首页> 外文会议>European Symposium on Research in Computer Security >On-Demand Time Blurring to Support Side-Channel Defense
【24h】

On-Demand Time Blurring to Support Side-Channel Defense

机译:按需时间模糊,以支持侧通道防御

获取原文

摘要

Side-channel attacks are a serious threat to multi-tenant public clouds. Past work showed how secret information in one virtual machine (VM) can be leaked to another, co-resident VM using timing side channels. Recent defenses against timing side channels focus on reducing the degree of resource sharing. However, such defenses necessarily limit the flexibility with which resources are shared. In this paper, we propose a technique that dynamically adjusts the granularity of platform time sources, to interfere with timing side-channel attacks. Our proposed technique supposes an interface by which a VM can request the temporary coarsening of platform time sources as seen by all VMs on the platform, which the hypervisor can effect since it virtualizes accesses to those timers. We show that the VM-Function (VMFUNC) mechanism provides a low-overhead such interface, thereby enabling applications to adjust timer granularity with minimal overhead. We present a proof-of-concept implementation using a Xen hypervisor running Linux-based VMs on a cloud server using commodity Intel processors and supporting adjustment of the timestamp-counter (TSC) granularity. We evaluate our implementation and show that our scheme mitigates timing side-channel attacks, while introducing negligible performance penalties.
机译:侧渠攻击对多租户公共云的严重威胁。过去的工作表明,使用定时侧通道可以泄漏一个虚拟机(VM)中的秘密信息如何泄露到另一个,共居民VM。最近防止定时侧通道的防御侧重于降低资源共享程度。但是,这些防御必然限制了共享资源的灵活性。在本文中,我们提出了一种动态调整平台时间源的粒度的技术,以干扰定时侧通道攻击。我们所提出的技术假设VM可以通过平台上的所有VM所见,VM可以要求临时粗化,因为它虚拟化可以效益,因为它虚拟化到这些定时器的访问。我们表明VM函数(VMFUNC)机制提供低开销的界面,从而使应用程序能够以最小的开销调整定时器粒度。我们使用商品Intel处理器在云服务器上运行基于Linux的VM的Xen虚拟机管理程序并支持调整时间戳 - 计数器(TSC)粒度的调整,我们提出了概念证据。我们评估我们的实施,并表明我们的计划减轻了时序侧渠攻击,同时引入了可忽略的绩效惩罚。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号