On the Detection of Applications in Co-Resident Virtual Machines via a Memory Deduplication Side-Channel

被引:4
|
作者
Lindemann, Jens [1 ]
Fischer, Mathias [1 ]
机构
[1] Univ Hamburg, Secur & Privacy Grp, Dept Comp Sci, Hamburg, Germany
来源
APPLIED COMPUTING REVIEW | 2018年 / 18卷 / 04期
关键词
security; side-channel attack; virtualization; cloud computing;
D O I
10.1145/3307624.3307628
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Nowadays, hosting services of multiple customers on the same hardware via virtualiation techniques is very common. Memory deduplication allows to save physical memory by merging identical memory pages of multiple Virtual Machines (VMs) running on the same host. However, this mechanism can leak information on memory pages to other. In this paper, we propose a timing-based side-channel to identify software versions running in co-resident VMs. The attack tests whether pages that are unique to a specific software version are present in co-resident VMs. We evaluate the attack in a setting without background load and in a more realistic setting with significant background load on the host memory. Our results indicate that, with few repetitions of our attack, we can precisely identify software versions within reasonable time frames and nearly independent of the background load. Finally, we discuss potential countermeasures against the presented side-channel attack.
引用
收藏
页码:31 / 46
页数:16
相关论文
共 25 条
  • [21] DeepAuditor: Distributed Online Intrusion Detection System for IoT Devices via Power Side-channel Auditing
    Jung, Woosub
    Feng, Yizhou
    Khan, Sabbir A.
    Xin, Chunsheng
    Zhao, Danella
    Zhou, Gang
    2022 21ST ACM/IEEE INTERNATIONAL CONFERENCE ON INFORMATION PROCESSING IN SENSOR NETWORKS (IPSN 2022), 2022, : 415 - 427
  • [22] SCAGuard: Detection and Classification of Cache Side-Channel Attacks via Attack Behavior Modeling and Similarity Comparison
    Wang, Limin
    Bui, Lei
    Song, Fu
    2023 60TH ACM/IEEE DESIGN AUTOMATION CONFERENCE, DAC, 2023,
  • [23] Enhanced Detection Range for EM Side-channel Attack Probes utilizing Co-planar Capacitive Asymmetry Sensing
    Seo, Dong-Hyun
    Nath, Mayukh
    Das, Debayan
    Ghosh, Santosh
    Sen, Shreyas
    PROCEEDINGS OF THE 2021 DESIGN, AUTOMATION & TEST IN EUROPE CONFERENCE & EXHIBITION (DATE 2021), 2021, : 1016 - 1019
  • [24] ZeroD-fender: A Resource-aware IoT Malware Detection Engine via Fine-grained Side-channel Analysis
    Li, Zhuoran
    Zhao, Danella
    ACM TRANSACTIONS ON DESIGN AUTOMATION OF ELECTRONIC SYSTEMS, 2024, 29 (06)
  • [25] PG-CAS: Patterned-Ground Co-planar Capacitive Asymmetry Sensing for mm-range EM Side-channel Attack Probe Detection
    Seo, Dong-Hyun
    Nath, Mayukh
    Das, Debayan
    Chatterjee, Baibhab
    Ghosh, Santosh
    Sen, Shreyas
    2021 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS (ISCAS), 2021,