Leveraging KVM Events to Detect Cache-Based Side Channel Attacks in a Virtualization Environment

Table 1

List of all collected scenarios for evaluation.

Positive class Negative class
Standard Op.CPU Intensive Op.

Prime + Probe (Gruss)IdleStress CPU
Flush + Reload (Gruss)RUBiS 20 clientsStress memory
Flush + Flush (Gruss)RUBiS 200 clientsBinary tree
Flush + Reload (Yarom)RUBiS 2000 clientsLucas-Lehmer
Flush + Reload (Hornby)Mail serverUrandom generator