On Preventing and Mitigating Cache Based Side-Channel Attacks on AES System in Virtualized Environments

Abdullah Albalawi
{"title":"On Preventing and Mitigating Cache Based Side-Channel Attacks on AES System in Virtualized Environments","authors":"Abdullah Albalawi","doi":"10.5539/cis.v17n1p9","DOIUrl":null,"url":null,"abstract":"Cloud computing aims to cut costs through a reduction in spending on equipment, infrastructure, and software by applying the multi-tenancy feature. Despite all the benefits of multi-tenancy, it is still a source of risk in cloud computing. Cloud adoption may be hampered by security concerns if suitable cloud-based security solutions are not available. Moreover, virtualization that enables multi-tenancy, considered one of the main components of a cloud, introduces major security risks and does not offer appropriate isolation between different instances running on the same physical machine. In this paper, we present a preliminary idea that may support the development of new countermeasures for a particular type of threat, namely cache-based side-channel attacks that target cache memories in virtualized environments. Attackers specifically target virtual machines in this type of attack to create many side channels and gather sensitive data. Additionally, this research offers preliminary concepts to aid in developing of solutions or defenses that enable us to identify unusual activity that could point to attacks associated with multi-tenancy, as well as security measures that preserve the benefits of multi-tenancy while lowering security concerns.","PeriodicalId":511930,"journal":{"name":"Computer and Information Science","volume":"264 1","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2024-02-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Computer and Information Science","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.5539/cis.v17n1p9","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Cloud computing aims to cut costs through a reduction in spending on equipment, infrastructure, and software by applying the multi-tenancy feature. Despite all the benefits of multi-tenancy, it is still a source of risk in cloud computing. Cloud adoption may be hampered by security concerns if suitable cloud-based security solutions are not available. Moreover, virtualization that enables multi-tenancy, considered one of the main components of a cloud, introduces major security risks and does not offer appropriate isolation between different instances running on the same physical machine. In this paper, we present a preliminary idea that may support the development of new countermeasures for a particular type of threat, namely cache-based side-channel attacks that target cache memories in virtualized environments. Attackers specifically target virtual machines in this type of attack to create many side channels and gather sensitive data. Additionally, this research offers preliminary concepts to aid in developing of solutions or defenses that enable us to identify unusual activity that could point to attacks associated with multi-tenancy, as well as security measures that preserve the benefits of multi-tenancy while lowering security concerns.
防止和缓解虚拟化环境中基于缓存的 AES 系统侧信道攻击
云计算旨在通过应用多租户功能,减少设备、基础设施和软件方面的开支,从而降低成本。尽管多租户有种种好处,但它仍然是云计算的一个风险源。如果没有合适的基于云的安全解决方案,安全问题可能会阻碍云计算的应用。此外,实现多租户的虚拟化被认为是云计算的主要组成部分之一,但它会带来重大的安全风险,并且无法在同一台物理机上运行的不同实例之间提供适当的隔离。在本文中,我们提出了一个初步想法,该想法可能有助于针对一种特殊类型的威胁(即基于缓存的侧信道攻击,其目标是虚拟化环境中的缓存存储器)开发新的应对措施。在这类攻击中,攻击者专门以虚拟机为目标,创建许多侧信道并收集敏感数据。此外,这项研究还提供了一些初步概念,有助于开发解决方案或防御措施,使我们能够识别可能指向与多租户相关的攻击的异常活动,以及既能保持多租户优势又能降低安全顾虑的安全措施。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信