetch: New Cross-Core Cache Side Channel AttacksYanan Guo, Andrew Zigerelli, Youtao Zhang, Jun YangS&P 2022 · 被引用 43 次
- MeshUp: Stateless Cache Side-channel Attack on CPU MeshJunpeng Wan, Yanxiang Bi, Zhe Zhou, Zhou LiS&P 2022 · 被引用 42 次
- Last-Level Cache Side-Channel Attacks Are Feasible in the Modern Public CloudZirui Neil Zhao, Adam Morrison, Christopher W. Fletcher, Josep TorrellasASPLOS 2024 · 被引用 20 次
- Leaky Way: A Conflict-Based Cache Covert Channel Bypassing Set AssociativityYanan Guo, Xin Xin, Youtao Zhang, Jun YangMICRO 2022 · 被引用 19 次
- Phantom: Exploiting Decoder-detectable MispredictionsJohannes Wikner, Daniël Trujillo, Kaveh RazaviMICRO 2023 · 被引用 19 次
它引用的顶会 Paper28
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 被引用 649 次
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz 等USENIX Security 2016 · 被引用 500 次
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck 等CCS 2019 · 被引用 464 次
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice 等USENIX Security 2016 · 被引用 451 次
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo 等S&P 2019 · 被引用 408 次
相关 Paper
- Spec-o-Scope: Cache Probing at Cache SpeedGal Horowitz, Eyal Ronen, Yuval YaromCCS 2024 · 被引用 4 次
- A Systematic Evaluation of Novel and Existing Cache Side ChannelsFabian Rauscher, Carina Fiedler, Andreas Kogler, Daniel GrussNDSS 2025
- Prime+Abort: A Timer-Free High-Precision L3 Cache Attack using Intel TSXCraig Disselkoen, David Kohlbrenner, Leo Porter, Dean M. TullsenUSENIX Security 2017 · 被引用 186 次
- DPrime+DAbort: A High-Precision and Timer-Free Directory-Based Side-Channel Attack in Non-Inclusive Cache Hierarchies using Intel TSXSowoong Kim, Myeonggyun Han, Woongki BaekHPCA 2022 · 被引用 6 次
- ClepsydraCache - Preventing Cache Attacks with Time-Based EvictionsJan Philipp Thoma, Christian Niesler, Dominic A. Funke, Gregor Leander 等USENIX Security 2023
