Projects per year
Abstract
Flush+Reload and Flush+Flush attacks target CPU caches and allow malicious actors to leak confidential data across different CPU cores. Typically, detection mechanisms against such attacks leverage hardware performance counters to observe architectural and microarchitectural events. However, recent research has shown that state-of-the-art security monitors can effectively be bypassed by camouflaged Flush+Reload attacks. Thus, flush-based cache side-channel attacks are still a significant threat to system security. In this work, we present WaitGuard, a novel detection technique with a >99.9 % detection rate based on the userspace monitor and wait instructions. Our framework automatically profiles internal CPU interactions of userspace monitor/waits with other unprivileged instructions. We use WaitWatcher to analyze 7 different server and desktop-class x86 CPUs from Intel and AMD. In our analysis, we uncover 5 spurious wakeup triggers and 18 user-mode instructions that completely bypass the wakeup mechanisms. Based on our analysis, we develop WaitGuard, a novel detection mechanism that repurposes the recently introduced userspace monitor and wait instructions to detect flush-based cache side-channel attacks on modern x86 hardware. We implement WaitGuard as a drop-in security monitor that reliably detects Flush+Reload and Flush+Flush attacks with a detection rate of >99.9 %, even when introducing heavy system noise. Moreover, we find that WaitGuard also detects the previously invisible camouflaged Flush+Reload attacks. Finally, we demonstrate the real-world applicability of WaitGuard by showing its effectiveness in detecting Flush+Reload attacks on the OpenSSL AES T-table implementation.
| Original language | English |
|---|---|
| Title of host publication | Computer Security – ESORICS 2025 |
| Subtitle of host publication | 30th European Symposium on Research in Computer Security, Toulouse, France, September 22–24, 2025, Proceedings, Part III |
| Editors | Vincent Nicomette, Abdelmalek Benzekri, Nora Boulahia-Cuppens, Jaideep Vaidya |
| Publisher | Springer, Cham |
| Pages | 303–322 |
| Number of pages | 20 |
| ISBN (Electronic) | 978-3-032-07894-0 |
| ISBN (Print) | 978-3-032-07893-3 |
| DOIs | |
| Publication status | Published - 18 Oct 2025 |
| Event | 30th European Symposium on Research in Computer Security, ESORICS 2025 - Toulouse, France Duration: 22 Sept 2025 → 24 Sept 2025 |
Publication series
| Name | Lecture Notes in Computer Science |
|---|---|
| Volume | 16055 LNCS |
| ISSN (Print) | 0302-9743 |
| ISSN (Electronic) | 1611-3349 |
Conference
| Conference | 30th European Symposium on Research in Computer Security, ESORICS 2025 |
|---|---|
| Abbreviated title | ESORICS 25 |
| Country/Territory | France |
| City | Toulouse |
| Period | 22/09/25 → 24/09/25 |
Keywords
- Cache Attacks
- Side Channels
- Userspace monitor/wait
ASJC Scopus subject areas
- Theoretical Computer Science
- General Computer Science
Fields of Expertise
- Information, Communication & Computing
Fingerprint
Dive into the research topics of 'WaitWatcher and WaitGuard: Detecting Flush-Based Cache Side-Channels Through Spurious Wakeups'. Together they form a unique fingerprint.-
EU - FSSec - Foundations for Sustainable Security
Gruss, D. (Project manager on research unit)
1/03/23 → 29/02/28
Project: Research project
-
AWARE - Hardware-Ensured Software Security
Mangard, S. (Consortium manager resp. coordinator with external organisations) & Mangard, S. (Project manager on research unit)
1/05/22 → 30/04/25
Project: Research project
Activities
- 1 Talk at conference or symposium
-
WaitWatcher & WaitGuard: Detecting Flush-Based Cache Side-Channels through Spurious Wakeups
Lamster, L. A. (Speaker)
22 Sept 2025Activity: Talk or presentation › Talk at conference or symposium › Science to science
Cite this
- APA
- Standard
- Harvard
- Vancouver
- Author
- BIBTEX
- RIS