Frozencache presented at hashdays 2010

by Jürgen Pabel (Georgia Tech and Norwich University),

Tags: Security Others Deep Knowledge


Summary : Cold boot attacks are a major risk for the protection that Full-Disk-Encryption solutions provide. FrozenCache is a general-purpose solution to this attack for x86 based systems that employs a special CPU cache mode known as "Cache-as-RAM". Switching the CPU cache into a special mode forces data to held exclusively in the CPU cache and not to be written to the backing RAM locations, thus safeguarding data from being obtained from RAM by means of cold boot attacks. A Proof-of-Concept implementation for Linux will be released and implementation details discussed.

Jürgen Pabel: ürgen Pabel studied Computer Science and Information Assurance at Georgia Tech and Norwich University. He was one of the first German CISSP's and works as an IT-Security Consultant at Akkaya Consulting GmbH in Cologne. His blog covers a broad range of technology topics with a slight focus on security. He likes to play Rugby but his ambitious playing days for the ASV Köln are over.