| title | Exploiting Out-of-Order Execution | ||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| date | 2015 | ||||||||||||||||||||||||||||||||
| authors |
|
||||||||||||||||||||||||||||||||
| conference |
|
||||||||||||||||||||||||||||||||
| resources |
|
Given the rise of cloud computing and platform-as-a-service, vulnerabilities inherent to systems sharing hardware resources are increasingly attractive targets. This talk presents a classification of possible cloud-based side channels using hardware virtualization, describes and implements a novel side channel exploiting out-of-order execution in the CPU pipeline, and demonstrates several adversarial applications deployed across this channel. The presentation also analyzes detection and mitigation techniques for these side-channel attacks.