在云计算环境中,不同租户的虚拟机可能运行于同一台物理主机之上,即虚拟机同驻.同驻的虚拟机之间共享物理主机的计算资源,并依赖于虚拟机监控器进行系统资源的分配与调度.这种跨域共享虽然提高了资源使用效率,但也给用户的隐私安全造成严重威胁.恶意租户通过探测共享资源的状态信息,建立泄漏模型,便可绕过虚拟化提供的隔离性,窃取其它同驻虚拟机的隐私信息,这种攻击模式通常称为跨虚拟机的侧信道攻击.文中深入分析了跨虚拟机Cache侧信道攻击的机理和实现方式,对跨虚拟机Cache侧信道攻击技术的研究现状与进展进行总结.首先,分析总结了Cache侧信道信息泄露的本质原因;其次,回顾了跨虚拟机Cache侧信道攻击的起源与研究进展,讨论了其与传统Cache侧信道攻击的关系,并提出跨虚拟机访问驱动Cache侧信道攻击的通用模型;然后,分类归纳并重点阐述了虚拟机同驻相关问题以及当前用于跨虚拟机Cache侧信道信息探测的主流方法;最后,分析了目前研究中存在的问题,并展望了未来的研究方向.
In cloud-computing, virtual machines(VMs)of different tenants might be scheduled torun on the same physical machine,namely VMs co-residency. Co-resident VMs would share the underlying computing resources of the physical machine, relying on the virtual machine monitor to allocate and schedule system resources. Cross-domain sharing of underlying computing resources,albeit improving the utilization efficiency of available resources extremely, poses a serious threat to users’ privacy concerns. A malicious VM could break the isolation mechanism and extract private information from other co-resident VMs, simply by probing the responses of shared resources and establishing a special leakage model. This attack pattern described above is usually called side-channel attacks. This paper deeply studied the mechanism and implementation of cross-VM cache side-channel attacks,and summarized its research status and advances. F irs t, the essential cause of cache-based side-channel information leakage is analyzed and summarized.Next,the origin and research progress of cross-VM cache side-channel attacks are reviewed, the differences and relations between classic cache side-channel attacks and cross-VM cache side-channel attacks are discussed,followed by presentation of the universal model of access-driven cross-VM cache side-channel attacks. Then, the related issues of VMs co-residency and the latest main-stream methods for cross-VM cache-based side-channel information probing are categorized and expounded in detail. Finally, the current problems existing in the research and the future research directions of this field are presented.