Projekte pro Jahr
Abstract
Research on cache attacks has shown that CPU caches leak significant information. Proposed detection mechanisms assume that all cache attacks cause more cache hits and cache misses than benign applications and use hardware performance counters for detection. In this article, we show that this assumption does not hold by developing a novel attack technique: the Flush+Flush attack. The Flush+Flush attack only relies on the execution time of the flush instruction, which depends on whether data is cached or not. Flush+Flush does not make any memory accesses, contrary to any other cache attack. Thus, it causes no cache misses at all and the number of cache hits is reduced to a minimum due to the constant cache flushes. Therefore, Flush+Flush attacks are stealthy, i.e., the spy process cannot be detected based on cache hits and misses, or state-of-the-art detection mechanisms. The Flush+Flush attack runs in a higher frequency and thus is faster than any existing cache attack. With 496 KB/s in a cross-core covert channel it is 6.7 times faster than any previously published cache covert channel.
Originalsprache | englisch |
---|---|
Titel | Detection of Intrusions and Malware, and Vulnerability Assessment - 13th International Conference, DIMVA 2016, Proceedings |
Herausgeber (Verlag) | Springer-Verlag Italia |
Seiten | 279-299 |
Seitenumfang | 21 |
Band | 9721 |
ISBN (Print) | 9783319406664 |
DOIs | |
Publikationsstatus | Veröffentlicht - 2016 |
Veranstaltung | 13th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, DIMVA 2016 - San Sebastian, Spanien Dauer: 7 Juli 2016 → 8 Juli 2016 |
Publikationsreihe
Name | Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) |
---|---|
Band | 9721 |
ISSN (Print) | 03029743 |
ISSN (elektronisch) | 16113349 |
Konferenz
Konferenz | 13th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, DIMVA 2016 |
---|---|
Land/Gebiet | Spanien |
Ort | San Sebastian |
Zeitraum | 7/07/16 → 8/07/16 |
ASJC Scopus subject areas
- Theoretische Informatik
- Informatik (insg.)
Fingerprint
Untersuchen Sie die Forschungsthemen von „Flush+Flush: A fast and stealthy cache attack“. Zusammen bilden sie einen einzigartigen Fingerprint.Projekte
- 3 Abgeschlossen
-
HECTOR - Hardware aktivierte Crypto und Randomness
Korak, T., Mangard, S. & Mendel, F.
1/03/15 → 31/07/18
Projekt: Forschungsprojekt
-
Matthew - [Original in Englisch: Multi-entity-security using active Transmission Technology for improved Handling of Exportable security credentials Without privacy restrictions (MATTHEW Project)]
Hanser, C., Wenger, E., Korak, T., Groß, H., Mangard, S. & Unterluggauer, T.
1/11/13 → 31/10/16
Projekt: Forschungsprojekt
-
SeCoS - Verbundene Welt [Original in Englisch: Secure Contactless Sphere Smart RFID-Technologies for a Connected World]
Bösch, W., Wenger, E., Khan, H. N., Schmidt, J., Gadringer, M. E., Spreitzer, R. C., Mendel, F., Gruss, D., Hutter, M., Freidl, P. F., Görtschacher, L. J., Mangard, S. & Grosinger, J.
1/01/13 → 31/12/15
Projekt: Forschungsprojekt