Preventing Denial-of-Service Attacks in Shared CMP Caches

Preventing Denial-of-Service Attacks in Shared CMP Caches
复制标题

防止共享 CMP 缓存中的拒绝服务攻击

DOI:
10.1007/11796435_37
复制
发表时间:
2006
期刊:
2008 International Symposium on Computer Architecture
影响因子:
--
通讯作者:
D. Serpanos
D. Serpanos
中科院分区:
--
文献类型:
--
作者:
G. Keramidas;Pavlos Petoumenos;S. Kaxiras;Alexandros Antonopoulos;D. Serpanos

文献摘要

被引文献

相似文献

拒绝服务(DoS)攻击试图耗尽以服务为中心的提供商的一些共享资源(例如,进程表、功能单元)。随着片上多处理器(CMP)成为服务器级处理器的主流架构,以能够提供QoS保证的方式来管理片上资源的需求成为必要。CMP中的共享资源通常包括L2高速缓存存储器。在本文中,我们探讨了在CMP工作站的恶意线程或只是缓存“饥饿”的线程试图占用该高速缓存引起的拒绝服务的机会管理片上共享缓存的问题。我们的方法的一个重要特点是,没有必要区分恶意和“健康”的线程。所提出的方法是基于一个统计模型的共享缓存,可以与运行时的信息,并准确地描述了共享线程的行为。使用此信息,我们能够了解哪个线程(恶意的或非恶意的)可以被“压缩”到更少的空间中,而损害可以忽略不计,并相应地驱动该高速缓存的底层替换策略。我们的研究结果表明,建议的抗攻击替换算法可以用来执行高级别的政策,如政策,试图最大限度地提高“有用性”的该高速缓存真实的房地产或分配自定义的空间分配政策的基础上外部QoS的需求。
Denial-of-Service (DoS) attacks try to exhaust some shared resources (e.g. process tables, functional units) of a service-centric provider. As Chip Multi-Processors (CMPs) are becoming mainstream architecture for server class processors, the need to manage on-chip resources in a way that can provide QoS guarantees becomes a necessity. Shared resources in CMPs typically include L2 cache memory. In this paper, we explore the problem of managing the on-chip shared caches in a CMP workstation where malicious threads or just cache “hungry” threads try to hog the cache giving rise to DoS opportunities. An important characteristic of our method is that there is no need to distinguish between malicious and “healthy” threads. The proposed methodology is based on a statistical model of a shared cache that can be fed with run-time information and accurately describe the behavior of the shared threads. Using this information, we are able to understand which thread (malicious or not) can be “compressed” into less space with negligible damage and to drive accordingly the underlying replacement policy of the cache. Our results show that the proposed attack-resistant replacement algorithm can be used to enforce high-level policies such as policies that try to maximize the “usefulness” of the cache real estate or assign custom space-allocation policies based on external QoS needs.