Open AccessProceedings Article
Practical Timing Side Channel Attacks Against Kernel Space ASLR.
Ralf Hund,Carsten Willems,Thorsten Holz +2 more
- 01 Jan 2013
261
TL;DR: In this paper, a generic side channel attack against the memory management system to deduce information about the privileged address space layout is proposed, based on the intrinsic property that the different caches are shared resources on computer systems.
read more
Abstract: Due to the prevalence of control-flow hijacking attacks, a wide variety of defense methods to protect both user space and kernel space code have been developed in the past years. A few examples that have received widespread adoption include stack canaries, non-executable memory, and Address Space Layout Randomization (ASLR). When implemented correctly (i.e., a given system fully supports these protection methods and no information leak exists), the attack surface is significantly reduced and typical exploitation strategies are severely thwarted. All modern desktop and server operating systems support these techniques and ASLR has also been added to different mobile operating systems recently. In this paper, we study the limitations of kernel space ASLR against a local attacker with restricted privileges. We show that an adversary can implement a generic side channel attack against the memory management system to deduce information about the privileged address space layout. Our approach is based on the intrinsic property that the different caches are shared resources on computer systems. We introduce three implementations of our methodology and show that our attacks are feasible on four different x86-based CPUs (both 32- and 64-bit architectures) and also applicable to virtual machines. As a result, we can successfully circumvent kernel space ASLR on current operating systems. Furthermore, we also discuss mitigation strategies against our attacks, and propose and implement a defense solution with negligible performance overhead.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
On-demand time blurring to support side-channel defense
Weijie Liu,Debin Gao,Michael K. Reiter +2 more
- 11 Sep 2017
TL;DR: The scheme mitigates timing side-channel attacks, while introducing negligible performance penalties, and is presented as a proof-of-concept implementation using a Xen hypervisor running Linux-based VMs on a cloud server using commodity Intel processors and supporting adjustment of the timestamp-counter (TSC) granularity.
27
•Posted Content
ERIM: Secure and Efficient In-process Isolation with Memory Protection Keys
Anjo Vahldiek-Oberwagner,Eslam Elnikety,Deepak Garg,Peter Druschel +3 more
- 21 Jan 2018
TL;DR: ErIM as mentioned in this paper is a technique that combines the security of hardware-enforced isolation with a switching performance near that of ASRL, which can support sensitive data access up to a million times per CPU core a second with low overhead.
27
A Benchmark Suite for Evaluating Caches' Vulnerability to Timing Attacks
Shuwen Deng,Wenjie Xiong,Jakub Szefer +2 more
- 09 Mar 2020
TL;DR: This work presents 88 Strong types of theoretical timing-based vulnerabilities in processor caches and presents and implements a new benchmark suite that can be used to test if processor cache is vulnerable to one of the attacks.
24
•Proceedings Article
Rendered Private: Making {GLSL} Execution Uniform to Prevent WebGL-based Browser Fingerprinting
Shujiang Wu,Song Li,Yinzhi Cao,Ningfei Wang +3 more
- 01 Jan 2019
TL;DR: A novel system, called UNIGL, to rewrite GLSL programs and make uniform WebGL rendering procedure with the support of existing WebGL functionalities is proposed, being the first in the community to point out that rendering discrepancies in state-of-the-art WebGLbased fingerprinting are caused by floating-point operations.
•Proceedings Article
Dynamically Finding Minimal Eviction Sets Can Be Quicker Than You Think for Side-Channel Attacks against the {LLC}
TL;DR: It is demonstrated that minimal eviction sets can be found within a fraction of a second on all processors, including a latest Coffee Lake one, and it is the first time to show that it is possible to find minimal eviction set with totally random addresses without fixing the page offset bits, which provides a starting point towards a viable attack against fully randomized LLCs if they are ever adopted in the future.
23
References
•Book
Computer Architecture: A Quantitative Approach
John L. Hennessy,David A. Patterson +1 more
- 01 Dec 1989
TL;DR: This best-selling title, considered for over a decade to be essential reading for every serious student and practitioner of computer design, has been updated throughout to address the most important trends facing computer designers today.
12.6K
•Proceedings Article
Timing attacks on Implementations of Diffie-Hellman, RSA, DSS, and other system
C. Kocher
- 01 Jan 1996
3.5K
Hey, you, get off of my cloud: exploring information leakage in third-party compute clouds
Thomas Ristenpart,Eran Tromer,Hovav Shacham,Stefan Savage +3 more
- 09 Nov 2009
TL;DR: It is shown that it is possible to map the internal cloud infrastructure, identify where a particular target VM is likely to reside, and then instantiate new VMs until one is placed co-resident with the target, and how such placement can then be used to mount cross-VM side-channel attacks to extract information from a target VM on the same machine.
•Proceedings Article
StackGuard: automatic adaptive detection and prevention of buffer-overflow attacks
Crispin Cowan,Calton Pu,Dave Maier,Heather Hintony,Jonathan Walpole,Peat Bakke,Steve Beattie,Aaron Grier,Perry Wagle,Qian Zhang +9 more
- 26 Jan 1998
TL;DR: StackGuard is described: a simple compiler technique that virtually eliminates buffer overflow vulnerabilities with only modest performance penalties, and a set of variations on the technique that trade-off between penetration resistance and performance.
The geometry of innocent flesh on the bone: return-into-libc without function calls (on the x86)
Hovav Shacham
- 28 Oct 2007
TL;DR: A return-into-libc attack to be mounted on x86 executables that calls no functions at all is presented, and how to discover such instruction sequences by means of static analysis is shown.
1.5K
Related Papers (5)
Ralf Hund,Carsten Willems,Thorsten Holz +2 more
- 19 May 2013
Jonathan Ganz,Sean Peisert +1 more
- 24 Sep 2017
Mathias Payer,Thomas R. Gross +1 more
- 26 Jan 2013