Malware Guard Extension: Using SGX to Conceal Cache Attacks
arXiv:1702.08719
Abstract
In modern computer systems, user processes are isolated from each other by the operating system and the hardware. Additionally, in a cloud scenario it is crucial that the hypervisor isolates tenants from other tenants that are co-located on the same physical machine. However, the hypervisor does not protect tenants against the cloud provider and thus the supplied operating system and hardware. Intel SGX provides a mechanism that addresses this scenario. It aims at protecting user-level software from attacks from other processes, the operating system, and even physical attackers. In this paper, we demonstrate fine-grained software-based side-channel attacks from a malicious SGX enclave targeting co-located enclaves. Our attack is the first malware running on real SGX hardware, abusing SGX protection features to conceal itself. Furthermore, we demonstrate our attack both in a native environment and across multiple Docker containers. We perform a Prime+Probe cache side-channel attack on a co-located SGX enclave running an up-to-date RSA implementation that uses a constant-time multiplication primitive. The attack works although in SGX enclaves there are no timers, no large pages, no physical addresses, and no shared memory. In a semi-synchronous attack, we extract 96% of an RSA private key from a single trace. We extract the full RSA private key in an automated attack from 11 traces within 5 minutes.
Extended version of DIMVA 2017 submission
Cited by in corpus (14)
- SgxPectre Attacks: Stealing Intel Secrets from SGX Enclaves via Speculative Execution
- Blockchain Consensus Protocols in the Wild
- Software Grand Exposure: SGX Cache Attacks Are Practical
- HECTOR-V: A Heterogeneous CPU Architecture for a Secure RISC-V Execution Environment
- HybCache: Hybrid Side-Channel-Resilient Caches for Trusted Execution Environments
- Snort Intrusion Detection System with Intel Software Guard Extension (Intel SGX)
- The Heisenberg Defense: Proactively Defending SGX Enclaves against Page-Table-Based Side-Channel Attacks
- Interface-Based Side Channel Attack Against Intel SGX
- Don't Mine, Wait in Line: Fair and Efficient Blockchain Consensus with Robust Round Robin
- The Pyramid Scheme: Oblivious RAM for Trusted Processors
- Virtualization Technologies and Cloud Security: advantages, issues, and perspectives
- Frontal Attack: Leaking Control-Flow in SGX via the CPU Frontend
- Enclave-Aware Compartmentalization and Secure Sharing with Sirius
- An operational architecture for privacy-by-design in public service applications