The implementation of DDIO in Intel chips allows for a network attack specifically targeting keystrokes in an SSH session.

A group of researchers from the Free University of Amsterdam and ETH Zurich has developed a network attack technique NetCAT (Network Cache ATtack) that allows, by applying data analysis methods through external channels, to remotely determine the keys pressed by the user during an SSH session. The issue only occurs on servers that use the RDMA (Remote Direct Memory Access) and DDIO (Data-Direct I/O).

Intel Corporation believes, making the attack difficult to execute in practice, as it requires the attacker to access the local network, sterile conditions, and organization of host communication using RDMA and DDIO technologies, which are typically used in isolated networks, such as those operating computing clusters. The problem has been assigned a low severity level (CVSS 2.6, CVE-2019-11184) and it is recommended not to include DDIO and RDMA in local networks where no security perimeter is provided and untrusted clients are allowed to connect. DDIO has been used in Intel server processors since 2012 (Intel Xeon E5, E7, and SP). Systems based on AMD processors and those from other manufacturers are not affected by the issue, as they do not support the caching of transmitted network data in CPU cache.

The method used for the attack resembles the vulnerability “Throwhammer“, which allows modifying the contents of individual bits in RAM through manipulation of network packets in systems with RDMA. The new problem is a consequence of efforts to minimize latency when using the DDIO mechanism, which provides direct interaction between the network card and other peripheral devices with the CPU cache (during packet processing by the network card, data is stored in the cache and retrieved from the cache without accessing memory).

Thanks to DDIO, data generated during malicious network activity also enters the CPU cache. The NetCAT attack is based on the fact that network cards actively cache data, and the speed of packet processing in modern local networks is sufficient to influence cache filling and determine the presence or absence of data in the cache through delay analysis during data transmission.

When using interactive sessions, such as via SSH, the network packet is sent immediately after a key is pressed, meaning that the delays between packets correlate with the delays between key presses. By employing statistical analysis methods and considering that delays between key presses generally depend on the position of the key on the keyboard, it's possible to reconstruct the inputted information with a certain probability. For instance, most people typically type 's' after 'a' significantly faster than 'g' after 's'.

Information residing in the processor cache allows for precise timing of packets sent by the network card when processing connections such as SSH. By generating a specific stream of traffic, an attacker can determine when new data appears in the cache related to particular activities in the system. The method used for cache content analysis is Prime+Probe, which involves filling the cache with a reference set of values and measuring the access time to them during re-filling to identify changes.

The implementation of DDIO in Intel chips allows for a network attack specifically targeting keystrokes in an SSH session.

The proposed technique can also be used to determine not only key presses but other types of sensitive data that reside in the CPU cache. Potentially, an attack could be conducted even with RDMA disabled, but the effectiveness decreases without RDMA, and execution becomes substantially more complicated. Additionally, DDIO can be used to establish a covert communication channel for transferring data after compromising the server, circumventing security measures.

Play video

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster