arrow
Return

One more set: Mitigating conflict-based cache side-channel attacks by extending cache set

delete2023-11-01
delete0
PRE
AI
Y
Yuzhe Gu
唐明 (Ming Tang) *
Q
Quancheng Wang
H
Han Wang
H
Haili Ding
DOI:10.1016/j.sysarc.2023.102997delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Caches are vulnerable to side-channel attacks as a type of shared hardware resource. Most existing defense methods can be categorized into two categories: partition and randomization. However, cache partition will bring a large performance overhead and randomization has been proven to be not safe enough. In this paper, we propose a design called ExtendCache. Different from other defense schemes applied to the entire cache, ExtendCache focuses on cache sets that may cause information leakage, which can greatly reduce the impact on performance. Based on the fact that a conflict-based attack requires a large number of accesses to the target set, ExtendCache locates the cache set that may contain sensitive information and be stolen by the attacker according to the number of accesses. After locating a suspicious set, it extends the set by borrowing cache lines from another set. This prevents attackers from controlling the state of the target set and observing effective victim behavior. We implemented ExtendCache on gem5 and took the modular square algorithm as an example to prove the effectiveness of our design. When evaluated using the SPEC2017 benchmarks, ExtendCache had minimal impact on performance, with only a 0.48% average performance loss observed.
Keywords:
Microarchitecture security
Cache side-channel attacks
Replacement policies
Hardware design

Journal

Journal of Systems Architecture cover
Journal of Systems Architecture
IF:
4.1
Papers:
3.0K
Citations:
4.2K

Organization

W
wuhan university
Scholars:
8.1W
Papers: 5.8W
Citations: 70