Vol. 12, No. 12, December 30, 2018
                        
                         10.3837/tiis.2018.12.026
                        10.3837/tiis.2018.12.026,
                        
Download Paper (Free):
                        
                             
                        
                        
                     
                    
                    Abstract
                    Cache-based side-channel attacks have achieved more attention along with the development of cloud computing technologies. However, current host-based mitigation methods either provide bad compatibility with current cloud infrastructure, or turn out too application-specific. Besides, they are defending blindly without any knowledge of on-going attacks. In this work, we present CacheSCDefender, a framework that provides a (Virtual Machine Monitor) VMM-based comprehensive defense framework against all levels of cache attacks. In designing CacheSCDefender, we make three key contributions: (1) an attack-aware framework combining our novel dynamic remapping and traditional cache cleansing, which provides a comprehensive defense against all three cases of cache attacks that we identify in this paper; (2) a new defense method called dynamic remapping which is a developed version of random permutation and is able to deal with two cases of cache attacks; (3) formalization and quantification of security improvement and performance overhead of our defense, which can be applicable to other defense methods. We show that CacheSCDefender is practical for deployment in normal virtualized environment, while providing favorable security guarantee for virtual machines.
                    
                    Statistics
                    
                        Show / Hide Statistics
                        
                        
                            
                                
                                Statistics (Cumulative Counts from December 1st, 2015)
                                Multiple requests among the same browser session are counted as one view.
                                If you mouse over a chart, the values of data points will be shown.
                            
                            
                         
                     
                    
                    Cite this article
                    
                        [IEEE Style]
                        C. Yang, Y. Guo, H. Hu, W. Liu, "CacheSCDefender: VMM-based Comprehensive Framework against Cache-based Side-channel Attacks," KSII Transactions on Internet and Information Systems, vol. 12, no. 12, pp. 6098-6122, 2018. DOI: 10.3837/tiis.2018.12.026.
                        
                        [ACM Style]
                        Chao Yang, Yunfei Guo, Hongchao Hu, and Wenyan Liu. 2018. CacheSCDefender: VMM-based Comprehensive Framework against Cache-based Side-channel Attacks. KSII Transactions on Internet and Information Systems, 12, 12, (2018), 6098-6122. DOI: 10.3837/tiis.2018.12.026.
                        
                        [BibTeX Style]
                        @article{tiis:21961, title="CacheSCDefender: VMM-based Comprehensive Framework against Cache-based Side-channel Attacks", author="Chao Yang and Yunfei Guo and Hongchao Hu and Wenyan Liu and ", journal="KSII Transactions on Internet and Information Systems", DOI={10.3837/tiis.2018.12.026}, volume={12}, number={12}, year="2018", month={December}, pages={6098-6122}}