FlushBlocker: Lightweight mitigating mechanism for CPU cache flush instruction based attacks

Shuhei Enomoto, Hiroki Kuzuno · 2021

CPU cache flush instruction based attacks (cache instruction attacks) such as FLUSH+RELOAD can function in many environments. Meltdown and Spectre adopt FLUSH+RELOAD with cache instructions to access secret data. Additionally, Rowhammer employs cache instructions to modify data in physical memory. An adversary can read and write arbitrary data using these attacks. The deployment of corresponding hardware to combat these attacks is difficult for users, and existing software-based countermeasures incur high overheads, or cannot be applied to a variety of machines. In this study, we propose a novel mitigation mechanism for cache instruction attacks called FlushBlocker, which employs an effective approach that focuses on restricting cache flush instructions. We implemented FlushBlocker on the latest Linux kernel to conduct experiments. The experimental results indicate that FlushBlocker prevents existing cache instruction attacks and runtime overhead is negligible.

Read the paper · More papers on PaperTik