Side-channel Attacks and Countermeasures in Cloud Services and Infrastructures

被引:2
|
作者
Albalawi, Abdullah [1 ]
Vassilakis, Vassilios [1 ]
Calinescu, Radu [1 ]
机构
[1] Univ York, Dept Comp Sci, York, N Yorkshire, England
关键词
Cloud Computing; Cache Side-channel Attacks;
D O I
10.1109/NOMS54207.2022.9789783
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud computing relies on the sharing of resources between users of the same physical machine, to reduce costs through optimizing and increasing utilization. However, sharing these resources may be with malicious users, which could lead to confidentiality violations through co-residency attacks. These attacks may exploit the sharing of resources such as cache memory to reveal a legitimate user's recent activities. Multiple techniques and factors can be exploited to perform side-channel attacks and other microarchitectural attacks successfully. Therefore, despite all its benefits, multi-tenancy remains a risk factor in cloud computing. Without appropriate mitigation, this security risk could become the primary concern hindering cloud adoption. This doctoral paper proposes the integrated use of three approaches to provide the necessary protection for shared virtualized systems. These approaches provide self-protection for the virtual machine (VM) on which they are used by monitoring activities within shared virtualized systems, determining the threat level of suspicious VMs, and providing periodic scanning of the virtualized system against microarchitectural attacks and viruses.
引用
收藏
页数:4
相关论文
共 50 条
  • [1] A Survey of Side-Channel Attacks on Caches and Countermeasures
    Yangdi Lyu
    Prabhat Mishra
    Journal of Hardware and Systems Security, 2018, 2 (1) : 33 - 50
  • [2] Timing Side-channel Attacks and Countermeasures in CPU Microarchitectures
    Zhang, Jiliang
    Chen, Congcong
    Cui, Jinhua
    Li, Keqin
    ACM COMPUTING SURVEYS, 2024, 56 (07)
  • [3] Cache Side-Channel Attacks in Cloud Computing
    Younis, Younis
    Kifayat, Kashif
    Merabti, Madjid
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON CLOUD SECURITY MANAGEMENT (ICCSM-2014), 2014, : 138 - 146
  • [4] Analysis and countermeasures to side-channel attacks: a hardware design perspective
    Zoni, Davide
    2019 14TH INTERNATIONAL SYMPOSIUM ON RECONFIGURABLE COMMUNICATION-CENTRIC SYSTEMS-ON-CHIP (RECOSOC 2019), 2019, : 1 - 4
  • [5] FPGA implementations of SPRING and their countermeasures against side-channel attacks
    Brenner, Hai
    Gaspar, Lubos
    Leurent, Gaëetan
    Rosen, Alon
    Standaert, François-Xavier
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2014, 8731 : 414 - 432
  • [6] Horizontal Side-Channel Attacks and Countermeasures on the ISW Masking Scheme
    Battistello, Alberto
    Coron, Jean-Sebastien
    Prouff, Emmanuel
    Zeitoun, Rina
    CRYPTOGRAPHIC HARDWARE AND EMBEDDED SYSTEMS - CHES 2016, 2016, 9813 : 23 - 39
  • [7] Formal Verification of Software Countermeasures against Side-Channel Attacks
    Eldib, Hassan
    Wang, Chao
    Schaumont, Patrick
    ACM TRANSACTIONS ON SOFTWARE ENGINEERING AND METHODOLOGY, 2014, 24 (02)
  • [8] Micro-architectural Cache Side-Channel Attacks and Countermeasures
    Shen, Chaoqun
    Chen, Congcong
    Zhang, Jiliang
    2021 26TH ASIA AND SOUTH PACIFIC DESIGN AUTOMATION CONFERENCE (ASP-DAC), 2021, : 441 - 448
  • [9] FPGA Implementations of SPRING And Their Countermeasures against Side-Channel Attacks
    Brenner, Hai
    Gaspar, Lubos
    Leurent, Gaetan
    Rosen, Alon
    Standaert, Francois-Xavier
    CRYPTOGRAPHIC HARDWARE AND EMBEDDED SYSTEMS - CHES 2014, 2014, 8731 : 414 - 432
  • [10] Compositional Verification of Efficient Masking Countermeasures against Side-Channel Attacks
    Gao, Pengfei
    Zhang, Yedi
    Song, Fu
    Chen, Taolue
    Standaert, Francois-Xavier
    PROCEEDINGS OF THE ACM ON PROGRAMMING LANGUAGES-PACMPL, 2023, 7 (OOPSLA):