Secret Spilling Drive: Leaking User Behavior through SSD Contention

Jonas Juffinger

Network and Distributed System Security (NDSS) Symposium 2025 · Day 2 · Side Channels 1

Overview

In an era where Solid State Drives (SSDs) are rapidly becoming the dominant storage technology across computing platforms, the talk "Secret Spilling Drive: Leaking User Behavior through SSD Contention" by Jonas Juffinger and his collaborators Fabian Rousa, Jeppelana, and Stin, unveils critical and often overlooked security vulnerabilities inherent in these high-performance devices. Presented at the NDSS Symposium, this research meticulously investigates whether the high speed and parallel processing capabilities of modern SSDs truly shield them from the contention-based side-channel attacks that have long plagued traditional Hard Disk Drives (HDDs). The findings present a stark challenge to the prevailing assumption that SSDs, due to their internal architecture and speed, are largely immune to such timing-based information leakage.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction and initial discovery of SSD contention
  2. 2:20 Visualizing victim read size impact on attacker timings
  3. 3:20 How SSDs behave differently, 2D detectability plots
  4. 4:00 Building a timing-based cover channel on SSDs
  5. 5:10 Novel automatic threshold finding for varying SSDs
  6. 6:10 High-speed inter-process cover channel performance results
  7. 6:50 Achieving significant data leakage between virtual machines

Secret Spilling Drive: Leaking User Behavior through SSD Contention

Speakers: Jonas Juffinger (presenter), Fabian Rousa, Jeppelana, Stin

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=_dlGON5vqVo

Overview

In an era where Solid State Drives (SSDs) are rapidly becoming the dominant storage technology across computing platforms, the talk "Secret Spilling Drive: Leaking User Behavior through SSD Contention" by Jonas Juffinger and his collaborators Fabian Rousa, Jeppelana, and Stin, unveils critical and often overlooked security vulnerabilities inherent in these high-performance devices. Presented at the NDSS Symposium, this research meticulously investigates whether the high speed and parallel processing capabilities of modern SSDs truly shield them from the contention-based side-channel attacks that have long plagued traditional Hard Disk Drives (HDDs). The findings present a stark challenge to the prevailing assumption that SSDs, due to their internal architecture and speed, are largely immune to such timing-based information leakage.

The core of the presentation demonstrates that measurable contention exists within SSDs, a phenomenon that can be exploited to construct high-bandwidth side channels and sophisticated user behavior leakage attacks. Specifically, the researchers showcase the creation of a cover channel capable of transmitting data at speeds significantly higher than previously observed on HDDs, alongside a potent website fingerprinting attack that can identify visited websites with remarkable accuracy by merely observing disk access patterns. This work is profoundly important because it exposes a new attack surface in widely deployed hardware, highlighting that the internal complexities and performance optimizations of SSD controllers can inadvertently become a source of sensitive information leakage, impacting user privacy and system security.

Background

▶ Watch: Introduction and initial discovery of SSD contention (0:00)

The landscape of storage security has historically been dominated by research into Hard Disk Drives (HDDs), where numerous side-channel and covert-channel attacks have been documented. These prior works leveraged various physical phenomena, such as the mechanical movement of the disk arm, which introduces measurable timing variations. Researchers have exploited these variations to build covert channels, albeit at very low data rates, such as 0.1 bits per second. Other studies on HDDs explored information leakage through magnetic radiation and even acoustic noise generated by the drive, demonstrating that physical characteristics of storage devices could be exploited to infer internal operations or transmit data covertly.

With the widespread adoption of Solid State Drives, a new set of questions emerged regarding their susceptibility to similar attacks. SSDs fundamentally differ from HDDs; they lack moving parts, are significantly faster, and employ complex internal controllers with sophisticated scheduling and Quality of Service (QoS) mechanisms to manage flash memory access. The prevailing assumption, or at least a common hope, was that the sheer speed and non-mechanical nature of SSDs would render contention-based side channels ineffective or at least too difficult to measure reliably. The high IOPS (Input/Output Operations Per Second) capabilities of SSDs were thought to provide a natural defense, effectively "smoothing out" any minor timing variations that could be exploited.

However, the researchers posited that despite these differences, the fundamental principle of resource contention – where multiple simultaneous requests for a shared resource can impact the processing time of individual requests – might still apply to SSDs. The internal architecture of an SSD, while complex, still involves shared NAND flash channels, internal buffers, and a controller that must arbitrate access. This arbitration, even if highly optimized, could inadvertently introduce timing variations detectable by an attacker. To investigate this, the team embarked on a comprehensive study of 12 different SSDs, encompassing a range of characteristics including PCI Express (PCIe) Generation 3 and 4 interfaces, the presence or absence of DRAM caches, and various manufacturers. This broad selection aimed to capture a representative picture of the diverse SSD ecosystem and ascertain if contention was indeed measurable and exploitable across different hardware implementations. Their initial experiment confirmed this hypothesis: reading an increasing number of pages from an SSD predictably resulted in longer read times, establishing the foundational premise for contention-based attacks on SSDs.

Key Findings

▶ Watch: How SSDs behave differently, 2D detectability plots (3:20)

The research presented by Jonas Juffinger et al. yielded several significant findings that redefine our understanding of SSD security:

Firstly, the study unequivocally confirmed the existence of measurable contention within modern SSDs. Contrary to the intuitive assumption that high IOPS would nullify such effects, the experiments showed a clear correlation: as the victim process reads more data from the disk, the attacker's observed read times increase. This fundamental observation forms the bedrock for all subsequent attacks. The researchers identified two critical variables influencing this detectability: the victim read size (the amount of data the victim reads, from single pages to megabytes) and the observer read delay (how frequently the attacker probes the SSD).

Secondly, a crucial discovery was the high variability in behavior across different SSDs. The internal controllers of the 12 tested SSDs, despite shared specifications like PCIe generation or DRAM cache presence, exhibited distinct responses to contention. This variability stems from different implementations of Quality of Service (QoS) and request scheduling algorithms within each SSD's firmware. This means that while contention is universally present, its characteristics and exploitability differ significantly between models, posing both challenges and opportunities for attackers.

Thirdly, the researchers successfully constructed a high-bandwidth cover channel utilizing SSD contention. This channel allowed for covert data transmission between processes on the same machine, achieving an average speed of 357 bits per second (bps) across all tested SSDs. When optimized for individual SSDs, the data rate surged to an impressive 1.8 kilobits per second (kbps) on the fastest drive, dwarfing the 0.1 bps typically achieved on HDDs by a factor of over 18,000. Furthermore, they demonstrated this cover channel operating effectively between virtual machines on the same physical host, achieving 180 bps on average and up to 1.5 kbps when individually optimized, thereby breaking traditional VM isolation boundaries for storage I/O.

Fourthly, a highly impactful website fingerprinting attack was developed, leveraging the unique disk access patterns generated when a browser loads cached assets for specific websites. This attack achieved a remarkable 97% accuracy on the best-performing SSD when identifying 100 different websites, including an "open-world" dataset (meaning not all possible websites were known during training). Even on the worst-performing SSD, the accuracy remained a significant 80.2%. This demonstrates a critical privacy leak, as an attacker with local code execution (even with minimal permissions) can infer a user's browsing activity.

Finally, the research revealed that these contention-based attacks are surprisingly resilient to noise. Even when significant artificial noise was introduced into the system – up to 50% of the SSD's maximum IOPS capacity – both the cover channel and the website fingerprinting attack continued to function effectively, albeit with some degradation in speed or accuracy. This finding is particularly concerning, as it suggests that simple mitigation strategies involving generating background I/O traffic are largely ineffective against these types of side channels.

Technical Deep Dive

▶ Watch: Building a timing-based cover channel on SSDs (4:00)

The technical foundation of this research rests on the meticulous observation and exploitation of timing variations induced by I/O contention within Solid State Drives. The initial phase involved a fundamental experiment to establish the presence of such contention. Researchers simply read an increasing number of pages from an SSD and measured the time taken for these operations. The expected, and observed, outcome was a direct correlation: more pages read led to longer read times, confirming that even high-speed SSDs exhibit measurable contention.

To understand the attack surface more deeply, two key variables were systematically explored:

  1. Victim Read Size: This refers to the amount of data a "victim" process reads from the disk. The experiments aimed to determine if even small reads (e.g., a single 4KB page) were sufficient to cause detectable contention, or if larger data transfers (e.g., several megabytes) were necessary.
  2. Observer Read Delay: This variable quantifies how frequently the "attacker" process probes the SSD to measure timing. Frequent probes can themselves introduce contention, potentially interfering with the measurements or the victim's activity. The goal was to find an optimal probing frequency that maximizes detection without overwhelming the system.

The results of these investigations were visualized using 2D graphs, plotting victim read size against observer read delay. These graphs clearly illustrated the "detectability landscape" for each SSD, revealing that different drives exhibited varying sensitivities and optimal attack parameters. For instance, some SSDs allowed detection of small victim reads but only within a narrow band of observer delays, while others were more broadly susceptible. This variability was attributed to the diverse and proprietary implementations of Quality of Service (QoS) and request scheduling algorithms within the SSD controllers.

Cover Channel Implementation

Building on the ability to detect contention, the researchers constructed a cover channel. This channel operates on a simple principle: a sender process induces contention by performing disk reads to transmit a "1" bit, and refrains from reading to transmit a "0" bit. A receiver process continuously monitors the SSD's timing, inferring the transmitted bits by detecting increases in read latency.

A critical challenge for the cover channel was the variability across different SSDs. To address this, an automatic threshold finding mechanism was developed. This adaptive technique allows the receiver to dynamically determine the optimal timing threshold to distinguish between "0" and "1" bits for a given SSD and system state. The process works as follows:

  1. Synchronization Pattern: The sender begins each transmission with a known bit pattern (e.g., 0011).
  2. Receiver Adaptation: The receiver, unaware of the exact start time, continuously attempts to fit this known pattern to its observed timing data.
  3. Threshold Calculation: When a potential match is found, the receiver calculates an initial threshold. It takes the average timing values corresponding to the "0" bits in the pattern and the "1" bits, and sets the threshold in the middle.
  4. Pattern Verification: This calculated threshold is then applied to the next segment of observed data, which is expected to contain the same known pattern. If the pattern is correctly decoded, the receiver has successfully synchronized and established the optimal threshold. If not, it continues searching for the pattern.

This adaptive approach proved highly effective, enabling the cover channel to function robustly across different SSDs and even in the presence of system noise. The performance metrics were striking: an average of 357 bps across all SSDs for inter-process communication, peaking at 1.8 kbps on the fastest SSD. For virtual machine-to-virtual machine communication, the rates were 180 bps average, with a peak of 1.5 kbps. These figures represent a dramatic increase in covert channel bandwidth compared to prior HDD-based attacks.

Website Fingerprinting Attack

The website fingerprinting attack leverages the fact that when a user visits a website, the browser often reads numerous cached assets (images, scripts, CSS files, etc.) from the local disk. These reads generate a unique, measurable sequence of disk accesses that can serve as a "fingerprint" for that specific website.

The attack model assumes local code execution, where a malicious process with minimal permissions (e.g., only needing to read from a single file) can monitor disk I/O timings. When a user navigates to a website, the attacker's process observes the resulting contention patterns. The researchers provided compelling visual examples, showing distinct timing signatures for popular websites like Google, Facebook, QQ.com, IMDb, and Dropbox. For instance, Google's access patterns were consistently similar across multiple measurements but distinct from Facebook's, which itself had a different signature (e.g., a quick load with a single disk access block for a login page). QQ.com, in contrast, exhibited a "huge block of disk accesses," indicative of loading many assets.

To automate and scale the identification of these fingerprints, a Convolutional Neural Network (CNN) was employed. Although described as a "pretty simple model" by the speaker, this machine learning approach proved highly effective. The CNN was trained on the collected disk access patterns from 100 different websites. The results were impressive, with the best accuracy reaching 97% on specific SSDs, even including an open-world dataset where the model had to classify websites it hadn't explicitly seen during training. The worst-case accuracy was still a substantial 80.2%. This high accuracy underscores the uniqueness and consistency of disk-based website fingerprints.

Noise Impact and Resilience

A crucial aspect of the technical deep dive was the assessment of noise resilience. The researchers systematically introduced artificial noise into the system by generating background I/O operations, simulating scenarios where other applications or system processes might be actively using the SSD. They measured each SSD's maximum IOPS and then introduced noise at varying percentages (e.g., 10%, 20%, 50% of max IOPS).

Surprisingly, both the cover channel and the website fingerprinting attack demonstrated significant resilience. While performance might degrade (e.g., higher error rates for the cover channel, slightly lower accuracy for fingerprinting), the attacks largely remained functional. The automatic threshold finding mechanism played a vital role in the cover channel's ability to adapt to noisy environments. For website fingerprinting, even with 50% noise, some SSDs still yielded "quite good results," indicating that simply flooding the disk with I/O is not an effective mitigation. However, one specific SSD (SSD age) showed poor resilience, with results degrading "instantly" with minimal noise, suggesting that some SSD controllers are indeed "pretty bad" at handling concurrent accesses or QoS, making them either more vulnerable or, in this specific case, less consistently exploitable under noise. This highlights the varied quality of SSD controller implementations.

Demo / Proof of Concept

▶ Watch: High-speed inter-process cover channel performance results (6:10)

While the presentation transcript does not explicitly describe a live, real-time demonstration during the talk, the research clearly outlines and visually presents the operational capabilities of their developed attacks, effectively serving as a proof of concept for both the cover channel and the website fingerprinting attack. The detailed methodology and presented results strongly indicate that these attacks were fully implemented and tested.

For the cover channel, the speaker explains precisely "how the cover channel looks," referring to a graphical representation of induced timings and detected bit patterns. The discussion of the "automatic threshold finding" mechanism is a core component of this proof of concept, detailing the adaptive logic required to make the channel robust across different SSDs and conditions. The quantitative results—ranging from 357 bits per second (bps) to 1.8 kilobits per second (kbps) for inter-process communication, and 180 bps to 1.5 kbps for virtual machine-to-virtual machine communication—are direct measurements from their working implementation.

Similarly, for the website fingerprinting attack, the presentation includes "a few examples" of distinct disk access patterns corresponding to various websites like Google, Facebook, QQ.com, IMDb, and Dropbox. These graphical representations visually demonstrate the unique "fingerprints" that are generated when a browser loads cached assets for a specific site. The subsequent discussion of using a Convolutional Neural Network (CNN) to achieve up to 97% accuracy in identifying these websites further validates the practical feasibility and effectiveness of this attack. The fact that they could achieve such high accuracy on 100 different websites, including an "open world" dataset, confirms that the system was built and extensively evaluated.

The discussion around noise impact also serves as a critical part of the proof of concept, showing how the implemented attacks behave under adverse, realistic conditions. The graphs illustrating how results degrade with introduced noise, yet remain largely effective for most SSDs, attest to the robustness of their developed techniques rather than being purely theoretical constructs. In essence, the entire presentation acts as a detailed technical demonstration of their working prototypes and the tangible results they achieved.

Defensive Implications

▶ Watch: Achieving significant data leakage between virtual machines (6:50)

The findings from "Secret Spilling Drive: Leaking User Behavior through SSD Contention" carry significant defensive implications, challenging several long-held assumptions about modern storage security and highlighting areas where current protective measures fall short.

Firstly, the research fundamentally challenges the notion that high IOPS and the non-mechanical nature of SSDs inherently protect against contention side channels. For years, the speed and internal complexities of SSDs were often implicitly assumed to mitigate or eliminate the timing variations exploitable by side channels. This work decisively proves otherwise, demonstrating that the very performance optimizations within SSD controllers can create observable contention, leading to high-bandwidth information leakage. Defenders can no longer rely on the sheer speed of SSDs as a sufficient barrier against such attacks.

Secondly, the study reveals that simple mitigation strategies, such as introducing artificial noise, are largely ineffective. The resilience of both the cover channel and website fingerprinting attacks to significant levels of background I/O (up to 50% of maximum IOPS) means that attempts to "drown out" the signal by generating spurious disk activity are unlikely to succeed. This necessitates a re-evaluation of current defensive techniques and a search for more sophisticated, architectural-level solutions.

Thirdly, the variability in SSD behavior across different manufacturers and models implies a significant challenge for generic defenses. Since there's no clear correlation between vulnerability and factors like PCIe generation or DRAM cache presence, defenders cannot simply recommend specific SSD models as inherently more secure. This complexity suggests that vulnerabilities might stem from proprietary and undocumented nuances in controller firmware design, making it difficult for external parties to assess risk or develop universal patches without vendor cooperation.

Fourthly, the successful VM-to-VM cover channel underscores a critical breakdown in traditional isolation boundaries. Virtualization technologies aim to provide strong isolation between guest operating systems, yet this research demonstrates that shared physical SSD resources can be exploited to leak information across these boundaries. This finding has profound implications for cloud environments and multi-tenant systems, where the privacy and confidentiality of virtualized workloads are paramount. Cloud providers and virtualization platform developers must consider enhanced I/O isolation mechanisms at the hypervisor or even hardware level.

Finally, the research points towards a need for more secure SSD controller design. The observed differences in how SSDs handle contention suggest that improving the Quality of Service (QoS) and scheduling algorithms within the controller firmware could be a viable mitigation. Controllers designed with stronger isolation guarantees, ensuring that I/O requests from different processes or VMs do not significantly interfere with each other's timing, could reduce or eliminate the observable contention. This would likely require collaboration between academic researchers, SSD manufacturers, and operating system developers to integrate security-aware I/O scheduling from the hardware up through the software stack. Operating systems might also need to implement more fine-grained, contention-aware I/O schedulers that could detect and mitigate such side channels by randomizing access patterns or introducing intentional, non-exploitable timing noise.

Key Takeaways

  • SSDs are Vulnerable to Contention Side Channels: Despite their high IOPS and lack of mechanical parts, modern SSDs are susceptible to measurable I/O contention, which can be exploited for information leakage.
  • High-Bandwidth Cover Channels are Possible: Researchers demonstrated a cover channel capable of transmitting data at up to 1.8 kilobits per second (kbps) between processes and 1.5 kbps between virtual machines, significantly exceeding prior HDD-based covert channels.
  • Effective Website Fingerprinting Attacks: By observing unique disk access patterns generated by cached web assets, an attacker can identify visited websites with high accuracy (up to 97%) using a CNN, posing a significant privacy risk.
  • Attacks are Noise Resilient: Both the cover channel and website fingerprinting attacks proved resilient to substantial artificial noise (up to 50% of max IOPS), indicating that simple I/O flooding is not an effective mitigation.
  • SSD Behavior Varies Widely: The vulnerability and characteristics of contention side channels differ significantly across SSD models, with no clear correlation to PCIe generation, DRAM cache, or manufacturer, complicating generic defensive strategies.
  • VM Isolation is Insufficient: The success of VM-to-VM cover channels highlights that traditional virtualization isolation mechanisms do not adequately protect against shared storage resource contention attacks.

About the Speaker(s)

The talk "Secret Spilling Drive: Leaking User Behavior through SSD Contention" was presented by Jonas Juffinger. He credited Fabian Rousa, Jeppelana, and Stin as co-authors on this joint research work. Beyond their names, specific titles, affiliations, or other biographical details for the speakers were not provided within the transcript or metadata.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Solid, original hardware side-channel research that systematically dismantles the 'SSDs are too fast to leak timing' assumption across 12 devices, building to a 97%-accurate website fingerprinting attack and a covert channel that blows HDD-based predecessors out of the water by four orders of magnitude. The VM-to-VM channel breaking storage isolation boundaries is the headline result that matters most for cloud security practitioners.

Heather Calloway (CISO) — WEAK

Technically rigorous research that surfaces a real and underappreciated attack surface in widely deployed hardware. But it stops at the research boundary and never crosses into the territory that makes it actionable — no guidance for cloud security teams, no vendor accountability path, no policy lever, no operator decision tree.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025