TaintHLS: High-Level Synthesis for Dynamic Information Flow Tracking

TaintHLS: High-Level Synthesis for Dynamic Information Flow Tracking
复制标题

TaintHLS:动态信息流跟踪的高级综合

DOI:
10.1109/tcad.2018.2834421
复制
发表时间:
2019
影响因子:
2.9
通讯作者:
F. Regazzoni
F. Regazzoni
中科院分区:
计算机科学3区
文献类型:
--
作者:
C. Pilato;Kaijie Wu;S. Garg;R. Karri;F. Regazzoni

文献摘要

被引文献

相似文献

动态信息流跟踪(DIFT)是一种在运行时跟踪软件和硬件系统中潜在安全漏洞的技术。不可信的数据被标记为标签(受污染的),这些标签通过系统传播,并分析其不安全使用的可能性以防止它们。异构系统特别是硬件加速器不支持DIFT。目前,DIFT是手动生成并集成到加速器中。此过程容易出错,可能会损害在异构系统中识别安全违规的过程。我们提出了TaintHLS,以自动生成一个微架构来支持基线操作,并在硬件加速器中自动生成一个影子微架构来支持内在的DIFT,同时提供可变粒度的污染标签。TaintHLS提供了一个配套的高级合成(HLS)方法,可以从高级规范自动生成支持dift的加速器。我们扩展了最先进的HLS工具来生成dift增强的加速器,并在许多基准测试中演示了该方法。启用dift的加速器的性能可以忽略不计,硬件开销不超过30%。
Dynamic information flow tracking (DIFT) is a technique to track potential security vulnerabilities in software and hardware systems at run time. Untrusted data are marked with tags (tainted), which are propagated through the system and their potential for unsafe use is analyzed to prevent them. DIFT is not supported in heterogeneous systems especially hardware accelerators. Currently, DIFT is manually generated and integrated into the accelerators. This process is error-prone, potentially hurting the process of identifying security violations in heterogeneous systems. We present TaintHLS, to automatically generate a micro-architecture to support baseline operations and a shadow microarchitecture for intrinsic DIFT support in hardware accelerators while providing variable granularity of taint tags. TaintHLS offers a companion high-level synthesis (HLS) methodology to automatically generate such DIFT-enabled accelerators from a high-level specification. We extended a state-of-the-art HLS tool to generate DIFT-enhanced accelerators and demonstrated the approach on numerous benchmarks. The DIFT-enabled accelerators have negligible performance and no more than 30% hardware overhead.