PhD Seminar • Systems and Networking • Side-Channel Attacks on Open vSwitchExport this event to calendar

Friday, July 19, 2024 — 1:00 PM to 2:00 PM EDT

Please note: This PhD seminar will take place in DC 1304.

Daewoo Kim, PhD candidate
David R. Cheriton School of Computer Science

Supervisor: Professor Sihang Liu

Virtualization is widely adopted in cloud systems to manage resource sharing among users. A virtualized environment usually deploys a virtual switch within the host system to enable virtual machines to communicate with each other and with the physical network. The Open vSwitch (OVS) is one of the most popular software-based virtual switches for virtualized environments. The OVS maintains a cache hierarchy to accelerate packet forwarding from the host to virtual machines.

We characterize the caching system inside OVS from a security perspective and identify three attack primitives. Based on the attack primitives, we present four remote attacks via OVS, breaking the isolation in virtualized environments. First, we identify remote covert channels using different caches. Second, we demonstrate an activity profiling attack that infers a remote user’s website access. Third, we present a header recovery attack that leaks a remote user’s packet header fields, breaking the confidentiality guarantees from the system. Finally, we demonstrate a keystroke attack that recovers a remote typer’s inter-keystroke latency. To defend against these attacks, we also discuss potential mitigations.

Location 
DC - William G. Davis Computer Research Centre
DC 1304
200 University Ave West

Waterloo, ON N2L 3G1
Canada
Event tags 

S M T W T F S
30
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
1
2
3
  1. 2024 (184)
    1. September (1)
    2. August (4)
    3. July (21)
    4. June (17)
    5. May (23)
    6. April (41)
    7. March (27)
    8. February (25)
    9. January (25)
  2. 2023 (296)
    1. December (20)
    2. November (28)
    3. October (15)
    4. September (25)
    5. August (30)
    6. July (30)
    7. June (22)
    8. May (23)
    9. April (32)
    10. March (31)
    11. February (18)
    12. January (22)
  3. 2022 (245)
  4. 2021 (210)
  5. 2020 (217)
  6. 2019 (255)
  7. 2018 (217)
  8. 2017 (36)
  9. 2016 (21)
  10. 2015 (36)
  11. 2014 (33)
  12. 2013 (23)
  13. 2012 (4)
  14. 2011 (1)
  15. 2010 (1)
  16. 2009 (1)
  17. 2008 (1)