CaSA: End-to-end Quantitative Security Analysis of Randomly Mapped Caches
Thomas Bourgeat, Jules Drean, Yuheng Yang, Lillian Tsai, Joel S. Emer, Mengjia Yan
摘要
It is well known that there are micro-architectural vulnerabilities that enable an attacker to use caches to exfiltrate secrets from a victim. These vulnerabilities exploit the fact that the attacker can detect cache lines that were accessed by the victim. Therefore, architects have looked at different forms of randomization to thwart the attacker's ability to communicate using the cache. The security analysis of those randomly mapped caches is based upon the increased difficulty for the attacker to determine the addresses that touch the same cache line that the victim has accessed.
In this paper, we show that the analyses used to evaluate those schemes were incomplete in various ways. For example, they were incomplete because they only focused on one of the steps used in the exfiltration of secrets. Specifically, the step that the attacker uses to determine the set of addresses that can monitor the cache lines used by the transmitter address. Instead, we broaden the analysis of micro-architecture side channels by providing an overall view of the communication process. This allows us to identify the existence of other communication steps that can also affect the security of randomly mapped caches, but have been ignored by prior work.
We design an analysis framework, CaSA, to comprehensively and quantitatively analyze the security of these randomly mapped caches. We comprehensively consider the end-to-end communication steps and study the statistical relationship between different steps. In addition, to perform quantitative analysis, we leverage the concepts from the field of telecommunications to formulate the security analysis into a statistical problem. We use CaSA to evaluate a wide range of attack strategies and cache configurations. Our result shows that the randomization mechanisms used in the state-of-the-art randomly mapped caches are insecure.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- MeshUp: Stateless Cache Side-channel Attack on CPU MeshJunpeng Wan, Yanxiang Bi, Zhe Zhou, Zhou LiS&P 2022 · 被引用 42 次
- MOESI-prime: preventing coherence-induced hammering in commodity workloadsKevin Loughlin, Stefan Saroiu, Alec Wolman, Yatin A. Manerkar 等ISCA 2022 · 被引用 34 次
- Opening Pandora's Box: A Systematic Study of New Ways Microarchitecture Can Leak Private DataJose Rodrigo Sanchez Vicarte, Pradyumna Shome, Nandeeka Nayak, Caroline Trippel 等ISCA 2021 · 被引用 29 次
- DAGguise: mitigating memory timing side channelsPeter W. Deutsch, Yuheng Yang, Thomas Bourgeat, Jules Drean 等ASPLOS 2022 · 被引用 19 次
- Metior: A Comprehensive Model to Evaluate Obfuscating Side-Channel Defense SchemesPeter W. Deutsch, Weon Taek Na, Thomas Bourgeat, Joel S. Emer 等ISCA 2023 · 被引用 15 次
它引用的顶会 Paper13
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice 等USENIX Security 2016 · 被引用 451 次
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp 等USENIX Security 2019 · 被引用 442 次
- Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLRDaniel Gruss, Clémentine Maurice, Anders Fogh, Moritz Lipp 等CCS 2016 · 被引用 278 次
相关 Paper
- Systematic Analysis of Randomization-based Protected Cache ArchitecturesAntoon Purnal, Lukas Giner, Daniel Gruss, Ingrid VerbauwhedeS&P 2021 · 被引用 93 次
- Are Randomized Caches Truly Random? Formal Analysis of Randomized-Partitioned CachesAnirban Chakraborty, Sarani Bhattacharya, Sayandeep Saha, Debdeep MukhopadhyayHPCA 2023 · 被引用 5 次
- Safecracker: Leaking Secrets through Compressed CachesPo-An Tsai, Andrés Sánchez, Christopher W. Fletcher, Daniel SánchezASPLOS 2020 · 被引用 23 次
- Systematic Evaluation of Randomized Cache Designs against Cache OccupancyAnirban Chakraborty, Nimish Mishra, Sayandeep Saha, Sarani Bhattacharya 等USENIX Security 2025
- PhantomCache: Obfuscating Cache Conflicts with Localized RandomizationQinhan Tan, Zhihua Zeng, Kai Bu, Kui RenNDSS 2020
