A framework for trusted instruction execution via basic block signature verification

A framework for trusted instruction execution via basic block signature verification
复制标题

通过基本块签名验证实现可信指令执行的框架

DOI:
10.1145/986537.986582
复制
发表时间:
2004
期刊:
--
影响因子:
--
通讯作者:
E. Jovanov
E. Jovanov
中科院分区:
--
文献类型:
--
作者:
M. Milenkovic;A. Milenković;E. Jovanov

文献摘要

被引文献

相似文献

当今的大多数计算机都连接到互联网或至少连接到本地网络,从而将系统漏洞暴露给潜在的攻击者。攻击者的目标之一是执行未经授权的代码。在本文中,我们提出了一个框架,将只允许执行的可信代码,并防止恶意代码执行。所提出的框架依赖于基本块签名的运行时验证。基本块签名是在可信安装过程中使用具有秘密系数和程序内基本块地址的签名函数生成的。可信安装的结果是加密的基本块签名表(BBST),它被附加到程序二进制文件中。使用SPEC CPU2000基准测试的痕迹,所提出的框架的潜力进行评估。结果表明,所提出的机制不会对性能产生很大的负面影响。
Most of today's computers are connected to the Internet or at least to a local network, exposing system vulnerabilities to the potential attackers. One of the attackers' goals is the execution of the unauthorized code. In this paper we propose a framework that will allow execution of the trusted code only and prevent malicious code from executing. The proposed framework relies on the run-time verification of basic block signatures. The basic block signatures are generated during a trusted installation process, using a signature function with secret coefficients and the address of the basic block within a program. The result of the trusted installation is the encrypted basic block signature table (BBST), which is appended to the program binary. The potential of the proposed framework is evaluated using traces of SPEC CPU2000 benchmarks. The results indicate that the proposed mechanism does not have a large negative impact on performance.