KernelSnitch: Side Channel-Attacks on Kernel Data Structures
Lukas Maar, Jonas Juffinger, Thomas Steinbauer, Daniel Gruss, Stefan Mangard
摘要
The sharing of hardware elements, such as caches, is known to introduce microarchitectural side-channel leakage. One approach to eliminate this leakage is to not share hardware elements across security domains. However, even under the assumption of leakage-free hardware, it is unclear whether other critical system components, like the operating system, introduce software-caused side-channel leakage.
In this paper, we present a novel generic software side-channel attack, KernelSnitch, targeting kernel data structures such as hash tables and trees. These structures are commonly used to store both kernel and user information, e.g., metadata for userspace locks. KernelSnitch exploits that these data structures are variable in size, ranging from an empty state to a theoretically arbitrary amount of elements. Accessing these structures requires a variable amount of time depending on the number of elements, i.e., the occupancy level. This variance constitutes a timing side channel, observable from user space by an unprivileged, isolated attacker. While the timing differences are very low compared to the syscall runtime, we demonstrate and evaluate methods to amplify these timing differences reliably. In three case studies, we show that KernelSnitch allows unprivileged and isolated attackers to leak sensitive information from the kernel and activities in other processes. First, we demonstrate covert channels with transmission rates up to 580 kbit/s. Second, we perform a kernel heap pointer leak in less than 65 s by exploiting the specific indexing that Linux is using in hash tables. Third, we demonstrate a website fingerprinting attack, achieving an F1 score of more than 89 %, showing that activity in other user programs can be observed using KernelSnitch. Finally, we discuss mitigations for our hardware-agnostic attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- MettEagle: Costs and Benefits of Implementing Containers on MicrokernelsTill Miemietz, Viktor Reusch, Matthias Hille, Lars Wrenger 等OSDI 2025 · 被引用 2 次
- Eviction Notice: Reviving and Advancing Page Cache AttacksSudheendra Raghav Neela, Jonas Juffinger, Lukas Maar, Daniel GrussNDSS 2026 · 被引用 2 次
- Attacks on Approximate Caches in Text-to-Image Diffusion ModelsDesen Sun, Shuncheng Jie, Sihang LiuUSENIX Security 2026 · 被引用 1 次
- Cross-Cache Attacks for the Linux Kernel via PCP MassagingClaudio Migliorelli, Andrea Mambretti, Alessandro Sorniotti, Vittorio Zaccaria 等NDSS 2026
- When Good Kernel Defenses Go Bad: Reliable and Stable Kernel Exploits via Defense-Amplified TLB Side-Channel LeaksLukas Maar, Lukas Giner, Daniel Gruss, Stefan MangardUSENIX Security 2025
它引用的顶会 Paper24
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLRDaniel Gruss, Clémentine Maurice, Anders Fogh, Moritz Lipp 等CCS 2016 · 被引用 278 次
- Port Contention for Fun and ProfitAlejandro Cabrera Aldaya, Billy Bob Brumley, Sohaib ul Hassan, Cesar Pereida García 等S&P 2019 · 被引用 240 次
相关 Paper
- Page Cache AttacksDaniel Gruss, Erik Kraft, Trishita Tiwari, Michael Schwarz 等CCS 2019 · 被引用 55 次
- I know What You Sync: Covert and Side Channel Attacks on File Systems via syncfsCheng Gu, Yicheng Zhang, Nael B. Abu-GhazalehS&P 2025
- IdleLeak: Exploiting Idle State Side Effects for Information LeakageFabian Rauscher, Andreas Kogler, Jonas Juffinger, Daniel GrussNDSS 2024
- RISCy Cache Coherence: Timer-Free Architectural Cache Attacks via Instruction/Data Cache IncoherenceFabian Thomas, Michael SchwarzS&P 2026 · 被引用 1 次
- MetaLeak: Uncovering Side Channels in Secure Processor Architectures Exploiting MetadataMd Hafizul Islam Chowdhuryy, Hao Zheng, Fan YaoISCA 2024 · 被引用 3 次
