{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T16:34:08Z","timestamp":1781109248489,"version":"3.54.1"},"reference-count":25,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2022,1,8]],"date-time":"2022-01-08T00:00:00Z","timestamp":1641600000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Cache side channel attacks, as a type of cryptanalysis, seriously threaten the security of the cryptosystem. These attacks continuously monitor the memory addresses associated with the victim\u2019s secret information, which cause frequent memory access on these addresses. This paper proposes CacheHawkeye, which uses the frequent memory access characteristic of the attacker to detect attacks. CacheHawkeye monitors memory events by CPU hardware performance counters. We proved the effectiveness of CacheHawkeye on Flush+Reload and Flush+Flush attacks. In addition, we evaluated the accuracy of CacheHawkeye under different system loads. Experiments demonstrate that CacheHawkeye not only has good accuracy but can also adapt to various system loads.<\/jats:p>","DOI":"10.3390\/fi14010024","type":"journal-article","created":{"date-parts":[[2022,1,9]],"date-time":"2022-01-09T20:29:26Z","timestamp":1641760166000},"page":"24","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["CacheHawkeye: Detecting Cache Side Channel Attacks Based on Memory Events"],"prefix":"10.3390","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1779-8034","authenticated-orcid":false,"given":"Hui","family":"Yan","sequence":"first","affiliation":[{"name":"Institutes of Physical Science and Information Technology, Anhui University, Hefei 230601, China"},{"name":"Institutes of Intelligent Machines, Hefei Institutes of Physical Sciences, Chinese Academy of Sciences, Hefei 230031, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chaoyuan","family":"Cui","sequence":"additional","affiliation":[{"name":"Institutes of Intelligent Machines, Hefei Institutes of Physical Sciences, Chinese Academy of Sciences, Hefei 230031, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,1,8]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Liu, F., Yarom, Y., Ge, Q., Heiser, G., and Lee, R.B. (2015, January 17\u201321). Last-level cache side-channel attacks are practical. Proceedings of the 2015 IEEE Symposium on Security and Privacy, San Jose, CA, USA.","DOI":"10.1109\/SP.2015.43"},{"key":"ref_2","unstructured":"Yarom, Y., and Falkner, K. (2014, January 20\u201322). FLUSH+ RELOAD: A high resolution, low noise, L3 cache side-channel attack. Proceedings of the 23rd {USENIX} Security Symposium ({USENIX} Security 14), San Diego, CA, USA."},{"key":"ref_3","unstructured":"Gruss, D., Maurice, C., Wagner, K., and Mangard, S. (2016). International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, Springer."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Wang, Y., Ferraiuolo, A., Zhang, D., Myers, A.C., and Suh, G.E. (2016, January 5\u20139). SecDCP: Secure dynamic cache partitioning for efficient timing channel protection. Proceedings of the 2016 53nd ACM\/EDAC\/IEEE Design Automation Conference (DAC), Austin, TX, USA.","DOI":"10.1145\/2897937.2898086"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Zhou, Z., Reiter, M.K., and Zhang, Y. (2016, January 24\u201328). A software approach to defeating side channels in last-level caches. Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Vienna, Austria.","DOI":"10.1145\/2976749.2978324"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Oliverio, M., Razavi, K., Bos, H., and Giuffrida, C. (2017, January 28\u201331). Secure Page Fusion with VUsion: https:\/\/www.vusec.net\/projects\/VUsion. Proceedings of the 26th Symposium on Operating Systems Principles, Shanghai, China.","DOI":"10.1145\/3132747.3132781"},{"key":"ref_7","unstructured":"Inci, M.S., Gulmezoglu, B., Irazoqui, G., Eisenbarth, T., and Sunar, B. (2016). International Conference on Cryptographic Hardware and Embedded Systems, Springer."},{"key":"ref_8","unstructured":"Osvik, D.A., Shamir, A., and Tromer, E. (2006). Cryptographers\u2019 Track at the RSA Conference, Springer."},{"key":"ref_9","unstructured":"Percival, C. (2022, January 06). Cache Missing for Fun and Profit. Available online: http:\/\/css.csail.mit.edu\/6.858\/2014\/readings\/ht-cache.pdf."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"101524","DOI":"10.1016\/j.is.2020.101524","article-title":"Winter is here! A decade of cache-based side-channel attacks, detection & mitigation for RSA","volume":"92","author":"Mushtaq","year":"2020","journal-title":"Inf. Syst."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"559","DOI":"10.1145\/2508148.2485970","article-title":"On the feasibility of online malware detection with performance counters","volume":"41","author":"Demme","year":"2013","journal-title":"ACM SIGARCH Comput. Archit. News"},{"key":"ref_12","unstructured":"Qader, Z., Mo, A., and Gegov, A. (2017). UK Workshop on Computational Intelligence, Springer."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Mushtaq, M., Akram, A., Bhatti, M.K., Chaudhry, M., Lapotre, V., and Gogniat, G. (2018, January 2). Nights-watch: A cache-based side-channel intrusion detector using hardware performance counters. Proceedings of the 7th International Workshop on Hardware and Architectural Support for Security and Privacy, Los Angeles, CA, USA.","DOI":"10.1145\/3214292.3214293"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Mushtaq, M., Akram, A., Bhatti, M.K., Rais, R.N.B., Lapotre, V., and Gogniat, G. (2018, January 23\u201325). Run-time detection of prime+ probe side-channel attack on AES encryption algorithm. Proceedings of the 2018 Global Information Infrastructure and Networking Symposium (GIIS), Thessaloniki, Greece.","DOI":"10.1109\/GIIS.2018.8635767"},{"key":"ref_15","unstructured":"Payer, M. (2016). International Symposium on Engineering Secure Software and Systems, Springer."},{"key":"ref_16","unstructured":"Gruss, D., Spreitzer, R., and Mangard, S. (2015, January 12\u201314). Cache template attacks: Automating attacks on inclusive last-level caches. Proceedings of the 24th {USENIX} Security Symposium ({USENIX} Security 15), Washington, DC, USA."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Briongos, S., Irazoqui, G., Malag\u00f3n, P., and Eisenbarth, T. (2018, January 19\u201321). Cacheshield: Detecting cache attacks through self-observation. Proceedings of the Eighth ACM Conference on Data and Application Security and Privacy, Tempe, AZ, USA.","DOI":"10.1145\/3176258.3176320"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Bazm, M.M., Sautereau, T., Lacoste, M., Sudholt, M., and Menaud, J.M. (2018, January 23\u201326). Cache-based side-channel attacks detection through intel cache monitoring technology and hardware performance counters. Proceedings of the 2018 Third International Conference on Fog and Mobile Edge Computing (FMEC), Barcelona, Spain.","DOI":"10.1109\/FMEC.2018.8364038"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"393","DOI":"10.1007\/s10207-018-0411-7","article-title":"SpyDetector: An approach for detecting side-channel attacks at runtime","volume":"18","author":"Kulah","year":"2019","journal-title":"Int. J. Inf. Secur."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"1162","DOI":"10.1016\/j.asoc.2016.09.014","article-title":"Real time detection of cache-based side-channel attacks using hardware performance counters","volume":"49","author":"Chiappetta","year":"2016","journal-title":"Appl. Soft Comput."},{"key":"ref_21","first-page":"564","article-title":"Performance Counters to Rescue: A Machine Learning based safeguard against Micro-architectural Side-Channel-Attacks","volume":"2017","author":"Alam","year":"2017","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref_22","unstructured":"Zhang, T., Zhang, Y., and Lee, R.B. (2016). International Symposium on Research in Attacks, Intrusions, and Defenses, Springer."},{"key":"ref_23","unstructured":"Tang, A., Sethumadhavan, S., and Stolfo, S.J. (2014). International Workshop on Recent Advances in Intrusion Detection, Springer."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Wang, X., Konstantinou, C., Maniatakos, M., and Karri, R. (2015, January 23\u201326). Confirm: Detecting firmware modifications in embedded systems using hardware performance counters. Proceedings of the 2015 IEEE\/ACM International Conference on Computer-Aided Design (ICCAD), Barcelona, Spain.","DOI":"10.1109\/ICCAD.2015.7372617"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"101698","DOI":"10.1016\/j.sysarc.2019.101698","article-title":"Flush+ Prefetch: A countermeasure against access-driven cache-based side-channel attacks","volume":"104","author":"Mukhtar","year":"2020","journal-title":"J. Syst. Archit."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/1\/24\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,13]],"date-time":"2025-10-13T14:01:43Z","timestamp":1760364103000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/1\/24"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,1,8]]},"references-count":25,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2022,1]]}},"alternative-id":["fi14010024"],"URL":"https:\/\/doi.org\/10.3390\/fi14010024","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,1,8]]}}}