Security and Communication Networks / 2018 / Article / Tab 3 / Research Article
Leveraging KVM Events to Detect Cache-Based Side Channel Attacks in a Virtualization Environment Table 3 Five features with the highest Fisher score for each non-CSCa scenario operation type compared to the CSCa scenarios. Note: “:” symbol represent delimiter.
Vs CSCa KVM event sequence Fisher score Non-CSCa Seq. Stat. CSCa Seq. Stat. Med. Mean St. dev. Med. Mean St. dev. Regular operation MSR_WRITE:kvm_apic:kvm_msr: 28.4 132 133.5 20.7 1 1.3 4.5 HLT:kvm_eoi:kvm_pv_eoi:kvm_apic_accept_irq: kvm_inj_virq: 26.7 45 45.1 8.6 0 0 0 HLT:kvm_inj_virq: 23.8 87 87.3 16.1 0 0 0 MSR_WRITE:kvm_apic:kvm_apic:kvm_apic_ipi: kvm_apic_accept_irq:kvm_msr: 19.5 109 108.2 21.6 0 0.1 2.8 HLT:kvm_eoi:kvm_pv_eoi:kvm_inj_virq: 17.2 312 305.8 67.3 0 0 0 CPU-intensive operation EXCEPTION_NMI:kvm_fpu: 9.3 9 9.2 2.2 0 0.5 0.6 EXTERNAL_INTERRUPT:kvm_fpu: 4.7 7 7.7 3.1 2 1.6 0.9 CR_ACCESS:kvm_cr:kvm_fpu: 0.8 0 0.4 2.4 3 2.6 0.9 PENDING_INTERRUPT:kvm_inj_virq: 0.4 2 3.2 6.6 167 106.5 84.3 EXTERNAL_INTERRUPT:kvm_apic_accept_irq: kvm_inj_virq: 0.3 255 255.4 6.1 94 152.8 82.6 Memory-intensive operation EXCEPTION_NMI:kvm_page_fault:kvm_emulate_insn: 434.9 1004 1002.1 15.7 0 0.7 18.3 EXCEPTION_NMI:kvm_page_fault:kvm_inj_exception: 87.1 5058 4949.2 233.6 0 5 189.8 EXCEPTION_NMI:kvm_page_fault:kvm_apic_accept_irq: kvm_inj_virq: 22.9 22 22.2 4.2 0 0 0.4 EXCEPTION_NMI:kvm_page_fault: 19.3 5128 5630.6 983.2 0 7.9 283.8 EXCEPTION_NMI:kvm_page_fault:kvm_emulate_insn: kvm_apic_accept_irq:kvm_inj_virq: 9.5 11 11.2 3.6 0 0 0