Security Analysis of Cache Replacement Policies

Security Analysis of Cache Replacement Policies
复制标题

缓存替换策略的安全分析

DOI:
10.1007/978-3-662-54455-6_9
复制
发表时间:
2017
期刊:
ACM Transactions on Embedded Computing Systems (TECS)
影响因子:
--
通讯作者:
J. Reineke
J. Reineke
中科院分区:
--
文献类型:
--
作者:
Pablo Cañones;Boris Köpf;J. Reineke

文献摘要

被引文献

相似文献

现代计算机体系结构在不同的程序之间共享物理资源,以提高面积、能源和成本效率。遗憾的是,共享通常会产生可被利用来提取或传输敏感信息的旁路通道。我们目前缺乏对安全和效率之间的相互作用进行系统推理的技术。特别是,没有一种既定的方法来量化共享缓存的安全属性。 在本文中,我们提出了一个新的模型,它使我们能够刻画缓存的重要安全属性。我们的模型包括两个方面:1可以被缓存吸收的信息量,以及2可以被对手有效地从缓存中提取的信息量。我们使用我们的模型来计算常见缓存替换策略FIFO、LRU和PLRU的两个量,并比较它们的隔离特性。我们将进一步展示我们的信息提取模型如何产生一个算法,该算法可用于改进CacheAudit静态分析器提供的界限。
Modern computer architectures share physical resources between different programs in order to increase area-, energy-, and cost-efficiency. Unfortunately, sharing often gives rise to side channels that can be exploited for extracting or transmitting sensitive information. We currently lack techniques for systematic reasoning about this interplay between security and efficiency. In particular, there is no established way for quantifying security properties of shared caches. In this paper, we propose a novel model that enables us to characterize important security properties of caches. Our model encompasses two aspects: 1 The amount of information that can be absorbed by a cache, and 2 the amount of information that can effectively be extracted from the cache by an adversary. We use our model to compute both quantities for common cache replacement policies FIFO, LRU, and PLRU and to compare their isolation properties. We further show how our model for information extraction leads to an algorithm that can be used to improve the bounds delivered by the CacheAudit static analyzer.