Co-residency of different clients' VMs on the same hardware platform puts users at risk of cache-based side-channel attacks in cloud. While current countermeasures fail to be general and precise, we observe that cache behaviors of co-resident VMs interfere with each other. So we set up a novel cache interference model which precisely depicts how a bystander's behavior affects cache side channels between VMs. Based on this model, we propose an interference-based VM migration strategy to defend against cache attacks by co-locating multiple VMs so as to maximize the effect of one VM's cache activities on disrupting the cache access pattern of another VM which might be utilized by side-channel attackers. Simulation result shows that our approach is effective against cache attacks by improving the average interference ratio by about 35%.
Interference-based VM Migration to Mitgate Cache-based Side-channel Attacks in Cloud
C. Yang,Wenyan Liu,Ya-wen Wang,Qing Tong,Ling-shu Li
Published 2018 in 2018 IEEE 4th International Conference on Computer and Communications (ICCC)
ABSTRACT
PUBLICATION RECORD
- Publication year
2018
- Venue
2018 IEEE 4th International Conference on Computer and Communications (ICCC)
- Publication date
2018-12-01
- Fields of study
Computer Science
- Identifiers
- External record
- Source metadata
Semantic Scholar
CITATION MAP
EXTRACTION MAP
CLAIMS
- No claims are published for this paper.
CONCEPTS
- No concepts are published for this paper.
REFERENCES
Showing 1-17 of 17 references · Page 1 of 1
CITED BY
Showing 1-5 of 5 citing papers · Page 1 of 1