Auteurs
Tianwei Zhang, Yinqian Zhang, Ruby B Lee
Date de publication
2016
Conférence
Research in Attacks, Intrusions, and Defenses: 19th International Symposium, RAID 2016, Paris, France, September 19-21, 2016, Proceedings 19
Pages
118-140
Éditeur
Springer International Publishing
Description
We present CloudRadar, a system to detect, and hence mitigate, cache-based side-channel attacks in multi-tenant cloud systems. CloudRadar operates by correlating two events: first, it exploits signature-based detection to identify when the protected virtual machine (VM) executes a cryptographic application; at the same time, it uses anomaly-based detection techniques to monitor the co-located VMs to identify abnormal cache behaviors that are typical during cache-based side-channel attacks. We show that correlation in the occurrence of these two events offer strong evidence of side-channel attacks. Compared to other work on side-channel defenses, CloudRadar has the following advantages: first, CloudRadar focuses on the root causes of cache-based side-channel attacks and hence is hard to evade using metamorphic attack code, while maintaining a low false positive rate. Second, CloudRadar is …
Nombre total de citations
201720182019202020212022202320241526455741464218
Articles Google Scholar
T Zhang, Y Zhang, RB Lee - Research in Attacks, Intrusions, and Defenses: 19th …, 2016