A Systematic Look at Quality-of-Service Feature Effects on Side Channels in AMD SEV-SNP

Abstract

Modern systems execute numerous workloads in parallel, with tasks contending for the same shared resources, e.g., cache and memory bandwidth. To minimize the impact on workloads by “noisy neighbors”, Intel and AMD released quality-of-service (QoS) extensions to enforce limits on such resources along with monitoring metrics. In this paper, we show that these well-intentioned quality-of-service extensions introduce new system-level cross-core side channels and amplify known attacks in confidential computing environments on modern AMD server CPUs, namely SEV-SNP. We demonstrate our attacks in the malicious or compromised hypervisor threat model, attacking an AMD SEV-SNP Confidential VM. In these settings we mount an MBM-based Bleichenbacher attack on RSA, inter-keystroke timing attacks (F1 score up to 96 %) exploiting MBM, MBA, CAT, and CDP, a new MBA ratelimit-based side channel (up to 205 B/s), and a website fingerprinting attack (F1 score up to 72.10 %) exploiting MBM, MBA, CAT, and CDP. We also evaluate a CAT-amplified Prime+Probe L3 covert channel with a maximum speedup of 2.27×. We conclude that these well-intention set of features require mitigation, most likely requiring hardware changes.

Publication
In European Symposium on Research in Computer Security
Ruiyi Zhang
Ruiyi Zhang
PhD Candidate

My research interests include software-based architectural attacks, side channels, and the security of Trusted Execution Environments.