Skip to main navigation Skip to search Skip to main content

WaitWatcher and WaitGuard: Detecting Flush-Based Cache Side-Channels Through Spurious Wakeups

Research output: Chapter in Book/Report/Conference proceedingConference paperpeer-review

Abstract

Flush+Reload and Flush+Flush attacks target CPU caches and allow malicious actors to leak confidential data across different CPU cores. Typically, detection mechanisms against such attacks leverage hardware performance counters to observe architectural and microarchitectural events. However, recent research has shown that state-of-the-art security monitors can effectively be bypassed by camouflaged Flush+Reload attacks. Thus, flush-based cache side-channel attacks are still a significant threat to system security. In this work, we present WaitGuard, a novel detection technique with a >99.9 % detection rate based on the userspace monitor and wait instructions. Our framework automatically profiles internal CPU interactions of userspace monitor/waits with other unprivileged instructions. We use WaitWatcher to analyze 7 different server and desktop-class x86 CPUs from Intel and AMD. In our analysis, we uncover 5 spurious wakeup triggers and 18 user-mode instructions that completely bypass the wakeup mechanisms. Based on our analysis, we develop WaitGuard, a novel detection mechanism that repurposes the recently introduced userspace monitor and wait instructions to detect flush-based cache side-channel attacks on modern x86 hardware. We implement WaitGuard as a drop-in security monitor that reliably detects Flush+Reload and Flush+Flush attacks with a detection rate of >99.9 %, even when introducing heavy system noise. Moreover, we find that WaitGuard also detects the previously invisible camouflaged Flush+Reload attacks. Finally, we demonstrate the real-world applicability of WaitGuard by showing its effectiveness in detecting Flush+Reload attacks on the OpenSSL AES T-table implementation.
Original languageEnglish
Title of host publicationComputer Security – ESORICS 2025
Subtitle of host publication30th European Symposium on Research in Computer Security, Toulouse, France, September 22–24, 2025, Proceedings, Part III
EditorsVincent Nicomette, Abdelmalek Benzekri, Nora Boulahia-Cuppens, Jaideep Vaidya
PublisherSpringer, Cham
Pages303–322
Number of pages20
ISBN (Electronic)978-3-032-07894-0
ISBN (Print)978-3-032-07893-3
DOIs
Publication statusPublished - 18 Oct 2025
Event30th European Symposium on Research in Computer Security, ESORICS 2025 - Toulouse, France
Duration: 22 Sept 202524 Sept 2025

Publication series

NameLecture Notes in Computer Science
Volume16055 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference30th European Symposium on Research in Computer Security, ESORICS 2025
Abbreviated titleESORICS 25
Country/TerritoryFrance
CityToulouse
Period22/09/2524/09/25

Keywords

  • Cache Attacks
  • Side Channels
  • Userspace monitor/wait

ASJC Scopus subject areas

  • Theoretical Computer Science
  • General Computer Science

Fields of Expertise

  • Information, Communication & Computing

Fingerprint

Dive into the research topics of 'WaitWatcher and WaitGuard: Detecting Flush-Based Cache Side-Channels Through Spurious Wakeups'. Together they form a unique fingerprint.

Cite this