TY - JOUR
T1 - Cross-VM Cache Side Channel Attacks in Cloud
T2 - A Survey
AU - Liang, Xin
AU - Gui, Xiao Lin
AU - Dai, Hui Jun
AU - Zhang, Chen
N1 - Publisher Copyright:
© 2017, Science Press. All right reserved.
PY - 2017/2/1
Y1 - 2017/2/1
N2 - In cloud-computing, virtual machines(VMs)of different tenants might be scheduled to run on the same physical machine, namely VMs co-residency. Co-resident VMs would share the underlying computing resources of the physical machine, relying on the virtual machine monitor to allocate and schedule system resources. Cross-domain sharing of underlying computing resources, albeit improving the utilization efficiency of available resources extremely, poses a serious threat to users' privacy concerns. A malicious VM could break the isolation mechanism and extract private information from other co-resident VMs, simply by probing the responses of shared resources and establishing a special leakage model. This attack pattern described above is usually called side-channel attacks. This paper deeply studied the mechanism and implementation of cross-VM cache side-channel attacks, and summarized its research status and advances. First, the essential cause of cache-based side-channel information leakage is analyzed and summarized. Next, the origin and research progress of cross-VM cache side-channel attacks are reviewed, the differences and relations between classic cache side-channel attacks and cross-VM cache side-channel attacks are discussed, followed by presentation of the universal model of access-driven cross-VM cache side-channel attacks. Then, the related issues of VMs co-residency and the latest mainstream methods for cross-VM cache-based side-channel information probing are categorized and expounded in detail. Finally, the current problems existing in the research and the future research directions of this field are presented.
AB - In cloud-computing, virtual machines(VMs)of different tenants might be scheduled to run on the same physical machine, namely VMs co-residency. Co-resident VMs would share the underlying computing resources of the physical machine, relying on the virtual machine monitor to allocate and schedule system resources. Cross-domain sharing of underlying computing resources, albeit improving the utilization efficiency of available resources extremely, poses a serious threat to users' privacy concerns. A malicious VM could break the isolation mechanism and extract private information from other co-resident VMs, simply by probing the responses of shared resources and establishing a special leakage model. This attack pattern described above is usually called side-channel attacks. This paper deeply studied the mechanism and implementation of cross-VM cache side-channel attacks, and summarized its research status and advances. First, the essential cause of cache-based side-channel information leakage is analyzed and summarized. Next, the origin and research progress of cross-VM cache side-channel attacks are reviewed, the differences and relations between classic cache side-channel attacks and cross-VM cache side-channel attacks are discussed, followed by presentation of the universal model of access-driven cross-VM cache side-channel attacks. Then, the related issues of VMs co-residency and the latest mainstream methods for cross-VM cache-based side-channel information probing are categorized and expounded in detail. Finally, the current problems existing in the research and the future research directions of this field are presented.
KW - Cache
KW - Cloud computing
KW - Side-channel attacks
KW - VMs co-residency
KW - Virtualization
UR - https://www.scopus.com/pages/publications/85019846798
U2 - 10.11897/SP.J.1016.2017.00317
DO - 10.11897/SP.J.1016.2017.00317
M3 - 文章
AN - SCOPUS:85019846798
SN - 0254-4164
VL - 40
SP - 317
EP - 336
JO - Jisuanji Xuebao/Chinese Journal of Computers
JF - Jisuanji Xuebao/Chinese Journal of Computers
IS - 2
ER -