Designing Secure Performance Metrics for Last Level Cache

Designing Secure Performance Metrics for Last Level Cache
复制标题

DOI:
10.1109/ipdpsw59300.2023.00069
复制
发表时间:
2023-05
期刊:
2023 IEEE International Parallel and Distributed Processing Symposium Workshops (IPDPSW)
影响因子:
--
通讯作者:
Probir Roy;Birhanu Eshete;Pengfei Su
Probir Roy;Birhanu Eshete;Pengfei Su
中科院分区:
其他
文献类型:
--
作者:
Probir Roy;Birhanu Eshete;Pengfei Su

文献摘要

相似文献

在现代CPU体系结构中,末级缓存(LLC)通常在多个CPU核心之间共享。LLC支持跨应用程序线程共享数据,并提高数据的可重用性。然而,由于资源有限,LLC的有效利用对应用程序性能至关重要。了解LLC使用情况的一种有效方法是使用硬件性能计数器来测量LLC性能指标,如命中率和未命中率。鉴于基于硬件计数器的性能指标的优势,由于安全隐患,在多租户环境中启用这些指标具有挑战性。对手可以利用这些指标进行各种旁路攻击。当前的缓解策略只是限制对性能指标的访问,这限制了这些指标用于性能监控和优化的合法用途。针对LLC度量作为旁路攻击附件的脆弱性,提出了一种新的安全性能度量CER-BERUS,旨在限制LLC基于性能计数器的旁路漏洞,同时提供有用的性能洞察。Cerberus的关键洞察力在于,它利用了一种不同的私有机制,使攻击者无法检测到旁路。通过对基准性能监控场景的系统评估,我们表明Cerberus的性能度量可用于LLC感知的Profile引导的编译器优化。
In modern CPU architectures, last level caches (LLC) are typically shared among multiple CPU cores. LLCs enable data sharing across application threads and promote data re-usability. However, due to limited resources, an efficient utilization of LLCs is vital for application performance. One effective way to understand the LLC usage is using hardware performance counters to measure the LLC performance metrics such as hit and miss ratios.Given the benefits of hardware counter based performance metrics, enabling these metrics in a multi-tenant environment is challenging due to security implications. An adversary can exploit these metrics for various side-channel attacks. Current mitigation policies simply restrict the access of performance metrics which limits the legitimate use of these metrics for performance monitoring and optimization. This paper addresses the vulnerability of LLC metrics as an accessory to side-channel attacks.This paper proposes novel secure performance metrics, CER-BERUS, aimed at limiting LLC performance counter-based side-channel vulnerability while providing usable performance insights. The key insight in CERBERUS is that it leverages a differentially private mechanism to make the side-channels undetectable to adversaries. Through a systematic evaluation of benchmark performance monitoring scenarios, we show that CERBERUS’s performance metrics are usable for LLC-aware profile-guided compiler optimization.