Matches in SemOpenAlex for { <https://semopenalex.org/work/W2516668814> ?p ?o ?g. }
Showing items 1 to 80 of
80
with 100 items per page.
- W2516668814 abstract "Memory deduplication, a well-known technique to reduce the memory footprint across virtual machines, is now also a default-on feature inside the Windows 8.1 and Windows 10 operating systems. Deduplication maps multiple identical copies of a physical page onto a single shared copy with copy-on-write semantics. As a result, a write to such a shared page triggers a page fault and is thus measurably slower than a write to a normal page. Prior work has shown that an attacker able to craft pages on the target system can use this timing difference as a simple single-bit side channel to discover that certain pages exist in the system. In this paper, we demonstrate that the deduplication side channel is much more powerful than previously assumed, potentially providing an attacker with a weird machine to read arbitrary data in the system. We first show that an attacker controlling the alignment and reuse of data in memory is able to perform byte-by-byte disclosure of sensitive data (such as randomized 64 bit pointers). Next, even without control over data alignment or reuse, we show that an attacker can still disclose high-entropy randomized pointers using a birthday attack. To show these primitives are practical, we present an end-to-end JavaScript-based attack against the new Microsoft Edge browser, in absence of software bugs and with all defenses turned on. Our attack combines our deduplication-based primitives with a reliable Rowhammer exploit to gain arbitrary memory read and write access in the browser. We conclude by extending our JavaScript-based attack to cross-process system-wide exploitation (using the popular nginx web server as an example) and discussing mitigation strategies." @default.
- W2516668814 created "2016-09-16" @default.
- W2516668814 creator A5014005406 @default.
- W2516668814 creator A5029566823 @default.
- W2516668814 creator A5082033768 @default.
- W2516668814 creator A5083941826 @default.
- W2516668814 date "2016-05-01" @default.
- W2516668814 modified "2023-09-29" @default.
- W2516668814 title "Dedup Est Machina: Memory Deduplication as an Advanced Exploitation Vector" @default.
- W2516668814 cites W1934458198 @default.
- W2516668814 cites W1963947298 @default.
- W2516668814 cites W1964281299 @default.
- W2516668814 cites W1964389195 @default.
- W2516668814 cites W1969949656 @default.
- W2516668814 cites W1969953090 @default.
- W2516668814 cites W1981260134 @default.
- W2516668814 cites W1982268168 @default.
- W2516668814 cites W2001978806 @default.
- W2516668814 cites W2033593513 @default.
- W2516668814 cites W2051751274 @default.
- W2516668814 cites W2058189720 @default.
- W2516668814 cites W2073524356 @default.
- W2516668814 cites W2097718182 @default.
- W2516668814 cites W2125977605 @default.
- W2516668814 cites W2293436273 @default.
- W2516668814 cites W2296602564 @default.
- W2516668814 cites W4249836985 @default.
- W2516668814 doi "https://doi.org/10.1109/sp.2016.63" @default.
- W2516668814 hasPublicationYear "2016" @default.
- W2516668814 type Work @default.
- W2516668814 sameAs 2516668814 @default.
- W2516668814 citedByCount "150" @default.
- W2516668814 countsByYear W25166688142016 @default.
- W2516668814 countsByYear W25166688142017 @default.
- W2516668814 countsByYear W25166688142018 @default.
- W2516668814 countsByYear W25166688142019 @default.
- W2516668814 countsByYear W25166688142020 @default.
- W2516668814 countsByYear W25166688142021 @default.
- W2516668814 countsByYear W25166688142022 @default.
- W2516668814 countsByYear W25166688142023 @default.
- W2516668814 crossrefType "proceedings-article" @default.
- W2516668814 hasAuthorship W2516668814A5014005406 @default.
- W2516668814 hasAuthorship W2516668814A5029566823 @default.
- W2516668814 hasAuthorship W2516668814A5082033768 @default.
- W2516668814 hasAuthorship W2516668814A5083941826 @default.
- W2516668814 hasConcept C111919701 @default.
- W2516668814 hasConcept C173608175 @default.
- W2516668814 hasConcept C178489894 @default.
- W2516668814 hasConcept C32587265 @default.
- W2516668814 hasConcept C33925742 @default.
- W2516668814 hasConcept C38652104 @default.
- W2516668814 hasConcept C41008148 @default.
- W2516668814 hasConcept C43364308 @default.
- W2516668814 hasConcept C49289754 @default.
- W2516668814 hasConceptScore W2516668814C111919701 @default.
- W2516668814 hasConceptScore W2516668814C173608175 @default.
- W2516668814 hasConceptScore W2516668814C178489894 @default.
- W2516668814 hasConceptScore W2516668814C32587265 @default.
- W2516668814 hasConceptScore W2516668814C33925742 @default.
- W2516668814 hasConceptScore W2516668814C38652104 @default.
- W2516668814 hasConceptScore W2516668814C41008148 @default.
- W2516668814 hasConceptScore W2516668814C43364308 @default.
- W2516668814 hasConceptScore W2516668814C49289754 @default.
- W2516668814 hasLocation W25166688141 @default.
- W2516668814 hasOpenAccess W2516668814 @default.
- W2516668814 hasPrimaryLocation W25166688141 @default.
- W2516668814 hasRelatedWork W154681553 @default.
- W2516668814 hasRelatedWork W1982579475 @default.
- W2516668814 hasRelatedWork W2547510008 @default.
- W2516668814 hasRelatedWork W2587323806 @default.
- W2516668814 hasRelatedWork W2736204053 @default.
- W2516668814 hasRelatedWork W2780813414 @default.
- W2516668814 hasRelatedWork W2884105280 @default.
- W2516668814 hasRelatedWork W3003602898 @default.
- W2516668814 hasRelatedWork W3033545316 @default.
- W2516668814 hasRelatedWork W3098351737 @default.
- W2516668814 isParatext "false" @default.
- W2516668814 isRetracted "false" @default.
- W2516668814 magId "2516668814" @default.
- W2516668814 workType "article" @default.