Projects per year
Abstract
In modern computer systems, user processes are isolated from each other by the operating system and the hardware. Additionally, in a cloud scenario it is crucial that the hypervisor isolates tenants from other tenants that are co-located on the same physical machine. However, the hypervisor does not protect tenants against the cloud provider and thus the supplied operating system and hardware. Intel SGX provides a mechanism that addresses this scenario. It aims at protecting user-level software from attacks from other processes, the operating system, and even physical attackers. In this paper, we demonstrate fine-grained software-based sidechannel attacks from a malicious SGX enclave targeting co-located enclaves. Our attack is the first malware running on real SGX hardware, abusing SGX protection features to conceal itself. Furthermore, we demonstrate our attack both in a native environment and across multiple Docker containers. We perform a Prime+Probe cache side-channel attack on a co-located SGX enclave running an up-to-date RSA implementation that uses a constant-time multiplication primitive. The attack works although in SGX enclaves there are no timers, no large pages, no physical addresses, and no shared memory. In a semi-synchronous attack, we extract 96% of an RSA private key from a single trace. We extract the full RSA private key in an automated attack from 11 traces.
| Original language | English |
|---|---|
| Title of host publication | Detection of Intrusions and Malware, and Vulnerability Assessment - 14th International Conference, DIMVA 2017, 2017 |
| Publisher | Springer-Verlag Italia |
| Pages | 3-24 |
| Number of pages | 22 |
| Volume | 10327 LNCS |
| ISBN (Print) | 9783319608754 |
| DOIs | |
| Publication status | Published - 2017 |
| Event | 14th International Conference on Detection of Intrusions and Malware, and Vulnerability Assess, DIMVA 2017 - Bonn, Germany Duration: 6 Jul 2017 → 7 Jul 2017 |
Publication series
| Name | Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) |
|---|---|
| Volume | 10327 LNCS |
| ISSN (Print) | 0302-9743 |
| ISSN (Electronic) | 1611-3349 |
Conference
| Conference | 14th International Conference on Detection of Intrusions and Malware, and Vulnerability Assess, DIMVA 2017 |
|---|---|
| Country/Territory | Germany |
| City | Bonn |
| Period | 6/07/17 → 7/07/17 |
ASJC Scopus subject areas
- Theoretical Computer Science
- General Computer Science
Fingerprint
Dive into the research topics of 'Malware guard extension: Using SGX to conceal cache attacks'. Together they form a unique fingerprint.Projects
- 2 Finished
-
EU - SOPHIA - Securing Software against Physical Attacks
Mangard, S. (Project manager on research unit)
1/09/16 → 31/12/21
Project: Research project
-
Dependable Internet of Things
Pernkopf, F. (Contact person), Zakany, N. (Contact person), Eichlseder, M. (Contact person), Saukh, O. (Contact person), Mangard, S. (Contact person), Steinbauer-Wagner, G. (Contact person), Knoll, C. (Attendee / Assistant), Tranninger, M. (Attendee / Assistant), Römer, K. U. (Consortium manager resp. coordinator of internal research units), Rath, M. (Attendee / Assistant), Kubin, G. (Contact person), Horn, M. (Contact person), Tappler, M. (Attendee / Assistant), Bloem, R. (Consortium manager resp. coordinator of internal research units), Weiser, S. (Attendee / Assistant), Leitinger, E. (Contact person), Ebrahimi, M. (Attendee / Assistant), Aichernig, B. (Contact person), Malenko, M. (Attendee / Assistant), Steinberger, M. (Contact person), Großwindhager, B. (Attendee / Assistant), Baunach, M. C. (Contact person), Witrisal, K. (Contact person), Teschl, R. (Contact person), Boano, C. A. (Contact person), Alothman Alterkawi, A. B. (Attendee / Assistant), Bösch, W. (Contact person) & Grosinger, J. (Contact person)
1/01/16 → 31/03/22
Project: Research project
Research output
- 1 Article
-
Malware Guard Extension: abusing Intel SGX to conceal cache attacks
Schwarz, M., Weiser, S., Gruß, D., Maurice, C. L. N. & Mangard, S., 1 Dec 2020, In: Cybersecurity. 3, 1, 20 p., 2.Research output: Contribution to journal › Article › peer-review
Open Access
Cite this
- APA
- Standard
- Harvard
- Vancouver
- Author
- BIBTEX
- RIS