A Hardware-Software Platform for Intrusion Prevention

A Hardware-Software Platform for Intrusion Prevention
复制标题

用于入侵防御的软硬件平台

DOI:
--
复制
发表时间:
2004
期刊:
Micro
影响因子:
--
通讯作者:
D. Kirovski
D. Kirovski
中科院分区:
--
文献类型:
--
作者:
Milenko Drinic;D. Kirovski

文献摘要

被引文献

相似文献

防止在给定计算机上执行未经授权的软件在系统安全中起着关键作用。关键的问题是,尽管程序在开始执行时可以被验证为是真实的,但它的执行流可以被重定向到外部注入的恶意代码,例如,使用缓冲区溢出漏洞。我们介绍了一种新的、简化的、硬件辅助的入侵防御平台。我们的平台引入了程序执行和MAC验证的重叠。它将程序二进制文件分割成指令块。每个块都使用一个带密钥的MAC签名,该MAC作为块的页脚附加到块上。当控制流到达一个特定的块时,它的指令被推测执行,而专用硬件在运行时验证附加的MAC。在推测执行期间,使用放置在处理器和L1数据缓存之间的中介缓冲区保存计算状态。在MAC验证之后,来自该缓冲区的结果将向外部传播。本文的核心是提出一种新的优化技术,该技术最初识别可能导致执行停滞的指令,并在给定指令块内重新排序基本块以最小化执行开销。虽然所提出的优化技术是特定于问题的,但它是灵活的,可以针对不同的优化目标进行调整。初步结果表明,我们的优化方法在SPEC2000基准测试套件和Microsoft Visual FoxPro上平均减少了60%的开销。
Preventing execution of unauthorized software on a given computer plays a pivotal role in system security. The key problem is that although a program at the beginning of its execution can be verified as authentic, its execution flow can be redirected to externally injected malicious code using, for example, a buffer overflow exploit. We introduce a novel, simplified, hardware-assisted intrusion prevention platform. Our platform introduces overlapping of program execution and MAC verification. It partitions a program binary into blocks of instructions. Each block is signed using a keyed MAC that is attached as a footer to the block. When the control flow reaches a particular block, its instructions are speculatively executed, while dedicated hardware verifies the attached MAC at run-time. The computation state is preserved during speculative execution using a mediating buffer placed between the processor and L1 data cache. Upon MAC verification, the results from this buffer are propagated externally. Central to this paper is the proposal of a novel optimization technique that initially identifies instructions that are likely to stall execution, and reorders basic blocks within a given instruction block to minimize the execution overhead. While the presented optimization technique is problem specific, it is flexible such that it can be adjusted for different optimization goals. Preliminary results showed that our optimization methods produced an average overhead reduction of 60% on the SPEC2000 benchmark suite and Microsoft Visual FoxPro.