HideMe: Hiding VMs from Co-Residency Attacks Using Network-Level Traffic Redirection
Bogdan-Nicolae Stănculete, Raffaele Sommese · 2025
Virtual Machine (VM) co-residency occurs when two virtual machines belonging to different users share the same physical host. Co-residency brings important security implications when one of the VMs is malicious: side-channel leakage, denial of service, and performance degradation are all possible attack vectors that can be leveraged. Achieving co-residency is a two-step process: VM placement and detection. While most of the literature focuses on preventing physical placement, we address the under-explored second step: preventing co-residency confirmation. We present HideMe, a modular, lightweight system that detects malicious probes based on dynamic host behavior and redirects them to decoy VMs. Evaluated in two realistic scenarios, HideMe demonstrates high efficacy, preventing 100% of attacks in consistent traffic environments and 97% in highly variable traffic, all with zero false positives and under strict visibility constraints. As contribution, we also release Hide me under an open-source license, provide deployment instructions for network operators, and outline directions for further improvement.