ShieldMMU: Detecting and Defending against Controlled-Channel Attacks in Shielding Memory System

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Liu, Gang, Li, Ningjie, Chen, Cen
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866912570076561408
author Liu, Gang
Li, Ningjie
Chen, Cen
author_facet Liu, Gang
Li, Ningjie
Chen, Cen
contents Intel SGX and hypervisors isolate non-privileged programs from other software, ensuring confidentiality and integrity. However, side-channel attacks continue to threaten Intel SGX's security, enabling malicious OS to manipulate PTE present bits, induce page faults, and steal memory access traces. Despite extensive research, existing defenses focus on detection or rely on impractical solutions. This paper presents ShieldMMU, a comprehensive solution for mitigating controlled channel attacks, balancing compatibility, performance, and usability. Leveraging a Merkle Tree-inspired Defense Tree (DD-Tree), ShieldMMU protects PTE integrity by detecting, locating, and restoring attacked PTEs. It identifies MMU page table lookup events and side-channel attacks, promptly restoring PTE parameters to prevent page fault traps and ensure secure non-privileged application operation within SGX. Our experiments confirm ShieldMMU's enhanced security and acceptable latency performance.
format Preprint
id arxiv_https___arxiv_org_abs_2509_03879
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle ShieldMMU: Detecting and Defending against Controlled-Channel Attacks in Shielding Memory System
Liu, Gang
Li, Ningjie
Chen, Cen
Cryptography and Security
Systems and Control
Intel SGX and hypervisors isolate non-privileged programs from other software, ensuring confidentiality and integrity. However, side-channel attacks continue to threaten Intel SGX's security, enabling malicious OS to manipulate PTE present bits, induce page faults, and steal memory access traces. Despite extensive research, existing defenses focus on detection or rely on impractical solutions. This paper presents ShieldMMU, a comprehensive solution for mitigating controlled channel attacks, balancing compatibility, performance, and usability. Leveraging a Merkle Tree-inspired Defense Tree (DD-Tree), ShieldMMU protects PTE integrity by detecting, locating, and restoring attacked PTEs. It identifies MMU page table lookup events and side-channel attacks, promptly restoring PTE parameters to prevent page fault traps and ensure secure non-privileged application operation within SGX. Our experiments confirm ShieldMMU's enhanced security and acceptable latency performance.
title ShieldMMU: Detecting and Defending against Controlled-Channel Attacks in Shielding Memory System
topic Cryptography and Security
Systems and Control
url https://arxiv.org/abs/2509.03879