首页> 外文会议>IEEE International Conference on Cloud Computing >A Server-Side Solution to Cache-Based Side-Channel Attacks in the Cloud
【24h】

A Server-Side Solution to Cache-Based Side-Channel Attacks in the Cloud

机译:在云中基于缓存的侧通道攻击的服务器端解决方案

获取原文

摘要

As Cloud services become more common place, recent work have uncovered vulnerabilities unique to Cloud systems. Specifically, the paradigm promotes a risk of information leakage across virtual machine isolation via side-channels. In this paper, we investigate the current state of side-channel vulnerabilities involving the CPU cache, and identify the shortcomings of traditional defenses in a Cloud environment. We explore why solutions to non-Cloud cache-based side-channels cease to work in Cloud environments, and develop a mitigation technique applicable for Cloud security. Applying this solution to a canonical Cloud environment, we demonstrate the validity of this Cloud-specific, cache-based side-channel mitigation technique. Furthermore, we show that it can be implemented as a server-side approach to improve security without inconveniencing the client. Finally, we conduct a comparison of our solution to the current state-of-the-art.
机译:随着云服务变得越来越普遍,最近的工作已经发现了云系统特有的漏洞。具体而言,该范式会增加通过侧通道隔离整个虚拟机的信息泄漏风险。在本文中,我们调查了涉及CPU缓存的侧通道漏洞的当前状态,并确定了云环境中传统防御的缺点。我们将探讨非基于云的基于缓存的侧通道解决方案为何在云环境中不再起作用,并开发适用于云安全性的缓解技术。将此解决方案应用于规范的Cloud环境,我们演示了这种特定于Cloud的,基于缓存的边信道缓解技术的有效性。此外,我们展示了它可以作为服务器端方法来实现,以在不给客户端带来麻烦的情况下提高安全性。最后,我们将解决方案与当前的最新技术进行比较。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号