Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Port Contention for Fun and Profit

IEEE via YouTube

Overview

Explore the intricacies of Simultaneous Multithreading (SMT) architectures as potential targets for side-channel attacks in this 22-minute IEEE conference talk. Delve into the concept of port contention as a high-resolution timing side-channel leakage source, which doesn't rely on the memory subsystem. Learn about an end-to-end attack implementation on Intel Skylake and Kaby Lake architectures with Hyper-Threading, demonstrating the recovery of a P-384 private key from an OpenSSL-powered TLS server. Discover how this attack method can be applied to shared libraries, static builds, and SGX enclaves, highlighting its wide-ranging implications. Gain insights into modern microarchitecture, execution engines, spatial resolution, and potential mitigations for this security vulnerability.

Syllabus

Introduction
Port Smash
Modern Microarchitecture
Execution Engine
Port Contention
Spy Process
Victim Process
Spatial Resolution
Proof of Attack
TLS
Intel SGX
Mitigations
Takeaway
Questions

Taught by

IEEE Symposium on Security and Privacy

Reviews

Start your review of Port Contention for Fun and Profit

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.