Abstract
This work exposes further vulnerabilities in virtualized cloud servers by mounting Cross-VM cache attacks in Xen and VMware VMs targeting AES running in the victim VM. Even though there exists a rich literature on cache attacks on AES, so far only a single work, demonstrating a working attack on an ARM platform running a L4Re virtualization layer has been published. Here we show that AES in a number popular cryptographic libraries including OpenSSL, PolarSSL and Libgcrypt are vulnerable to Bernstein’s correlation attack when run in Xen and VMware (bare metal version) VMs, the most popular VMs used by cloud service providers (CSP) such as Amazon and Rackspace. We also show that the vulnerability persists even if the VMs are placed on different cores in the same machine. The results of this study shows that there is a great security risk to AES and (data encrypted under AES) on popular cloud services.
| Originalsprache | Englisch |
|---|---|
| Titel | 2014 IEEE Fourth International Conference on Big Data and Cloud Computing |
| Seitenumfang | 8 |
| Herausgeber (Verlag) | IEEE |
| Erscheinungsdatum | 07.04.2014 |
| Seiten | 737-744 |
| ISBN (elektronisch) | 978-1-4799-6719-3 |
| DOIs | |
| Publikationsstatus | Veröffentlicht - 07.04.2014 |
| Veranstaltung | 4th International Conference on Big Data and Cloud Computing - Sydney, Australien Dauer: 03.12.2014 → 05.12.2014 |
UN SDGs
Dieser Output leistet einen Beitrag zu folgendem(n) Ziel(en) für nachhaltige Entwicklung
-
SDG 9 – Industrie, Innovation und Infrastruktur
-
SDG 11 – Nachhaltige Städte und Gemeinschaften
-
SDG 12 – Verantwortungsvoller Konsum und Produktion
Fingerprint
Untersuchen Sie die Forschungsthemen von „Fine Grain Cross-VM Attacks on Xen and VMware“. Zusammen bilden sie einen einzigartigen Fingerprint.Zitieren
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver